
As I visit with providers, I discover managers that are not well educated in the HIPAA process, and do not understand they are required to do an annual Security Risk Audit and review of their practice even if they do not have an EMR, writes Carol Gibbons in her latest blog.

