Apgar & Associates, LLC, HIPAA Privacy and Security

Apgar & Associates, LLC, HIPAA Privacy and Security Apgar & Associates, LLC | Consulting expertise in privacy, infosec, HIPAA, HITECH & cert readiness

At Apgar & Associates, we provide expert HIPAA privacy, information security, HITECH and regulatory compliance consulting services to health plans, physician group practices, clinics and hospitals and the vendors (business associates) that support them. Additionally, Chris Apgar, CISSP, CEO, is a frequent educator and panelist for OMA, HCCA and other industry-leading organizations.

A federal agency wants your ER records — and it's raising real privacy red flags.The CPSC is asking hospitals across the...
08/11/2026

A federal agency wants your ER records — and it's raising real privacy red flags.

The CPSC is asking hospitals across the country to hand over digital patient data to a contractor called Konza Health, as part of an effort to modernize a decades-old system that tracks injuries from consumer products. Sounds reasonable on paper... until you look closer.

HIPAA does let hospitals share data with agencies like this for public health reasons, but only the minimum info needed — nothing more. Critics say this request blows past that line. Some hospitals are already pushing back, saying the ask is way too broad. On top of that, nobody's gotten a clear answer on how the contractor will actually protect all this sensitive data once it has it.

Bottom line: "it's for public health" isn't a blank check. Hospitals should be asking hard questions before they hit send.

https://1l.ink/5PTNLMC

When did you last conduct a Security Risk Analysis? 🤔With how fast technology evolves — and how often workforces turn ov...
07/09/2026

When did you last conduct a Security Risk Analysis? 🤔

With how fast technology evolves — and how often workforces turn over — security risks change constantly. That’s why we recommend organizations complete a comprehensive SRA every 12 to 18 months.

A current SRA helps you:
→ Understand risks to the confidentiality, integrity, and availability of your data
→ Reduce the risk of non-compliance penalties
→ Meet MACRA requirements
→ Test the strength of your security protocols

Once completed, every risk gets classified as 🔴 high, 🌕 medium, or low — and you walk away with a concrete Risk Management Plan, not just a report.

Compliance isn’t a one-time event. Is your SRA up to date? 📞 Call Us: 503.384.2538

Prove compliance is important to you with a security risk analysis. The Security Risk Analysis (SRA) is the cornerstone of your ability to comply with privacy, security and data breach notification regulations under ISO and HIPAA.

05/29/2026

HIPAA's Security Rule requires that healthcare organizations and their BAs have a Security Incident Response Plan. Is yours ready to hold up under pressure? 📞 (503) 384-2538

When a breach happens (because they do), you need to know *instantly* who to call, what to do, and how to notify the right people. Plus, if your state's privacy laws are stricter than HIPAA (check yours if you're not sure), you're required to meet that higher bar, too.

Apgar & Associates helps healthcare organizations and their BAs create, test, and train on incident response plans built for real-world compliance: HIPAA, state law, and beyond.

Why wait for an incident to find out your plan has gaps? 🌐 https://1l.ink/SRRDNN8

05/18/2026

Get [Gap] Closure for your P&Ps - at Apgar & Associates, we've made it straightforward. Whether you need:
✅ Template-style P&P manuals you can implement right away 📚
✅ A custom manual built around your specific environment
✅ A Mock OCR HIPAA Audit so you know exactly where you stand before an auditor does 🧐

…you get what you need, like a clear roadmap so you if you're audited, you can respond to the OCR (or your largest customer's CISO) with 💯confidence.
Let's make your policies and procedures work FOR you, not collect dust.👇
📞 (503) 384-2538

🚨 Oregon hospitals and FQHCs: new law in effect June 5, 2026. https://1l.ink/57MF5F3 Senate Bill 1570 changes how your f...
05/18/2026

🚨 Oregon hospitals and FQHCs: new law in effect June 5, 2026. https://1l.ink/57MF5F3
Senate Bill 1570 changes how your facility must respond when law enforcement arrives. This law applies to interactions with federal, state, and local law enforcement.
⏳Prepare now. Need a policy template to address these new requirements in time? Please @-tag me in the Comments or DM!
:

More info to follow! ⚠️ New federal cybersecurity rules are coming; ⏰'s ticking. CISA is finalizing regulations under CI...
05/06/2026

More info to follow! ⚠️ New federal cybersecurity rules are coming; ⏰'s ticking. CISA is finalizing regulations under CIRCIA that will require 300,000+ businesses across 16 critical infrastructure sectors to report cyber incidents within 72 hours and ransomware payments within 24 hours. Many businesses that never thought they were “critical infrastructure” will find themselves "squarely in scope." >>> https://1l.ink/5P3P67C

ICYMI: CMS published the new standards for claims documentation e-transfers > https://1l.ink/BBQQFFJ
03/31/2026

ICYMI: CMS published the new standards for claims documentation e-transfers > https://1l.ink/BBQQFFJ

Address

7100 SW Hampton Street, Ste 137
Tigard, OR
97223

Opening Hours

Monday 9am - 5pm
Tuesday 8:30am - 5pm
Wednesday 8:30am - 5pm
Thursday 8:30am - 5pm
Friday 8:30am - 5pm

Telephone

(503) 384-2538

Alerts

Be the first to know and let us send you an email when Apgar & Associates, LLC, HIPAA Privacy and Security posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Apgar & Associates, LLC, HIPAA Privacy and Security:

Shortcuts

Share