Industries · Medical practices
HIPAA compliance a real practice can run.
No compliance department, no enterprise software rollout. A documented program built around how a practice actually works — and a partner who keeps it running.
We build for the reality, not the org chart.
The patterns we see in practices and provider groups, honestly stated.
- The office manager is also the privacy officer, the trainer, and the person who signs BAAs
- PHI lives in the EHR — but also in email, texting, scanned faxes, and the billing company's portal
- Staff turnover means access removal and training constantly fall behind
- The last 'risk assessment' was a questionnaire from an insurance application
What the program covers.
- A real Security Rule risk analysis, documented and reusable at each annual refresh
- Policies written for how a practice actually operates — not enterprise boilerplate
- Staff training with tracked completion and acknowledgment records
- A vendor list with BAA status for the EHR, billing, IT support, shredding, and messaging vendors
- Incident and breach playbooks, plus an incident log that stands up to scrutiny
- Contingency and backup review sized to a practice, not a data center
- An annual calendar so it all recurs without anyone heroically remembering
How it runs.
Weeks 1–2 · Look
Applicability check, walkthrough of systems and vendors, and the Security Rule risk analysis — interviews sized for a working practice's schedule.
Weeks 3–6 · Fix
Policies customized and acknowledged, training completed, BAAs collected or corrected, and the highest-risk technical gaps closed with your IT support.
Ongoing · Keep
Quarterly check-ins, the annual risk-analysis refresh and training campaign, and renewal reminders — for $399/month after implementation.
Recommended package.
HIPAA Foundations
Small practices, business associates, and early-stage healthcare vendors that need a documented HIPAA program but are not pursuing SOC 2 yet.
$4,500 implementation
+ $399/month ongoing
Or $7,500/year prepaid.
Target: 4–8 weeks
Timelines are targets, assuming timely client responses.
Included
- Applicability and entity-status assessment
- HIPAA Security Rule risk analysis
- Privacy and security gap assessment
- Remediation plan prioritized by risk
- Administrative, physical, and technical safeguard review
- Policy and procedure library customized to your organization
- Security/privacy officer role documentation
- + 11 more — see full inclusions
Medical practice FAQ
We're small. Do we really need all this?
The Security Rule scales with size — its safeguards are required, but what's "reasonable and appropriate" for a five-provider practice differs from a hospital. Our program is sized accordingly: the documentation is real, the meetings are few, and nothing is included just to look thorough.
Our EHR vendor says they're HIPAA compliant. Doesn't that cover us?
No. Your EHR vendor's compliance covers their side of the BAA. Your practice still owes its own risk analysis, policies, training, access management, and incident procedures — most enforcement actions against practices involve exactly those gaps, not the EHR.
How much of our staff's time does this take?
Modest and front-loaded: a discovery conversation, review of policies we draft, and an hour or two of training per person. The office manager or designated officer spends a few hours per week during implementation, far less afterward.
Do we need SOC 2 too?
Almost never — SOC 2 is for technology vendors whose customers demand it. For a practice, HIPAA Foundations is the right scope, and we'll tell you plainly if anyone tries to sell you more.
Get a real HIPAA program without the enterprise overhead.
Contact us — we'll tell you honestly what your practice needs and what it doesn't.