It is technologically agnostic, because it applies whether your doctor is fully remote and everything uses electronic records, or if the provider is still using pen and paper and carrier pigeons.
For actual security details, there may be some regulations with the change to the mandating of electronic records, but nothing in HIPAA ourself. For that, you want to look for organizations that have a certification like SOC2 or similar.
Okay, great. So which employees were held personally liable for these two breeches? I got "The Letter" telling me I was one of the victims for both of them.
https://www.hhs.gov/hipaa/for-professionals/compliance-enfor...
How about the 18 standards labelled A) through R) in page 97 of: https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/ad...
I am no expert but HIPPA seems far more prescriptive than say GDPR or PII regulations.
I do agree that self-certification leads to perverse incentives and lowers the bar