Skip to content
Patient records and a laptop on a practice meeting table

Health Insurance Portability and Accountability Act

HIPAA compliance without the legal bill.

Privacy, security and breach notification handled by consultants who work in medical offices every day. Plain-English policies, a documented security risk analysis, and workforce training your staff will follow.

The problem

Most practices are not non-compliant. They are undocumented.

The Privacy Rule, the Security Rule and the Breach Notification Rule each require written evidence: policies, a risk analysis, workforce training records, signed business associate agreements, and a documented response process. Investigators asked to review a complaint start with those documents.

The Security Rule in particular requires a thorough assessment of the risks to the confidentiality, integrity and availability of electronic protected health information, and a documented risk management plan addressing what the analysis found. In our experience it is the single most commonly missing document in a small practice.

We produce these documents with you, in language your staff can follow, without the hourly rates of outside counsel — and we keep them current as your systems and vendors change.

Clinician reviewing paperwork with a patient
A privacy complaint is answered with documents, not intentions.

What we handle

The full compliance picture.

Security risk analysis

A documented assessment of risks to ePHI across your systems, devices, vendors and physical premises, with a risk management plan addressing each finding.

Policies and procedures

A complete written policy set covering uses and disclosures, patient rights, safeguards, workforce sanctions and incident response.

Business associate agreements

Identification of every vendor that creates, receives, maintains or transmits PHI on your behalf, and a compliant agreement in place with each.

Breach response

A documented four-factor risk assessment process, notification templates, and the timelines for notifying individuals, the Secretary and the media.

Workforce training

Annual training covering realistic threats: social media, phishing, curiosity browsing of records, and password practice.

Patient rights

Access, amendment, accounting of disclosures, restriction requests and confidential communication — with the forms and response timelines built in.

A privacy complaint is answered with documents, not intentions. If the policy is not written and the training is not logged, it does not exist.

Get your HIPAA documentation in order.

Start with a consultation. We will tell you exactly which documents you are missing before you commit to anything.