HIPAA Digest | Catapult Business Innovations – September 17, 2025

GAO: HHS Yet to Implement 82 Cybersecurity and IT Management Recommendations

A new GAO report highlights ongoing gaps in federal cybersecurity and IT management that could affect HIPAA compliance and vendor security programs, signaling where business leaders should focus risk management and controls as they consider AI and digital marketing tools.

Read full article

Stampli Announces HIPAA Compliance, Now Offers Business Associate Agreements to HIPAA Customers

Stampli now provides HIPAA compliance and BAAs, helping healthcare-focused clients ensure PHI handling aligns with HIPAA rules as they adopt automated payments and AI-assisted workflows.

Read full article

TPSC Data Breach Affects PII & PHI

A data breach affecting PII and PHI underscores the risk to patient data and the need for robust breach response, vendor risk management, and monitoring—common considerations when evaluating partners or deploying AI marketing tech that touches PHI.

Read full article

Caldwell County renews Emergency Air Medical Membership Agreement with PHI Cares – follows 15 years of outstanding service to the community

The ongoing EMS membership with PHI Cares illustrates the value of reliable healthcare partnerships and long-term service contracts, a consideration for business leaders when planning vendor relationships and continuity strategies.

Read full article

Time to Rush – Pacific Index

Time to Rush from Pacific Index provides regional updates; while not HIPAA-specific, staying informed on local market and risk factors can inform localized marketing, operations, and resilience planning.

Read full article