Find the gaps in 30 minutes.
Practices that keep patient records on a computer have to meet the HIPAA Security Rule. We go through ten areas with you in 30 minutes, including the five technical safeguard standards in the HIPAA Security Rule, and tell you in writing where we see gaps. It is a gap check, not a formal risk analysis, and it does not certify compliance.
Ten things
we look at.
The ones marked 164.312 are the technical safeguard standards in the Security Rule. The rest are what auditors and insurers ask about next to them.
Access control
164.312 standard
Unique logins, role-based permissions, automatic logoff
Person or entity authentication
164.312 standard
MFA and how people prove who they are
Audit controls
164.312 standard
Logging and monitoring on the systems we can see
Integrity
164.312 standard
Endpoint protection, change monitoring, file integrity
Transmission security
164.312 standard
Encrypted email, TLS, remote access
Backup & recovery
Tested restores, not just backups
Device security
Managed antivirus, endpoint protection, disk encryption
Risk analysis
Is there a documented, current one
Staff training
Security awareness and phishing tests, with records
Incident process
Is there a written plan? Notice to patients and HHS is still the practice's job
What you leave with
A written gap report on all 10 areas.
Written punch list. Yours to keep. No obligation. No follow-up sales calls unless you ask. If you want us to fix what we find, practices run on Office with the Compliance Pack. We set up and document the technical safeguards on the systems we manage.
Philip Robb · Owner · (806) 370-4700
Book it.
We reply within one business day. Gap check happens over a 30-minute call.
Prefer the phone? Call (806) 370-4700.