Resource Center
Compliance
6 answered so far, with more on the way.
Answers
- Can a healthcare practice use ChatGPT or Copilot under HIPAA?Yes, but only with tools covered by a Business Associate Agreement (BAA) and set up correctly. Free and personal AI accounts have no BAA, so protected health information must never go into them. Microsoft covers Microsoft 365 services under its BAA, and OpenAI offers BAAs only for certain business products. Confirm coverage for the exact product and license before any patient data goes in.
- Do we need a HIPAA risk assessment?Yes, if you're a covered entity or business associate. The HIPAA Security Rule requires an accurate and thorough risk analysis of threats to electronic protected health information, and it's the first thing investigators ask for after a breach. It should be updated regularly and whenever your systems or operations change significantly.
- Does our accounting firm need a written information security plan (WISP)?Yes. Tax and accounting professionals are covered by the FTC Safeguards Rule, which requires a written information security program, and the IRS expects every tax preparer to have one. IRS Publication 4557 explains the requirements, and Publication 5708 provides a sample plan to start from. It needs to reflect what your firm actually does.
- Does the FTC Safeguards Rule apply to our dealership?If your dealership arranges financing or leasing, almost certainly. The FTC treats those dealers as financial institutions under the Gramm-Leach-Bliley Act. The updated Safeguards Rule requires a written information security program, a qualified person in charge of it, risk assessments, multi-factor authentication, encryption, and notifying the FTC of certain breaches.
- What is data classification, and do we need it?Data classification means sorting your information by how sensitive it is, usually into three or four levels such as Public, Internal, Confidential, and Restricted, and labeling it so people and systems handle it properly. Most organizations of 20 or more people benefit, and it matters more once AI tools like Copilot can search across everything.
- What should an AI acceptable-use policy say?Keep it short enough that people read it. It should name the approved AI tools, list the information that never goes into any AI tool, require a person to review anything AI produces before it reaches a client, and say who to ask about a new tool. Review it at least yearly, because the tools change quickly.
Talk to a person, not a ticket
Tell us what's going on. We'll listen, ask good questions, and give you a straight answer about whether we can help.