Search
magnifying-glass
The Encrypted Chart
Log in
Subscribe
Home
Archive
The Encrypted Chart
Oliver Buchannon
Brad Lieberman

Practicing PMHNP with a Juris Doctor (retired). The Encrypted Chart is operational privacy guidance for solo and small-group healthcare practice — the shields you'd have if you had a hospital's compliance team.

Add social links

Intake Forms and Consent

+2

Your Privacy Notice May Describe a Rule That No Longer Exists

Aug 11, 2026

•

4 min read

Your Privacy Notice May Describe a Rule That No Longer Exists

A federal rule was struck down, New York got stricter, and nothing on your forms said a word. Introducing Compliance Watch.

Brad Lieberman
Brad Lieberman

Practice Security

+2

The Annual HIPAA Risk Assessment: Why It Exists and Why One Click in Illinois Just Made It Urgent

Aug 8, 2026

•

4 min read

The Annual HIPAA Risk Assessment: Why It Exists and Why One Click in Illinois Just Made It Urgent

Fourteen investigations, one missing document, and the quietest four weeks of your working year.

Brad Lieberman
Brad Lieberman

Practice Security

+1

I Bolted a Hard Drive to a Desk That Moves Up and Down

Aug 4, 2026

•

7 min read

I Bolted a Hard Drive to a Desk That Moves Up and Down

A moving day, a screwdriver, and the part of HIPAA nobody writes about

Brad Lieberman
Brad Lieberman

Intake Forms and Consent

+1

The Forms That Started All of This

Jul 15, 2026

•

3 min read

The Forms That Started All of This

Before the newsletter, before the Vault, there was a set of intake forms that should have been fine. This is where all of it started.

Brad Lieberman
Brad Lieberman

Intake Forms and Consent

+1

Telehealth and Digital Communication Consent: Why It Exists and Why the Talkspace Case Just Made It Urgent

Jul 7, 2026

•

4 min read

Telehealth and Digital Communication Consent: Why It Exists and Why the Talkspace Case Just Made It Urgent

HIPAA binds you, not your client. When a patient records a session, or a platform quietly stores every word, the law that governs is not the one you reach for first. Here is the consent language that sets the rules before the recording starts.

Brad Lieberman
Brad Lieberman

Intake Forms and Consent

+2

AI Scribes: Four States Now Require Patient Opt-Out

Jun 30, 2026

•

5 min read

AI Scribes: Four States Now Require Patient Opt-Out

If you run an AI scribe, the question isn't whether you got consent today. It's whether your consent paperwork survives the law your state is about to pass.

Brad Lieberman
Brad Lieberman

Intake Forms and Consent

+1

Your practice name, already on every page

Jun 26, 2026

•

1 min read

Your practice name, already on every page

The Private Practice Protection Vault now arrives personalized to your practice, and stays current as the rules change.

Brad Lieberman
Brad Lieberman

Practice Security

+1

No One Hacked Your EHR. They Just Logged In.

Jun 24, 2026

•

3 min read

No One Hacked Your EHR. They Just Logged In.

In June, researchers found a database of 24 billion stolen passwords, most of it freshly lifted off infected personal devices. Here is how a solo practice's EHR login lands in it, and why "remember this device for 30 days" quietly cancels the MFA you were counting on.

Brad Lieberman
Brad Lieberman

HIPAA Compliance

+1

Two Breaches, One Question: When Does Your Clock Start?

Jun 20, 2026

•

4 min read

Two Breaches, One Question: When Does Your Clock Start?

Two breaches hit the news this week, but the part that matters for your practice is not the headline. It is one question hiding in the HIPAA notification rule: when does your sixty-day clock actually start.

Brad Lieberman
Brad Lieberman

Practice Security

+2

The Email Habits That Just Cost a Mental Health Practice $900,000

Jun 13, 2026

•

5 min read

The Email Habits That Just Cost a Mental Health Practice $900,000

A Massachusetts behavioral health center settled a class action this week for $900,000 over a breach that started with one phished email account. A national legal alert published two days ago explains how a routine group email becomes a reportable HIPAA event. Both stories point at the same form most solo therapy practices don't have.

Brad Lieberman
Brad Lieberman

Practice Security

+1

Three Breaches Last Month. All Started With One Email

Jun 9, 2026

•

6 min read

Three Breaches Last Month. All Started With One Email

The Acadia Healthcare notice that went out May 22, the Genesis ransomware that hit an independent California cardiology practice, and the 35,000-account phishing campaign Microsoft tracked in April. Same fact pattern, three different scales. The attackers did not break in. They logged in.

Brad Lieberman
Brad Lieberman

Vendor and BAA Risk

+1

Your Vendor's Breach Just Became Your Lawsuit.

Jun 2, 2026

•

4 min read

Your Vendor's Breach Just Became Your Lawsuit.

A federal court in Chicago ruled last week that patients can sue a healthcare provider over a vendor's data breach. The diligence defense — "they were reputable, they had certifications, I trusted them" — just got materially narrower.

Brad Lieberman
Brad Lieberman

HIPAA Compliance

+1

$900,000 for the 72 Hours You Didn't Plan For

May 30, 2026

•

6 min read

$900,000 for the 72 Hours You Didn't Plan For

A Small OB/GYN practice just paid $900,000 to settle a class action over a four-day breach in 2022. The breach itself wasn't extraordinary — what made it expensive was what happened next. Here's the operational document most independent practices don't have, and why it's the difference between $0 and seven figures.

Brad Lieberman
Brad Lieberman

HIPAA Compliance

+1

California Just Reached Into Your Out-of-State Practice.

May 26, 2026

•

4 min read

California Just Reached Into Your Out-of-State Practice.

A California Supreme Court ruling last week makes it easier to sue any practice that holds a California resident's medical records — including the records of patients who moved there years ago and you haven't seen since.

Brad Lieberman
Brad Lieberman

Intake Forms and Consent

+1

Your Forms Predate the 42 CFR Part 2 Update. So Did Mine.

May 23, 2026

•

6 min read

Your Forms Predate the 42 CFR Part 2 Update. So Did Mine.

This weekend I sat down to audit my own NPP and intake consent against the 42 CFR Part 2 Final Rule. I found gaps. Here's what I found, how I'm fixing them by Tuesday morning, and the same audit you can run on yours.

Brad Lieberman
Brad Lieberman

HIPAA Compliance

+1

$245,000 for the Form You Don't Have

May 19, 2026

•

4 min read

$245,000 for the Form You Don't Have

OCR fined five practices a combined $1.41 million in the past two weeks. The common thread wasn't sophisticated hacking. It was a missing annual document. Here's why solo and small-group practices should be reading their own compliance paperwork this week.

Brad Lieberman
Brad Lieberman

Practice Security

+1

Your Website Is Probably Leaking Patient Data to TikTok and Meta.

May 16, 2026

•

5 min read

Your Website Is Probably Leaking Patient Data to TikTok and Meta.

Bloomberg just confirmed every state-run health insurance exchange in America is doing it. The same tracking pixels sit on most practice websites. Here's the operational audit that closes the gap this week.

Brad Lieberman
Brad Lieberman

Intake Forms and Consent

+2

Sutter's AI Scribe Just Got Sued. You Use the Same Tool.

May 12, 2026

•

4 min read

Sutter's AI Scribe Just Got Sued. You Use the Same Tool.

Three California health systems just got named in a class action over how they record patient visits with an AI scribe. The lawsuit isn't HIPAA. Your vendor's contract doesn't cover it. Here's the gap and what to check this week.

Brad Lieberman
Brad Lieberman

Vendor and BAA Risk

+2

When Your Billing Service Gets Hacked: A $225K Federal Wake-Up Call

May 9, 2026

•

7 min read

When Your Billing Service Gets Hacked: A $225K Federal Wake-Up Call

If your billing service got hacked tomorrow, what does the contract you signed with them actually say? Last month the federal government fined a vendor in that exact pattern $225,000. Here's what to read this week — before it's your patients calling.

Brad Lieberman
Brad Lieberman

Vendor and BAA Risk

+1

Five Questions Hospital Compliance Officers Ask About AI Scribes — and Solo Practices Don't

May 6, 2026

•

8 min read

Five Questions Hospital Compliance Officers Ask About AI Scribes — and Solo Practices Don't

The institutional version of this conversation happens before the contract is signed. The independent version happens after the breach. Here's the operational protocol that bridges them.

Brad Lieberman
Brad Lieberman

The Encrypted Chart

Join the list to receive our newest posts straight to your inbox.

The Encrypted Chart

Home

Subscribe

Archive

Login

Reset Password

Update Password

Profile

Search

© 2026 The Encrypted Chart · The Encrypted Chart is published by Lieberman Consulting, LLC, a consulting firm — not a law firm. Content is educational, not legal advice..
beehiivPowered by beehiiv