HIPAA Security Risk Analysis
Annual Security Risk Analysis as required under HIPAA Security Rule §164.308(a)(1). Documentation you can hand to an auditor.
Your clients trust you with their most sensitive information. We make sure the technology protects that trust, with HIPAA-aligned infrastructure, 42 CFR Part 2 awareness, secure telehealth, protected EHR access, and same-day support when something breaks.
Clinics, imaging, and ambulatory groups have their own page, without the 42 CFR Part 2 layer.
This vertical carries a heavier compliance load than most healthcare settings. Generic providers either over-promise on compliance or quietly avoid the subject.
Annual Security Risk Analysis as required under HIPAA Security Rule §164.308(a)(1). Documentation you can hand to an auditor.
Support for common behavioral health platforms including SimplePractice, TherapyNotes, and Valant. Access controls, MFA, and audit logging.
Zoom for Healthcare, Doxy.me, and Microsoft Teams for Healthcare, deployed with signed BAAs and clinician-friendly workflows.
Microsoft 365 Business Premium or Google Workspace Business Plus set up for encrypted email, DLP rules for PHI, and a signed platform BAA.
Intake forms, consents, and assessments delivered through HIPAA-compliant platforms. No email attachments, no public file links.
Written incident response plan aligned to the HIPAA Breach Notification Rule and Wisconsin Stat. §134.98. Contact tree, counsel identified, insurance liaison.
Administrative, physical, and technical safeguards for electronic PHI. Annual risk analysis is mandatory and breach notification timelines are strict.
If you treat substance use disorders, Part 2 sits on top of HIPAA with stricter consent and record-segregation rules. Many practices miss it entirely.
The state breach notification standard for personal information of Wisconsin residents, layered on top of federal HIPAA obligations. Notification timing matters.
We are IT professionals, not legal counsel. Compliance obligations should be reviewed with a qualified healthcare attorney. We configure and maintain the technical and administrative safeguards under your practice's responsibility.
What drives the number: clinician and staff count, EHR complexity, telehealth volume, and how many locations you run. You get an itemized quote after a 15-minute discovery call, with the assumptions written out so you can see what would change it. Rates and inclusions for the underlying service are on Managed IT Services.
Yes. We sign a Business Associate Agreement with every behavioral health and healthcare client before we handle any system that touches PHI. A provider who will not sign one is telling you something.
Breach obligations do not scale down with practice size. A solo clinician with one staff member answers to the same Breach Notification Rule as a large group. Small practices usually have fewer controls in place, which makes a reportable event more likely, not less. Our packages are scoped for practices of 1–20 clinicians.
We support the common behavioral health platforms including SimplePractice, TherapyNotes, Valant, and Therabill. We do not replace your EHR. We secure how the practice reaches it, through MFA, access reviews, session timeouts, and audit logging.
We deploy and support HIPAA-compliant platforms, meaning Zoom for Healthcare, Doxy.me, and Microsoft Teams for Healthcare, each with a signed vendor BAA. We do not recommend consumer Zoom, FaceTime, or standard Google Meet for clinical sessions.
Part 2 records need to stay segregated and disclosure needs to be consent-aware, which pushes past what HIPAA alone asks for. In practice that means tighter access boundaries, closer attention to where records get copied, and logging that shows who saw what. The broader security stack behind it lives on Cybersecurity & Compliance.
A short review of your top risks, ending with a prioritized action list you keep and can use with any provider.