Skip to main content

Software, apps, websites, networks and AI automation

HIPAA Compliance & Security Risk Analysis

Security Rule risk analysis, remediation and documentation for practices and health tech vendors.

HIPAA Compliance & Security Risk Analysis

HIPAA Compliance & Security Risk Analysis

The HIPAA Security Rule requires every covered entity and business associate to conduct an accurate and thorough risk analysis of the confidentiality, integrity and availability of the electronic protected health information it holds, and to act on what that analysis finds. It is not a one-time form. It is a documented review of where ePHI lives, what threats and vulnerabilities apply to each place it lives, how likely and how damaging each one is, and what you are doing about it. There is no official government HIPAA certification, so no vendor can make you certified. What you can have is a defensible risk analysis, a risk management plan, written policies, signed business associate agreements and evidence that you followed through. Cost is driven by how many systems and locations hold ePHI, how many vendors touch it, whether you have current policies and prior analyses to build on, how much of the remediation you want us to perform versus do yourself, and whether an independent third-party assessment is required by a contract or a payer. Ranges vary widely for exactly those reasons, and any firm quoting a flat price before scoping your environment is guessing.

We work with medical and dental practices, behavioral health and therapy groups, billing companies, and health tech vendors that need to answer security questionnaires from hospital and payer customers. The engagement starts with an inventory of every system that creates, receives, maintains or transmits ePHI, including the ones nobody lists on the first pass, such as scanners, text reminder tools, personal phones, backup drives and the cloud accounts a staff member set up years ago. From there we run the analysis, rate the risks, and produce a risk management plan you can actually execute. We also do the remediation. Because we build and run networks, servers, workstations and line-of-business software for small and mid-sized businesses, we can close the findings ourselves rather than hand you a report and leave. That includes access controls, encryption, logging and log review, backup and recovery testing, email and endpoint hardening, offboarding procedures, workforce training, and the business associate agreements that are missing or outdated. Where a contract or regulator requires an independent assessment body, we deliver that portion with accredited partners and keep our own role on the remediation side.

What We Offer

Full ePHI inventory across systems, devices and cloud
Security Rule risk analysis with rated findings
Risk management plan mapped to each finding
Administrative, physical and technical safeguard review
Business associate agreement review and tracking
Written policies and procedures your staff can follow
Workforce training and sanction policy support
Remediation performed by our own engineers

Our Process

1
Scoping

We walk through your practice or product to learn how many locations, systems, vendors and users touch ePHI before we quote anything.

2
ePHI inventory

We map every place protected health information is created, received, stored or transmitted, including devices and accounts outside the official list.

3
Risk analysis

We identify threats and vulnerabilities for each asset, assess likelihood and impact, and document the reasoning behind each rating.

4
Risk management plan

We turn the findings into a prioritized plan with owners, target dates and a clear distinction between quick fixes and capital projects.

5
Remediation

We implement the technical and administrative fixes ourselves or alongside your staff, and update policies to match what actually happens.

6
Review cycle

We revisit the analysis on a regular schedule and after any material change, such as a new system, new location or new vendor.

7

Key Benefits

  • A defensible answer when a regulator or payer asks
  • Findings fixed, not just listed in a report
  • Clear scope before you commit to a price
  • Security questionnaires you can complete honestly
  • Documentation that survives staff turnover
  • One firm for the analysis and the IT work

Technologies

HIPAA Security Rule HIPAA Privacy Rule HITECH Breach Notification Rule NIST SP 800-66 NIST SP 800-30 OCR Audit Protocol NIST Cybersecurity Framework CIS Controls
Benefits

Frequently Asked Questions

No. The federal government does not certify practices or vendors as HIPAA compliant, and no company can grant you an official HIPAA certification. What exists is the required risk analysis, a risk management plan, policies, agreements and evidence that you followed them. Some vendors sell a certificate or seal, but it carries no regulatory weight on its own.
The Security Rule requires an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of the ePHI you hold. In practice that means inventorying where ePHI lives, identifying threats and vulnerabilities for each location, rating likelihood and impact, documenting the analysis, and then implementing measures to reduce risk to a reasonable level. It has to be updated when things change, not filed once and forgotten.
It depends on scope, and anyone quoting a flat price before looking at your environment is guessing. The main drivers are how many locations and systems hold ePHI, how many vendors and integrations touch it, whether you already have policies and a prior analysis to build on, how much remediation is needed, and whether a payer or contract requires an independent third-party assessment. We scope first and then quote, so you know what you are paying for.
At minimum: an inventory of all ePHI systems and devices, access controls and unique user IDs, encryption at rest and in transit, audit logging and who reviews it, backup and tested recovery, physical security, mobile and remote access, vendor and business associate agreements, workforce training, onboarding and offboarding procedures, and an incident response and breach notification plan. A checklist alone is not the analysis, though. The analysis is the reasoning about likelihood and impact that the checklist feeds.
A business associate agreement is a written contract between a covered entity and any vendor that creates, receives, maintains or transmits ePHI on its behalf, covering how that vendor safeguards the data and what happens after a breach. Billing companies, IT providers, cloud hosting, transcription services, shredding companies and many software vendors typically need one. Missing or expired agreements are one of the most common gaps we find in small practices.
Usually the same short list: no current risk analysis or one that was never updated, shared logins, backups that have never been restore-tested, ePHI on personal devices or in personal email, missing business associate agreements, no log review, staff who still have access months after leaving, and policies that describe a workflow nobody actually uses. None of these are exotic, and most are fixable without major spending.
The Office for Civil Rights typically opens a matter after a breach report or a complaint, sends a data request letter, and asks for documentation such as your risk analysis, risk management plan, policies, training records and business associate agreements. The quality and dates of that documentation matter a great deal, because you are being asked to show what you had in place before the incident. Cases can close with technical assistance, a corrective action plan, or a settlement, depending on the facts.
Yes. The Security Rule applies regardless of practice size, and small offices are covered the same as hospital systems. What changes with size is scale, not obligation, and the rule allows you to consider your size, complexity and capabilities when deciding which safeguards are reasonable and appropriate. A small practice with a handful of systems can get through a credible risk analysis without an enterprise budget.

Tell us how many locations and systems touch patient data, and we will scope a risk analysis and give you a real number.

Contact us today for a free consultation and discover how we can help transform your business.

Get Started Call 954-235-2316

Explore Our Other Services

Comprehensive technology solutions for every aspect of your business

Custom Software Development

In today's competitive landscape, off-the-shelf software often falls short of meeting your unique business requirements....

Learn More
Mobile App Development (iOS & Android)

Your customers live on their phones. Internet Pros designs and builds mobile apps for iPhone, iPad and Android that feel...

Learn More
Web Design & Development

Your website is often the first impression potential customers have of your business. At Internet Pros, we create stunni...

Learn More