ePHI is any electronic information that can identify a patient and relates to their health, care, or payment — charts in the EHR, appointment notes, scanned insurance cards, emailed referrals, voicemails, X-ray files, even the billing spreadsheet. If your practice creates, stores, or sends it electronically, the HIPAA Security Rule applies — and it requires administrative, physical, and technical safeguards around all of it.
You’re the covered entity. We’re the technical partner that does the heavy lifting, runs the safeguards, and backs it with a signed BAA.
The annual risk assessment the Security Rule requires — we assess your whole environment and document every gap.
We put the required controls in place — access control, encryption, MFA and audit logging — as our default stack, not an upgrade.
Continuous log monitoring and evidence collection, so you can prove your safeguards — not just claim them.
Managed detection & response on every workstation and server — threats caught and contained 24/7.
Identity threat detection & response for Microsoft 365 and Google — your mailboxes and logins protected.
Restore-tested backups of workstations, servers, email and drives — with a recovery plan that actually works.
HIPAA-aligned staff training with completion records, so your team becomes your first line of defense — not your weakest link.
A business associate agreement isn’t a favor — it’s required, and we don’t hesitate. We stand behind the safeguards we run.
Ready-to-use HIPAA policy and procedure library tailored to your practice — Notice of Privacy Practices, Privacy/Security Officer designation, access and sanction policies, breach procedures.
The Security Rule doesn’t stop at software. Physical safeguards — cameras and door access on records areas, workstation privacy, and certified destruction of retired drives and copiers — are part of the same requirement, and we install and document those too. Surveillance & Access Control · Medical & Dental Offices.
If a vendor tells you they’re “HIPAA certified” — or that a certificate will make your practice compliant — walk away. HHS does not recognize or endorse any HIPAA certification, for practices or for the vendors who serve them.
Compliance is an ongoing program: safeguards you implement, maintain, and document. When the Office for Civil Rights investigates — usually after a breach or a patient complaint — they ask for evidence: your risk analysis, your policies, your training records, your logs. A practice with decent security but no paper trail is treated as non-compliant.
We also track HHS rulemaking so you don’t have to. HHS has proposed a Security Rule update that would make safeguards like MFA and encryption explicitly mandatory. It isn’t final yet — but our standard stack already meets it, so our clients won’t be scrambling when it lands.
That’s the standard we build to. Not “certified” — provable, and current.
Most practices treat HIPAA as a once-a-year scramble. We make it continuous, so you’re ready the day an auditor, an insurer, or a breach comes knocking.
We run your Security Risk Assessment and map every gap against the HIPAA Security Rule — in plain English. If you attest under MIPS, this is the risk analysis you’re attesting to.
We put the technical safeguards in place, roll out MDR and ITDR, and sign your BAA.
Detection, log monitoring, patching and restore-tested backups run continuously in the background.
Evidence, reports and training records stay audit-ready — so if anyone asks, you can show your work. If a breach ever happens, HIPAA gives you 60 days to notify affected patients — we make sure you have the facts documented to meet it.
Under HIPAA, your practice is the covered entity — legal responsibility for compliance stays with you and can’t be signed away. Any vendor who says otherwise is misleading you. What can move to us is nearly all of the work: the safeguards, the monitoring, the documentation, the training, the annual risk assessment. What stays on your side is short — designating a Privacy/Security Officer, adopting the policies we provide, making sure staff complete the training — and we hand you the tools for each item. The vendors in our stack that handle your data operate under BAAs with us, so the chain of accountability doesn’t break at your IT company.
Responsibility stays with you. Nearly all of the work moves to us — with proof for everything that’s been done.