惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
博客园 - 聂微东
B
Blog RSS Feed
Apple Machine Learning Research
Apple Machine Learning Research
Hugging Face - Blog
Hugging Face - Blog
博客园 - 三生石上(FineUI控件)
博客园 - Franky
小众软件
小众软件
罗磊的独立博客
G
Google Developers Blog
美团技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
MongoDB | Blog
MongoDB | Blog
腾讯CDC
N
Netflix TechBlog - Medium
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Security Latest
Security Latest
T
Threatpost
L
LINUX DO - 热门话题
P
Privacy & Cybersecurity Law Blog
J
Java Code Geeks
T
Threat Research - Cisco Blogs
V2EX - 技术
V2EX - 技术
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
NISL@THU
NISL@THU
M
MIT News - Artificial intelligence
Cisco Talos Blog
Cisco Talos Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
H
Heimdal Security Blog
The Last Watchdog
The Last Watchdog
量子位
P
Palo Alto Networks Blog
W
WeLiveSecurity
H
Hacker News: Front Page
Hacker News - Newest:
Hacker News - Newest: "LLM"
博客园_首页
爱范儿
爱范儿
V
Vulnerabilities – Threatpost
Engineering at Meta
Engineering at Meta
Help Net Security
Help Net Security
D
Darknet – Hacking Tools, Hacker News & Cyber Security
S
Security Affairs
云风的 BLOG
云风的 BLOG
A
About on SuperTechFans
A
Arctic Wolf
大猫的无限游戏
大猫的无限游戏
T
The Exploit Database - CXSecurity.com
Hacker News: Ask HN
Hacker News: Ask HN
C
Cisco Blogs
Jina AI
Jina AI

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
HIPAA + HRSA + FTCA + OSHA at an FQHC: One Compliance Stack, Four Rulebooks
Joe Gellatly · 2026-05-20 · via DEV Community

Joe Gellatly

FQHCs run on a four-rulebook compliance regime — HIPAA, HRSA OSV, FTCA deeming, OSHA. The mistake we see most often is treating them as four separate compliance functions, with four separate spreadsheets, four separate trainings, four separate evidence-collection workflows, and four separate panic responses when the auditor calls.

They don't have to be. The four rulebooks have substantial overlap in what they want documented, who's responsible, and what evidence proves it. A reasonable engineering goal is one compliance stack with four output views.

This post walks the four rulebooks, the overlap, and what a single-stack architecture looks like in practice.

1. HIPAA 2026

What it requires from an FQHC, in engineering terms:

  • Annual Security Risk Assessment with documented findings and remediation tracking. The 2026 Security Rule moved the SRA from "do it once a year" to "the spine of the program."
  • BAA inventory with subcontractor flow-down. Every vendor that touches PHI — including the EHR, the cloud backup, the appointment reminder vendor, the transcription service, the IT MSP — needs a current BAA on file.
  • Workforce training with role-based content and completion records tied to SRA findings.
  • Audit trail of access to PHI in the EHR and other PHI systems, queryable by date range.
  • Breach response runbook with a tested communications path.

The data model: SRA findings, controls, evidence records, BAA records, training completion records, breach incidents.

2. HRSA Operational Site Visit (OSV)

HRSA's OSV looks at the full Section 330 program requirements for FQHCs — governance, financial systems, clinical performance, and management/finance compliance. From a compliance-stack perspective, the HIPAA-adjacent items are:

  • Governance documentation — board composition, board minutes, board oversight of compliance and quality.
  • Financial systems — sliding fee schedule administration, billing accuracy, sliding-fee documentation.
  • Clinical — credentialing and privileging records, quality improvement program, clinical performance metrics.
  • HIPAA-adjacent items in OSV — confidentiality/privacy policies, workforce training documentation, breach notification procedures, IT security overview.

The overlap with HIPAA: the workforce training records, the BAA inventory, the breach-response runbook, and the asset inventory all feed directly into OSV documentation requests. If your HIPAA evidence is in good shape, the HIPAA-adjacent OSV items are effectively pre-staged.

The non-overlap: OSV's clinical and financial items live outside the HIPAA stack and need their own data sources (EHR clinical reports, billing system reports, board documents).

3. FTCA deeming

FTCA covers FQHCs and their providers for medical malpractice claims as if they were federal employees. To maintain deeming, an FQHC has to demonstrate annually that it has, among other things:

  • An active risk management program with documented risk assessments and remediation tracking.
  • Quality improvement and quality assurance processes with documented activities.
  • Credentialing and privileging of providers per the deeming requirements.
  • Claims management processes including timely reporting of potential claims.

The HIPAA overlap is at the risk-management documentation layer. Your HIPAA SRA, the remediation tracking, and the documented governance review of compliance findings are all evidence that supports the FTCA risk-management requirement. The same SRA tool that produces HIPAA findings can, with the right evidence model, produce the risk-management documentation FTCA wants.

The non-overlap: credentialing and privileging is a separate workflow, usually owned by clinical operations, and lives outside the compliance stack.

4. OSHA

The OSHA rulebooks that matter at an FQHC:

  • Bloodborne Pathogens Standard (29 CFR 1910.1030) — exposure control plan, annual training, hepatitis B vaccination offer documentation, sharps injury log, post-exposure follow-up.
  • Hazard Communication (HazCom) — chemical inventory, SDS access, labeling, training.
  • Workplace Violence Prevention — under the OSHA healthcare-specific WPV rule, FQHCs need a written WPV prevention program, a hazard assessment, training, and incident logging.
  • Recordkeeping (300/300A logs) if applicable to size.

The HIPAA overlap: training cadence and recordkeeping. Bloodborne pathogens, HazCom, and WPV training are all annual; HIPAA training is annual; new-hire onboarding triggers all four. If your training platform can handle role-based content for HIPAA, it can handle the OSHA modules too — and the completion records belong in the same audit trail.

The non-overlap: the sharps-injury log, the SDS library, and the WPV incident log are OSHA-specific data that doesn't fit cleanly into a HIPAA SRA tool.

One compliance stack architecture

The four rulebooks have four different auditors, but they keep asking for the same six artifacts:

  1. Single asset inventory — one source of truth for devices, systems, and locations. Feeds HIPAA SRA, HRSA OSV IT review, OSHA hazard assessment.
  2. Single training platform — role-based, with one completion record per person per module. Feeds HIPAA training requirement, HRSA workforce training documentation, OSHA bloodborne / HazCom / WPV training.
  3. Single BAA / vendor repository — every vendor with renewal tracking, scope of access, and subcontractor flow-down. Feeds HIPAA BAA inventory and HRSA's contract-review items.
  4. Single risk-management workflow — one SRA / risk-assessment process that produces findings, remediation tasks, and a governance review trail. Feeds HIPAA SRA, FTCA risk-management documentation, HRSA QI/QA.
  5. Single audit trail — append-only, queryable by date range and record class. Feeds OCR investigations, OSV evidence requests, FTCA deeming applications.
  6. Single incident log — one place where breaches, sharps injuries, WPV incidents, and adverse events get logged with a consistent schema. Different rulebooks pull different views.

The architecture point: the four rulebooks are four output views over a small, shared set of underlying data. A compliance platform built for the healthcare vertical (and FQHCs specifically) should treat them that way. A general-purpose GRC platform built for SOC 2 will not, because the underlying data model doesn't include the FQHC-specific objects.

The practical test: if your compliance platform can answer "show me all training completion records for Jane Doe across HIPAA, bloodborne pathogens, HazCom, and WPV in 2026, with timestamps" in a single query, you have one stack. If it requires four separate exports and a spreadsheet merge, you have four stacks pretending to be one.


Reading list