{"id":8,"date":"2025-08-12T11:22:16","date_gmt":"2025-08-12T17:22:16","guid":{"rendered":"https:\/\/mrsspeechonline.com\/personal-hipaa-compliance-journey\/"},"modified":"2025-08-12T11:22:16","modified_gmt":"2025-08-12T17:22:16","slug":"personal-hipaa-compliance-journey","status":"publish","type":"post","link":"https:\/\/mrsspeechonline.com\/staging\/2315\/personal-hipaa-compliance-journey\/","title":{"rendered":"My Personal HIPAA Compliance Journey: Steps to Secure Data"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-how-i-m-making-my-solo-practice-hipaa-happy\">How I&#8217;m Making My Solo Practice HIPAA-Happy!<\/h2>\n\n\n\n<p>Hey fellow SLPs and healthcare pros! Today, I want to share some insights from my personal journey towards HIPAA compliance.<\/p>\n\n\n\n<p>In my last two posts, we delved into the crucial topic of&nbsp;<strong>HIPAA compliance for telepractice<\/strong>.  They covered the &#8220;what&#8221; and the &#8220;why.&#8221;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/mrsspeechonline.com\/staging\/2315\/hipaa-compliance-at-home\" target=\"_blank\" rel=\"noreferrer noopener\">HIPAA Compliance At Home: Cloud, Schools, Teletherapy &amp; PHI Security<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/mrsspeechonline.com\/staging\/2315\/slp-business-associate-agreement-hipaa-guide\/\" target=\"_blank\" rel=\"noreferrer noopener\">Navigating Business Associate Agreements as an SLP:  Your HIPAA BAA Guide<\/a><\/li>\n<\/ul>\n\n\n\n<p>Today, I want to share the &#8220;how&#8221; \u2013 my personal journey of putting these principles into practice! I\u2019ve been diving deep into my tech setup to make sure it&#8217;s not just functional, but also rock-solid HIPAA compliant. <em><strong> <\/strong><\/em>For example, as a teletherapist, some of my schools don&#8217;t invite me into their workspace. This leaves it up to me to securely manage all my client notes and materials. This kind of gap is precisely what drove me to build a truly robust system.<\/p>\n\n\n\n<p>It might sound daunting, but trust me, it&#8217;s all about peace of mind for both you and your clients. I wanted to share a rundown of what I&#8217;ve done.  More importantly, I want to share why I&#8217;ve done it, in case it helps you level up your practice too!<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-the-why-behind-my-personal-hipaa-compliance-journey\">The &#8220;Why&#8221; Behind My Personal HIPAA Compliance Journey<\/h3>\n\n\n\n<p>My biggest drive was simple. I needed to know, without any doubt, that I was protecting my clients&#8217; sensitive information to the highest standard. HIPAA isn&#8217;t just a checkbox; it&#8217;s about building trust. First, conducted a&nbsp;<strong>thorough risk analysis<\/strong>&nbsp;of my setup to identify any potential vulnerabilities.<\/p>\n\n\n\n<p>I&#8217;ve now meticulously created and am maintaining a detailed&nbsp;<strong>&#8220;Security Policies and Procedures&#8221; document<\/strong>&nbsp;that guides all my practices. Plus, having everything clearly documented helps me sleep better at night!<\/p>\n\n\n\n<p>Honestly, it wasn&#8217;t that long ago, a few weeks, that I wasn&#8217;t even aware of all of this.  I didn&#8217;t know about Business Associate Agreements (BAAs), or their critical role.  My previous security stance of &#8220;just don&#8217;t share client info&#8221; felt sufficient.  Since then, I&#8217;ve realized how&nbsp;<strong>nebulous and insufficient<\/strong>&nbsp;that really was for both cloud-based and desktop information.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-how-it-all-started\">How It All Started<\/h3>\n\n\n\n<p>So, if I wasn&#8217;t born with this wealth of knowledge, and it wasn&#8217;t covered in grad school, what happened?  Well, I discovered that simply removing what I thought was identifying information was&nbsp;<strong>not sufficient for HIPAA de-identification<\/strong>.  That realization truly sent me down this &#8220;rabbit hole&#8221; of learning and implementing everything you&#8217;re about to read!<\/p>\n\n\n\n<p>Honestly, as a single user, all this might seem like&nbsp;<strong>overkill<\/strong>&nbsp;at times.  That is, until I really think about the potential&nbsp;<strong>cost and repercussions of a HIPAA violation<\/strong>. That quickly puts things into perspective!<\/p>\n\n\n\n<p>Here&#8217;s information and tips I&#8217;ve learned on this individual HIPAA compliance trek.  <em><strong>(No, I&#8217;m not affiliated with, or sponsored by, Google in any way, it was just easier to work with.)<\/strong><\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-the-secure-foundation-my-google-workspace-enterprise-standard\">The Secure Foundation: My Google Workspace Enterprise Standard<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"320\" height=\"213\" src=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/06\/network-3866435_1280.webp\" alt=\"Three modern computer monitors with blank screens, digitally connected to a glowing blue global network sphere covered in white binary code, set against a blue background with radiating lines.\" class=\"wp-image-77\" title=\"Securing Cloud Data and Professional Networks\" srcset=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/06\/network-3866435_1280.webp 320w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/06\/network-3866435_1280-300x200.webp 300w\" sizes=\"auto, (max-width: 320px) 100vw, 320px\" \/><figcaption class=\"wp-element-caption\">Establishing a secure digital foundation for Protected Health Information in the cloud.<\/figcaption><\/figure>\n<\/div>\n\n\n<p>Before even setting up my specific security rules, choosing the right Google Workspace edition was crucial. There are several tiers, and it&#8217;s not just about how many emails you can send! For me, picking&nbsp;<strong>Enterprise Standard<\/strong>&nbsp;was absolutely essential because of the level of HIPAA security I was comfortable with.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Pro-Tip on Choosing a Platform:<\/strong>&nbsp;I actually considered Microsoft 365 Business plans, as they also offer BAAs. However, I was already using and familiar with Google&#8217;s interface. More importantly,&nbsp;<strong>I found it much easier to get clear information about Google&#8217;s BAA and HIPAA-included functionality upfront.<\/strong>&nbsp;Microsoft seems to hide their BAA documentation behind a subscriber wall, making it difficult to fully vet before committing. This ease of information access, combined with my familiarity, ultimately swayed my decision towards Google.&nbsp; Basically, it looks like any paid workspace can have a BAA:&nbsp; &nbsp;<a href=\"https:\/\/support.google.com\/a\/answer\/2888485?sjid=14092164238884574583-NC\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/support.google.com\/a\/answer\/2888485?sjid=14092164238884574583-NC<\/a><\/li>\n<\/ul>\n\n\n\n<p>Here\u2019s why I landed on it during my own HIPAA compliance trip, and what foundational elements it provides:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-the-non-negotiable-baa\"><strong>The Non-Negotiable BAA<\/strong><\/h4>\n\n\n\n<p>This was the top priority. Enterprise Standard definitely comes with a&nbsp;<strong>Business Associate Agreement (BAA)<\/strong>. This gives me that crucial legal agreement with Google to handle Protected Health Information. This is absolutely non-negotiable for anyone handling PHI with Google Workspace. (You can find Google&#8217;s BAA here:&nbsp;<em><a href=\"https:\/\/workspace.google.com\/terms\/2015\/1\/hipaa_baa\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/workspace.google.com\/terms\/2015\/1\/hipaa_baa\/<\/a><\/em>).<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Pro-Tip on Choosing a Tier<\/strong> &#8211;&nbsp;I actually started with the cheapest business tier (Business Starter $7\/mo), which I can confirm offers a BAA. However, after really digging into the features, I chose to upgrade to Enterprise Standard. It offered&nbsp;<strong>much better control over information and more robust policy enforcement options<\/strong>.  These ultimately felt essential for protecting client PHI effectively.&nbsp;&nbsp;<a href=\"https:\/\/workspace.google.com\/pricing.html?utm_source=google&amp;utm_medium=cpc&amp;utm_campaign=1710046-Workspace-DR-NA-US-en-Google-BKWS-sitelink&amp;utm_content=c-Hybrid+%7C+BKWS+-+MIX+%7C+Txt-Google+Workspace-Top-43700076441559576&amp;utm_term=google%20workspace%20cost&amp;gad_source=1&amp;gad_campaignid=20159848972&amp;gclid=Cj0KCQjwmqPDBhCAARIsADorxIYo7rdIj7qMVbdiL1ouVc1tXhZGsD0qfIzDt2J21ImymFsCjBe18s0aAgLjEALw_wcB&amp;gclsrc=aw.ds\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google Tiers &amp; Pricing<\/a>&nbsp;<\/li>\n\n\n\n<li><strong>Don&#8217;t Forget Your Domain Name!&nbsp;<\/strong>A domain name is an additional, but necessary, cost for any Google Workspace Business account. While Google offers to sell you one directly, I opted to buy my domain&nbsp;through Cloudflare for just $10.44\/year. This was a cost-effective choice since I already used Cloudflare for other services.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-serious-pooled-storage\">Serious Pooled Storage<\/h4>\n\n\n\n<p>Enterprise Standard offers a massive&nbsp;<strong>5 TB of pooled storage per user<\/strong>. (Just a heads-up: This pooled storage gets released in stages after payments, so my Drive initially showed less!). This is more than enough space for all my therapy materials and client files.<\/p>\n\n\n\n<div class=\"wp-block-media-text has-media-on-the-right is-stacked-on-mobile\" style=\"grid-template-columns:auto 25%\"><div class=\"wp-block-media-text__content\">\n<h4 class=\"wp-block-heading\" id=\"h-google-vault-for-ironclad-data-retention\">Google Vault for Ironclad Data Retention<\/h4>\n\n\n\n<p>This was a game-changer! Enterprise Standard includes&nbsp;<strong>Google Vault<\/strong>, which allows me to set an&nbsp;<strong>indefinite retention policy<\/strong>&nbsp;for all my Google data. This ensures I meet and exceed HIPAA&#8217;s minimum six-year data retention requirement. It\u2019s like a super-secure, always-on backup for everything.<\/p>\n<\/div><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"866\" height=\"1024\" src=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/06\/strongbox-154022_1280-1-866x1024.webp\" alt=\"A large, grey, rectangular safe with a circular combination dial and heavy bolted door, casting a shadow on a light grey floor.\" class=\"wp-image-724 size-full\" srcset=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/06\/strongbox-154022_1280-1-866x1024.webp 866w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/06\/strongbox-154022_1280-1-254x300.webp 254w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/06\/strongbox-154022_1280-1-768x908.webp 768w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/06\/strongbox-154022_1280-1.webp 1083w\" sizes=\"auto, (max-width: 866px) 100vw, 866px\" \/><\/figure><\/div>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-advanced-data-loss-prevention-dlp\">Advanced Data Loss Prevention (DLP)<\/h4>\n\n\n\n<p>This tier gives me access to advanced DLP rules for Gmail and Drive, which are central to my security strategy. These are the powerful rules that can warn me if I try to share sensitive files externally.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-comprehensive-security-controls\">Comprehensive Security Controls<\/h4>\n\n\n\n<p>Enterprise Standard unlocks a lot of the granular administrative controls I needed. This allowed me to configure things like forcing 2FA, setting strong password policies, and disabling third-party apps.<\/p>\n\n\n\n<p>Basically, for handling PHI and needing robust, auditable security features, Enterprise Standard provided the comprehensive toolkit I needed to feel confident and stay compliant. It&#8217;s an investment at $27\/mo, but one that\u2019s absolutely worth it for peace of mind and professional responsibility.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-the-core-pillars-of-my-personal-hipaa-compliance-policy\">The Core Pillars of My Personal HIPAA Compliance Policy:<\/h3>\n\n\n\n<p>Here&#8217;s a look at the specific configurations I implemented (See Google&#8217;s HIPAA Implementation Guide:&nbsp;&nbsp;<a href=\"https:\/\/services.google.com\/fh\/files\/misc\/gsuite_cloud_identity_hipaa_implementation_guide.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/services.google.com\/fh\/files\/misc\/gsuite_cloud_identity_hipaa_implementation_guide.pdf<\/a>):<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1. Bulletproof Access Control (Who Gets In? Only Me!)<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:35% auto\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1920\" height=\"1373\" src=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/secure-access-2fa.png\" alt=\"A digital illustration of a hand touching a &quot;Login&quot; button on a smartphone. The screen shows two password fields filled with asterisks and a shield icon at the top, indicating a secure login process.\" class=\"wp-image-2384 size-full\" srcset=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/secure-access-2fa.png 1920w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/secure-access-2fa-300x215.png 300w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/secure-access-2fa-1024x732.png 1024w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/secure-access-2fa-768x549.png 768w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/secure-access-2fa-1536x1098.png 1536w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/secure-access-2fa-1320x944.png 1320w\" sizes=\"auto, (max-width: 1920px) 100vw, 1920px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<ul class=\"wp-block-list\">\n<li><strong>2-Step Verification (2FA) is Mandatory:<\/strong>&nbsp;No exceptions! I enforced 2FA for all account access. This is your absolute best defense against unauthorized logins.<\/li>\n\n\n\n<li><strong>Strong Passwords, Always:<\/strong>&nbsp;My system enforces strong password policies, requiring a&nbsp;<strong>minimum length of 16 characters<\/strong>&nbsp;and prompting for a refresh every&nbsp;<strong>180 days<\/strong>. No weak links here!<\/li>\n<\/ul>\n<\/div><\/div>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Third-Party Apps? Deny by Default!<\/strong>&nbsp;My policy is strict: all third-party app access is blocked by default. If I ever need an app, it goes through a security review and is force-installed by me, the admin. This prevents unvetted apps from touching my client data.<\/li>\n\n\n\n<li><strong>Strictly BAA-Covered Services Only:<\/strong>&nbsp;As part of my setup, I went into my Google Admin Console and literally turned&nbsp;<strong>OFF<\/strong>&nbsp;any Google services that aren&#8217;t explicitly covered by the BAA (like Google Photos, YouTube, etc.). Why? To make sure no PHI accidentally ends up in a non-compliant service. (You can find a list of Google&#8217;s HIPAA Included Functionality and BAA-covered services here:&nbsp;<em><a href=\"https:\/\/workspace.google.com\/terms\/2015\/1\/hipaa_functionality\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/workspace.google.com\/terms\/2015\/1\/hipaa_functionality\/<\/a><\/em>).<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">2. Smart Data Protection (No Accidental Leaks!)<\/h4>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"200\" height=\"172\" src=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/06\/data-2998180_1280.webp\" alt=\"A bright blue digital folder icon with an orange padlock placed in front of it, symbolizing secure or locked digital files.\" class=\"wp-image-83\" style=\"width:252px;height:auto\"\/><figcaption class=\"wp-element-caption\">Locking down your digital files to prevent accidental data leaks.<\/figcaption><\/figure>\n<\/div>\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Gmail Content Compliance:<\/strong>&nbsp;I set up an automated rule in Gmail that quarantines any outbound email containing PHI-related keywords if it&#8217;s addressed to a domain not on my pre-approved &#8220;Trusted School Districts&#8221; list. It&#8217;s a huge safety net!<\/li>\n\n\n\n<li><strong>Drive DLP (Data Loss Prevention) Rule:<\/strong>&nbsp;For Google Drive, I have a rule that gives me a real-time warning if I ever try to externally share a file containing PHI keywords. It&#8217;s an extra &#8220;Are you sure?&#8221; before a potential mishap.<\/li>\n\n\n\n<li><strong>Always Use Secure Communication Channels:<\/strong>&nbsp;Beyond these automated rules, I always ensure that any direct client communication involving PHI occurs only through secure, HIPAA-compliant platforms (like my employer&#8217;s therapy portal).  I now&nbsp;<strong>avoid using regular email, text messages, or consumer video calls for sensitive information<\/strong>.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">3. Endpoint &amp; Browser Security (My Laptop &amp; Chrome)<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>My Laptop is Encrypted &amp; Protected:<\/strong>&nbsp;My main computer has full-disk encryption (BitLocker\/FileVault) and a robust antivirus solution. I&#8217;m currently using&nbsp;<strong>Norton Small Business ($59\/1st year with $119\/year renewal)<\/strong>&nbsp;for this, primarily for its strong endpoint protection. While I&#8217;m actively looking into BAA-covered antivirus and endpoint detection &amp; response (EDR) solutions, it&#8217;s been a real challenge to find providers willing to work with a single user. For now, Norton Business helps secure my device itself.  I had to specifically&nbsp;<strong>disable its cloud backup features<\/strong>&nbsp;to prevent any PHI from being stored on non-BAA servers.&nbsp; I&#8217;ve also upgraded my mouse to use&nbsp;<strong>Logi Bolt technology<\/strong>&nbsp;for a more secure wireless connection.<\/li>\n\n\n\n<li><strong>Physical Security for My Home Office:<\/strong>&nbsp;Beyond digital protection, I also ensure any limited physical PHI (like printed notes) is kept in a&nbsp;<strong>locked file box when unattended<\/strong>, and my work area is secured to prevent unauthorized access. I&#8217;ve even rearranged my office so that my&nbsp;<strong>computer screen is not visible from the doorway<\/strong>, even though I always make sure to close the door when I&#8217;m with clients.<\/li>\n\n\n\n<li><strong>Dedicated Chrome Profiles:<\/strong>&nbsp;This is a big one! I have separate Chrome browser profiles. One just for&nbsp;<strong>my professional W<\/strong>orkspace&nbsp;(where I handle PHI), and others for personal stuff or employer-provided Outlook\/therapy portals. This completely isolates data and workflows.\n<ul class=\"wp-block-list\">\n<li>Updated to add &#8211; I&#8217;ve now gone a step farther and added another Windows user to my computer.  This way all therapy stuff stays in the therapy user.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Chrome Policies Enforced:<\/strong>&nbsp;My professional Google Workspace Chrome profile has Enhanced Safe Browse, &#8220;Always use secure connections&#8221; (HTTPS), and strict extension blocking enforced by policy. This means my browser is secured from the top down.<\/li>\n\n\n\n<li><strong>Windows Settings Tuned:<\/strong>&nbsp;Beyond the basics, I dove into Windows settings to ensure my device is locked down. Strong PIN\/Windows Hello, Dynamic Lock (locks when I walk away), automatic screen lock, firewall active, and app permissions reviewed app-by-app.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">4. Tackling Existing Data &amp; Migration<\/h4>\n\n\n\n<p>This was a big project, especially for older files, and probably the hardest part in my HIPAA compliance trek!<\/p>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:39% auto\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1280\" height=\"1280\" src=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/data-migration-cloud-consolidation.png\" alt=\"An illustration of multiple yellow digital folders connected via lines to a central white cloud icon, with additional symbols for Wi-Fi, data sharing, and bidirectional data transfer, all on a grey background.\" class=\"wp-image-2385 size-full\" srcset=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/data-migration-cloud-consolidation.png 1280w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/data-migration-cloud-consolidation-300x300.png 300w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/data-migration-cloud-consolidation-1024x1024.png 1024w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/data-migration-cloud-consolidation-150x150.png 150w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/data-migration-cloud-consolidation-768x768.png 768w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<ul class=\"wp-block-list\">\n<li><strong>Consolidating All My Data (PHI &amp; Non-PHI):<\/strong>&nbsp;I meticulously went through&nbsp;<strong>all my files, both on my computer&#8217;s desktop and in my Drive<\/strong>.  I identified any possible PHI or general therapy materials. That data was then securely moved to&nbsp;<strong>my professional Drive<\/strong>, ensuring it was consolidated into my compliant environment.<\/li>\n\n\n\n<li><strong>No More OneDrive Sync:<\/strong>&nbsp;I&#8217;ve also&nbsp;<strong>disabled Microsoft OneDrive&#8217;s automatic PC folder backup<\/strong>.  I&#8217;m in the process of moving those files from the OneDrive synced location back to my local user&#8217;s root folders. This ensures no client data is inadvertently stored or synced to a non-BAA cloud service.<\/li>\n<\/ul>\n<\/div><\/div>\n\n\n\n<h5 class=\"wp-block-heading\" id=\"h-google-drive-settings-and-workarounds\">Google Drive Settings and Workarounds<\/h5>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Google Drive for Desktop (Strategically!):<\/strong>&nbsp;I used Google Drive for Desktop for efficiency with many files, but with a key rule. I keep it on&nbsp;<strong>&#8220;stream files&#8221; mode<\/strong>. This means files are only downloaded when I open them, minimizing PHI stored locally on my hard drive. I also keep its &#8220;offline access&#8221; feature for PHI files disabled in the Admin Console to prevent local copies, unless absolutely necessary and then with extreme care.<\/li>\n\n\n\n<li><strong>Native Google Docs\/Sheets\/Slides:<\/strong>&nbsp;This was tricky! I learned you can&#8217;t just drag-and-drop native Google files between different accounts using Drive for Desktop. For these, especially if they contained PHI, I had to&nbsp;<strong>download them in Microsoft Office format<\/strong>&nbsp;from my personal Drive.  Then I&nbsp;<strong>re-uploaded them<\/strong>&nbsp;to&nbsp;<strong>my professional Google Workspace Drive<\/strong>. This ensured ownership transferred correctly and, crucially, kept the PHI handling within my secured processes.<\/li>\n\n\n\n<li><strong>Unzipping Files:<\/strong>&nbsp;Since Google Drive doesn&#8217;t have a built-in unzipper, I securely downloaded ZIP files to my local, encrypted computer.  I unzipped them using Windows&#8217; built-in function, and then re-uploaded the extracted files to&nbsp;<strong>my professional Google Workspace Drive<\/strong>.<\/li>\n\n\n\n<li><strong>Disconnecting My Personal Drive:<\/strong>&nbsp;Once the transfer was done, I disconnected my personal Google Drive account from Google Drive for Desktop. Why? Fewer accounts connected equals less potential risk.<\/li>\n\n\n\n<li><strong>Cleaning Up My Personal Drive (Carefully!):<\/strong>&nbsp;After moving all PHI, I used a cloud cleaner like Norton Cloud Cleaner on my&nbsp;<em>personal<\/em>&nbsp;Google Drive to remove duplicates and old non-PHI files. <strong>NEVER<\/strong>&nbsp;use such a tool on&nbsp;any PHI files or folders due to compliance risks, if it&#8217;s not covered by a BAA.<\/li>\n<\/ul>\n\n\n\n<h5 class=\"wp-block-heading\" id=\"h-involving-others-in-my-personal-hippa-journey\">Involving Others in My Personal HIPPA Journey<\/h5>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Dealing with Shared PHI from Others:<\/strong>&nbsp;I found some old PHI-containing files in my personal Gmail&#8217;s &#8220;Shared with me&#8221; section, shared by a school district. I immediately downloaded these to&nbsp;<strong>my professional Google Workspace Drive<\/strong>,&nbsp;<strong>securely deleted them from my personal Drive and my local computer<\/strong>. Then I reached out to the owner (politely!) asking them to remove my personal Gmail from the access list. This is an&nbsp;<strong>active and ongoing effort<\/strong>&nbsp;where I&#8217;m proactively contacting owners to ensure my access is removed.  I&#8217;m&nbsp;<strong>documenting all my attempts<\/strong>&nbsp;as part of my due diligence, especially if I encounter non-responsive contacts or technical difficulties.<\/li>\n\n\n\n<li><strong>Updating My Employer:<\/strong>&nbsp;I proactively contacted my employer to update my email address for all Google Drive file sharing.  I specifically requested that anything with sensitive client info go to&nbsp;<strong>my new, secure professional email address (e.g., your.professional.email@yourdomain.com)<\/strong>. This helps them send things to the right place from the start.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">My Ongoing Commitment:<\/h3>\n\n\n\n<p>This isn&#8217;t a one-and-one project! I&#8217;ve also built in:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Annual Policy Review:<\/strong>&nbsp;I&#8217;ll review my entire security policy document at least once a year.<\/li>\n\n\n\n<li><strong>Self-Education:<\/strong>&nbsp;Staying informed about HIPAA and cybersecurity is an ongoing task. I&#8217;ve even been learning about specific processes like the&nbsp;<strong>HIPAA de-identification process<\/strong>.<\/li>\n\n\n\n<li><strong>Basic Incident Response:<\/strong>&nbsp;I have a plan for what to do if something ever goes wrong, including who to notify.<\/li>\n\n\n\n<li><strong>Learning Curve:<\/strong>&nbsp;I won&#8217;t lie, all these tech skills required some serious reading up and a lot of help (shout out to Gemini! \ud83d\ude09). It&#8217;s a journey, not a sprint, but totally doable!<\/li>\n<\/ul>\n\n\n\n<p>Setting all this up has been a journey, but it&#8217;s given me immense confidence in my practice&#8217;s security. If you&#8217;re an SLP (or any healthcare professional) using tech in your practice, I highly encourage you to take a look at your own setup. It&#8217;s worth every bit of effort for your peace of mind and, most importantly, for your clients&#8217; privacy!<\/p>\n\n\n\n<p>Here&#8217;s to HIPAA Happiness!<\/p>\n\n\n\n<div class=\"wp-block-group\"><div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\"><div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"810\" height=\"169\" src=\"https:\/\/i0.wp.com\/vmx.erb.mybluehost.me\/wp-content\/uploads\/2025\/07\/Mrs.-Speech-signature-transparent.webp?fit=810%2C169&amp;ssl=1\" alt=\"Mrs. Speech Signature\" class=\"wp-image-804\" style=\"width:364px;height:auto\" srcset=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/Mrs.-Speech-signature-transparent.webp 810w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/Mrs.-Speech-signature-transparent-300x63.webp 300w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/Mrs.-Speech-signature-transparent-768x160.webp 768w\" sizes=\"auto, (max-width: 810px) 100vw, 810px\" \/><\/figure>\n<\/div>\n\n\n<div class=\"wp-block-group is-content-justification-center is-nowrap is-layout-flex wp-container-core-group-is-layout-94bc23d7 wp-block-group-is-layout-flex\">\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/www.facebook.com\/profile.php?id=61556892726241\" target=\"_blank\" rel=\" nofollow noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" width=\"388\" height=\"398\" src=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/1-e1751811762918.webp\" alt=\"facebook icon\" class=\"wp-image-815\" style=\"width:48px\" srcset=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/1-e1751811762918.webp 388w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/1-e1751811762918-292x300.webp 292w\" sizes=\"auto, (max-width: 388px) 100vw, 388px\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/www.instagram.com\/mrs.speechonline\/\" target=\"_blank\" rel=\" nofollow noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" width=\"418\" height=\"408\" src=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/4-e1751812074939.webp\" alt=\"Instagram Icon\" class=\"wp-image-818\" style=\"width:50px\" srcset=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/4-e1751812074939.webp 418w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/4-e1751812074939-300x293.webp 300w\" sizes=\"auto, (max-width: 418px) 100vw, 418px\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/www.pinterest.com\/mrsspeechonline\/\" target=\"_blank\" rel=\" nofollow noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" width=\"413\" height=\"410\" src=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/2-e1751811897435.webp\" alt=\"pinterest icon\" class=\"wp-image-816\" style=\"width:50px\" srcset=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/2-e1751811897435.webp 413w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/2-e1751811897435-300x298.webp 300w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/2-e1751811897435-150x150.webp 150w\" sizes=\"auto, (max-width: 413px) 100vw, 413px\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/www.linkedin.com\/in\/jennifer-tillock-821999287\/\" target=\"_blank\" rel=\" nofollow noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" width=\"402\" height=\"402\" src=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/5-e1751812160224.webp\" alt=\"LinkedIn Icon\" class=\"wp-image-821\" style=\"width:50px\" srcset=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/5-e1751812160224.webp 402w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/5-e1751812160224-300x300.webp 300w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/5-e1751812160224-150x150.webp 150w\" sizes=\"auto, (max-width: 402px) 100vw, 402px\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"http:\/\/www.youtube.com\/@Mrs.Speech-wk4mr\" target=\"_blank\" rel=\" nofollow noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" width=\"429\" height=\"416\" src=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/3-e1751811991232.webp\" alt=\"YouTube icon\" class=\"wp-image-817\" style=\"width:50px\" srcset=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/3-e1751811991232.webp 429w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/3-e1751811991232-300x291.webp 300w\" sizes=\"auto, (max-width: 429px) 100vw, 429px\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><a href=\"https:\/\/www.teacherspayteachers.com\/store\/mrs-speech\" target=\"_blank\" rel=\" noreferrer noopener\"><img loading=\"lazy\" decoding=\"async\" width=\"423\" height=\"416\" src=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/6-e1751812225756.webp\" alt=\"TeachersPayTeachers Icon\" class=\"wp-image-822\" style=\"width:50px\" srcset=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/6-e1751812225756.webp 423w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/6-e1751812225756-300x295.webp 300w\" sizes=\"auto, (max-width: 423px) 100vw, 423px\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"414\" height=\"413\" src=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/social-icons-1-e1751812692319.webp\" alt=\"Mrs. Speech Books Icon\" class=\"wp-image-1322\" style=\"width:50px\" srcset=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/social-icons-1-e1751812692319.webp 414w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/social-icons-1-e1751812692319-300x300.webp 300w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/social-icons-1-e1751812692319-150x150.webp 150w\" sizes=\"auto, (max-width: 414px) 100vw, 414px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"387\" height=\"377\" src=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/7-e1751813665307.webp\" alt=\"MailTo Icon\" class=\"wp-image-1326\" style=\"width:50px\" srcset=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/7-e1751813665307.webp 387w, https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/7-e1751813665307-300x292.webp 300w\" sizes=\"auto, (max-width: 387px) 100vw, 387px\" \/><\/figure>\n<\/div>\n<\/div><\/div>\n\n\n\n<p class=\"icon-attribution\">\n    Social Media Icons: <a href=\"https:\/\/www.freepik.com\" target=\"_blank\" rel=\"noopener\">designed by rawpixel.com &#8211; Freepik.com<\/a>\n<\/p>\n\n\n\n<div style=\"height:47px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n<div style=\"color:#db820e;font-style:normal;font-weight:300\" class=\"taxonomy-post_tag has-text-align-center has-link-color wp-elements-e81afc2be6272024545412bcb750c79c wp-block-post-terms has-text-color\"><a href=\"https:\/\/mrsspeechonline.com\/staging\/2315\/tag\/business-associate-agreement\/\" rel=\"tag\">Business Associate Agreement<\/a><span class=\"wp-block-post-terms__separator\">, <\/span><a href=\"https:\/\/mrsspeechonline.com\/staging\/2315\/tag\/google\/\" rel=\"tag\">Google<\/a><span class=\"wp-block-post-terms__separator\">, <\/span><a href=\"https:\/\/mrsspeechonline.com\/staging\/2315\/tag\/google-workspace\/\" rel=\"tag\">Google Workspace<\/a><span class=\"wp-block-post-terms__separator\">, <\/span><a href=\"https:\/\/mrsspeechonline.com\/staging\/2315\/tag\/hipaa-security\/\" rel=\"tag\">HIPAA Security<\/a><span class=\"wp-block-post-terms__separator\">, <\/span><a href=\"https:\/\/mrsspeechonline.com\/staging\/2315\/tag\/home-office\/\" rel=\"tag\">Home Office<\/a><span class=\"wp-block-post-terms__separator\">, <\/span><a href=\"https:\/\/mrsspeechonline.com\/staging\/2315\/tag\/insights\/\" rel=\"tag\">Insights<\/a><span class=\"wp-block-post-terms__separator\">, <\/span><a href=\"https:\/\/mrsspeechonline.com\/staging\/2315\/tag\/microsoft\/\" rel=\"tag\">Microsoft<\/a><span class=\"wp-block-post-terms__separator\">, <\/span><a href=\"https:\/\/mrsspeechonline.com\/staging\/2315\/tag\/personal-journey\/\" rel=\"tag\">Personal Journey<\/a><span class=\"wp-block-post-terms__separator\">, <\/span><a href=\"https:\/\/mrsspeechonline.com\/staging\/2315\/tag\/technology\/\" rel=\"tag\">Technology<\/a><span class=\"wp-block-post-terms__separator\">, <\/span><a href=\"https:\/\/mrsspeechonline.com\/staging\/2315\/tag\/teletherapy\/\" rel=\"tag\">Teletherapy<\/a><span class=\"wp-block-post-terms__separator\">, <\/span><a href=\"https:\/\/mrsspeechonline.com\/staging\/2315\/tag\/tips\/\" rel=\"tag\">Tips<\/a><\/div>","protected":false},"excerpt":{"rendered":"<p>How I&#8217;m Making My Solo Practice HIPAA-Happy! Hey fellow SLPs and healthcare pros! Today, I want to share some insights from my personal journey towards HIPAA compliance. In my last two posts, we delved into the crucial topic of&nbsp;HIPAA compliance for telepractice. They covered the &#8220;what&#8221; and the &#8220;why.&#8221; Today, I want to share the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2383,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"nf_dc_page":"","footnotes":""},"categories":[914,916],"tags":[958,1022,1023,932,1031,954,1025,1015,1042,946,949],"class_list":["post-8","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-clinical-practice-management","category-compliance-ethics","tag-business-associate-agreement","tag-google","tag-google-workspace","tag-hipaa-security","tag-home-office","tag-insights","tag-microsoft","tag-personal-journey","tag-technology","tag-teletherapy","tag-tips"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.7.1 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Personal HIPAA Compliance Journey: My Insights - Mrs. Speech Online<\/title>\n<meta name=\"description\" content=\"Discover the key lessons from my personal HIPAA compliance journey and enhance your telepractice with practical insights.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/mrsspeechonline.com\/staging\/2315\/personal-hipaa-compliance-journey\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"My Personal HIPAA Compliance Journey: Steps to Secure Data\" \/>\n<meta property=\"og:description\" content=\"Discover the key lessons from my personal HIPAA compliance journey and enhance your telepractice with practical insights.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/mrsspeechonline.com\/staging\/2315\/personal-hipaa-compliance-journey\/\" \/>\n<meta property=\"og:site_name\" content=\"Mrs. Speech Online\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/profile.php?id=61556892726241\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/profile.php?id=61556892726241\" \/>\n<meta property=\"article:published_time\" content=\"2025-08-12T17:22:16+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/HIPAA-Me-Shield.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1350\" \/>\n\t<meta property=\"og:image:height\" content=\"1350\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Jennifer\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jennifer\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"14 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"TechArticle\",\"@id\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/personal-hipaa-compliance-journey\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/personal-hipaa-compliance-journey\\\/\"},\"author\":{\"name\":\"Jennifer\",\"@id\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/#\\\/schema\\\/person\\\/05d8350c5dc28f8b1a02cfd86462c22b\"},\"headline\":\"My Personal HIPAA Compliance Journey: Steps to Secure Data\",\"datePublished\":\"2025-08-12T17:22:16+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/personal-hipaa-compliance-journey\\\/\"},\"wordCount\":2614,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/#\\\/schema\\\/person\\\/05d8350c5dc28f8b1a02cfd86462c22b\"},\"image\":{\"@id\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/personal-hipaa-compliance-journey\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/HIPAA-Me-Shield.png\",\"keywords\":[\"Business Associate Agreement\",\"Google\",\"Google Workspace\",\"HIPAA Security\",\"Home Office\",\"Insights\",\"Microsoft\",\"Personal Journey\",\"Technology\",\"Teletherapy\",\"Tips\"],\"articleSection\":[\"Clinical\",\"Compliance &amp; Ethics\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/personal-hipaa-compliance-journey\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/personal-hipaa-compliance-journey\\\/\",\"url\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/personal-hipaa-compliance-journey\\\/\",\"name\":\"Personal HIPAA Compliance Journey: My Insights - Mrs. Speech Online\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/personal-hipaa-compliance-journey\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/personal-hipaa-compliance-journey\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/HIPAA-Me-Shield.png\",\"datePublished\":\"2025-08-12T17:22:16+00:00\",\"description\":\"Discover the key lessons from my personal HIPAA compliance journey and enhance your telepractice with practical insights.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/personal-hipaa-compliance-journey\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/personal-hipaa-compliance-journey\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/personal-hipaa-compliance-journey\\\/#primaryimage\",\"url\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/HIPAA-Me-Shield.png\",\"contentUrl\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/HIPAA-Me-Shield.png\",\"width\":1350,\"height\":1350,\"caption\":\"Securing patient data: My personal journey to HIPAA compliance at home. \u00a9 2025 Jennifer Tillock, Mrs. Speech LLC\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/personal-hipaa-compliance-journey\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Clinical\",\"item\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/category\\\/clinical-practice-management\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Compliance &amp; Ethics\",\"item\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/category\\\/clinical-practice-management\\\/compliance-ethics\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"My Personal HIPAA Compliance Journey: Steps to Secure Data\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/#website\",\"url\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/\",\"name\":\"Mrs. Speech Online\",\"description\":\"Tips &amp; Resources for SLPs and Educators (Excuse our dust, our gnomes are renovating!)\",\"publisher\":{\"@id\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/#\\\/schema\\\/person\\\/05d8350c5dc28f8b1a02cfd86462c22b\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/#\\\/schema\\\/person\\\/05d8350c5dc28f8b1a02cfd86462c22b\",\"name\":\"Jennifer\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/mrs-speech-online-website-banner.webp\",\"url\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/mrs-speech-online-website-banner.webp\",\"contentUrl\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/mrs-speech-online-website-banner.webp\",\"width\":1920,\"height\":553,\"caption\":\"Jennifer\"},\"logo\":{\"@id\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/mrs-speech-online-website-banner.webp\"},\"sameAs\":[\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/staging\\\/2315\",\"https:\\\/\\\/www.facebook.com\\\/profile.php?id=61556892726241\",\"https:\\\/\\\/www.instagram.com\\\/mrs.speechonline\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/jennifer-tillock-821999287\\\/\",\"https:\\\/\\\/www.pinterest.com\\\/mrsspeechonline\\\/\",\"http:\\\/\\\/www.youtube.com\\\/@Mrs.Speech-wk4mr\"],\"url\":\"https:\\\/\\\/mrsspeechonline.com\\\/staging\\\/2315\\\/author\\\/jennifer\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Personal HIPAA Compliance Journey: My Insights - Mrs. Speech Online","description":"Discover the key lessons from my personal HIPAA compliance journey and enhance your telepractice with practical insights.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/mrsspeechonline.com\/staging\/2315\/personal-hipaa-compliance-journey\/","og_locale":"en_US","og_type":"article","og_title":"My Personal HIPAA Compliance Journey: Steps to Secure Data","og_description":"Discover the key lessons from my personal HIPAA compliance journey and enhance your telepractice with practical insights.","og_url":"https:\/\/mrsspeechonline.com\/staging\/2315\/personal-hipaa-compliance-journey\/","og_site_name":"Mrs. Speech Online","article_publisher":"https:\/\/www.facebook.com\/profile.php?id=61556892726241","article_author":"https:\/\/www.facebook.com\/profile.php?id=61556892726241","article_published_time":"2025-08-12T17:22:16+00:00","og_image":[{"width":1350,"height":1350,"url":"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/HIPAA-Me-Shield.png","type":"image\/png"}],"author":"Jennifer","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Jennifer","Est. reading time":"14 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"TechArticle","@id":"https:\/\/mrsspeechonline.com\/staging\/2315\/personal-hipaa-compliance-journey\/#article","isPartOf":{"@id":"https:\/\/mrsspeechonline.com\/staging\/2315\/personal-hipaa-compliance-journey\/"},"author":{"name":"Jennifer","@id":"https:\/\/mrsspeechonline.com\/staging\/2315\/#\/schema\/person\/05d8350c5dc28f8b1a02cfd86462c22b"},"headline":"My Personal HIPAA Compliance Journey: Steps to Secure Data","datePublished":"2025-08-12T17:22:16+00:00","mainEntityOfPage":{"@id":"https:\/\/mrsspeechonline.com\/staging\/2315\/personal-hipaa-compliance-journey\/"},"wordCount":2614,"commentCount":0,"publisher":{"@id":"https:\/\/mrsspeechonline.com\/staging\/2315\/#\/schema\/person\/05d8350c5dc28f8b1a02cfd86462c22b"},"image":{"@id":"https:\/\/mrsspeechonline.com\/staging\/2315\/personal-hipaa-compliance-journey\/#primaryimage"},"thumbnailUrl":"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/HIPAA-Me-Shield.png","keywords":["Business Associate Agreement","Google","Google Workspace","HIPAA Security","Home Office","Insights","Microsoft","Personal Journey","Technology","Teletherapy","Tips"],"articleSection":["Clinical","Compliance &amp; Ethics"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/mrsspeechonline.com\/staging\/2315\/personal-hipaa-compliance-journey\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/mrsspeechonline.com\/staging\/2315\/personal-hipaa-compliance-journey\/","url":"https:\/\/mrsspeechonline.com\/staging\/2315\/personal-hipaa-compliance-journey\/","name":"Personal HIPAA Compliance Journey: My Insights - Mrs. Speech Online","isPartOf":{"@id":"https:\/\/mrsspeechonline.com\/staging\/2315\/#website"},"primaryImageOfPage":{"@id":"https:\/\/mrsspeechonline.com\/staging\/2315\/personal-hipaa-compliance-journey\/#primaryimage"},"image":{"@id":"https:\/\/mrsspeechonline.com\/staging\/2315\/personal-hipaa-compliance-journey\/#primaryimage"},"thumbnailUrl":"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/HIPAA-Me-Shield.png","datePublished":"2025-08-12T17:22:16+00:00","description":"Discover the key lessons from my personal HIPAA compliance journey and enhance your telepractice with practical insights.","breadcrumb":{"@id":"https:\/\/mrsspeechonline.com\/staging\/2315\/personal-hipaa-compliance-journey\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/mrsspeechonline.com\/staging\/2315\/personal-hipaa-compliance-journey\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/mrsspeechonline.com\/staging\/2315\/personal-hipaa-compliance-journey\/#primaryimage","url":"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/HIPAA-Me-Shield.png","contentUrl":"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/HIPAA-Me-Shield.png","width":1350,"height":1350,"caption":"Securing patient data: My personal journey to HIPAA compliance at home. \u00a9 2025 Jennifer Tillock, Mrs. Speech LLC"},{"@type":"BreadcrumbList","@id":"https:\/\/mrsspeechonline.com\/staging\/2315\/personal-hipaa-compliance-journey\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/mrsspeechonline.com\/staging\/2315\/"},{"@type":"ListItem","position":2,"name":"Clinical","item":"https:\/\/mrsspeechonline.com\/staging\/2315\/category\/clinical-practice-management\/"},{"@type":"ListItem","position":3,"name":"Compliance &amp; Ethics","item":"https:\/\/mrsspeechonline.com\/staging\/2315\/category\/clinical-practice-management\/compliance-ethics\/"},{"@type":"ListItem","position":4,"name":"My Personal HIPAA Compliance Journey: Steps to Secure Data"}]},{"@type":"WebSite","@id":"https:\/\/mrsspeechonline.com\/staging\/2315\/#website","url":"https:\/\/mrsspeechonline.com\/staging\/2315\/","name":"Mrs. Speech Online","description":"Tips &amp; Resources for SLPs and Educators (Excuse our dust, our gnomes are renovating!)","publisher":{"@id":"https:\/\/mrsspeechonline.com\/staging\/2315\/#\/schema\/person\/05d8350c5dc28f8b1a02cfd86462c22b"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/mrsspeechonline.com\/staging\/2315\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/mrsspeechonline.com\/staging\/2315\/#\/schema\/person\/05d8350c5dc28f8b1a02cfd86462c22b","name":"Jennifer","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/mrs-speech-online-website-banner.webp","url":"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/mrs-speech-online-website-banner.webp","contentUrl":"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/mrs-speech-online-website-banner.webp","width":1920,"height":553,"caption":"Jennifer"},"logo":{"@id":"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-content\/uploads\/2025\/07\/mrs-speech-online-website-banner.webp"},"sameAs":["https:\/\/mrsspeechonline.com\/staging\/2315\/staging\/2315","https:\/\/www.facebook.com\/profile.php?id=61556892726241","https:\/\/www.instagram.com\/mrs.speechonline\/","https:\/\/www.linkedin.com\/in\/jennifer-tillock-821999287\/","https:\/\/www.pinterest.com\/mrsspeechonline\/","http:\/\/www.youtube.com\/@Mrs.Speech-wk4mr"],"url":"https:\/\/mrsspeechonline.com\/staging\/2315\/author\/jennifer\/"}]}},"_links":{"self":[{"href":"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-json\/wp\/v2\/posts\/8","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-json\/wp\/v2\/comments?post=8"}],"version-history":[{"count":16,"href":"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-json\/wp\/v2\/posts\/8\/revisions"}],"predecessor-version":[{"id":2387,"href":"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-json\/wp\/v2\/posts\/8\/revisions\/2387"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-json\/wp\/v2\/media\/2383"}],"wp:attachment":[{"href":"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-json\/wp\/v2\/media?parent=8"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-json\/wp\/v2\/categories?post=8"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mrsspeechonline.com\/staging\/2315\/wp-json\/wp\/v2\/tags?post=8"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}