HIPAA Security Risk Analysis
Annual Security Risk Analysis as required under HIPAA Security Rule §164.308(a)(1). Documented findings you can hand to an auditor.
Patient care does not pause for a network outage. Your EHR, imaging, scheduling, and patient messaging all have to just work. We handle that with HIPAA-aligned infrastructure, tested backups, signed BAAs, and same-day response.
Therapy, psychiatry, and substance use programs carry 42 CFR Part 2 on top of HIPAA. That has its own page.
Annual Security Risk Analysis as required under HIPAA Security Rule §164.308(a)(1). Documented findings you can hand to an auditor.
Support for common ambulatory EHR platforms. Access controls, MFA, session timeouts, and audit logging, without breaking clinician workflows.
Zoom for Healthcare, Microsoft Teams for Healthcare, and Doxy.me, deployed with signed BAAs and clinician-friendly setup.
Encrypted email for PHI, DLP rules that flag outbound PHI, a BAA with the email platform, and external-sender banners to cut impersonation.
Immutable cloud backups for EHR export files, mailboxes, and on-premises systems. Tested quarterly, with documented RTO and RPO.
Clinician, guest, and medical-device networks kept separate. Wi-Fi engineered for the whole footprint, not just reception, with redundant internet where patient messaging depends on it.
We produce and maintain the technical artifacts that answer these questions, not the legal or policy ones. HIPAA compliance is shared between the practice, its counsel, and its IT provider.
What drives the number: how many clinicians and staff you have, how complex your EHR environment is, clinical device count, how many locations you run, and how much compliance overhead you carry. We scope it specifically after a discovery call and put it in writing before you commit to anything, so there are no surprise line items. Rates and inclusions for the underlying service live on Managed IT Services.
Yes. We sign a BAA before we touch any system that stores or transmits ePHI. We also help you confirm that your other vendors have one on file, since that is one of the first things an auditor asks for.
We support common ambulatory EHR platforms at the access and infrastructure layer: identity, MFA, session timeouts, audit logging, endpoint health, and connectivity. Application-level configuration stays with your EHR vendor. We work alongside them rather than replacing them.
Annually, as required under the HIPAA Security Rule at §164.308(a)(1). You get documented findings you can hand to an auditor, along with a prioritized list of what to fix first.
Zoom for Healthcare, Microsoft Teams for Healthcare, and Doxy.me, each with a signed BAA in place and a setup your clinicians will actually use.
No. We build, document, and maintain the technical safeguards. Policies, workforce sanctions, and legal interpretation sit with the practice and its counsel. The split matters, and any IT provider claiming otherwise is overselling.
Thirty minutes on your top HIPAA risks, ending with a prioritized action list you keep whether or not you hire us. If you want the broader security picture, see Cybersecurity & Compliance.
Thirty minutes on your top risks, ending with a prioritized action list. You keep the list either way.