Remote Support Client login Get a free quote
Compliance & HIPAA

HIPAA compliance work, handled as a service.

The technical safeguards are the part you can’t do yourself — so we run them for you, by default. The risk assessment, the safeguards, the evidence, the staff training and the paperwork: covered, continuously. And we sign your BAA.

Book a free assessment★★★★★5.0 on Google
What counts as ePHI

ePHI is any electronic information that can identify a patient and relates to their health, care, or payment — charts in the EHR, appointment notes, scanned insurance cards, emailed referrals, voicemails, X-ray files, even the billing spreadsheet. If your practice creates, stores, or sends it electronically, the HIPAA Security Rule applies — and it requires administrative, physical, and technical safeguards around all of it.

What we handle

Your HIPAA Security Rule — covered end to end.

You’re the covered entity. We’re the technical partner that does the heavy lifting, runs the safeguards, and backs it with a signed BAA.

Security Risk Assessment

The annual risk assessment the Security Rule requires — we assess your whole environment and document every gap.

Technical Safeguards

We put the required controls in place — access control, encryption, MFA and audit logging — as our default stack, not an upgrade.

Evidence & Log Monitoring

Continuous log monitoring and evidence collection, so you can prove your safeguards — not just claim them.

Endpoint MDR

Managed detection & response on every workstation and server — threats caught and contained 24/7.

Email ITDR

Identity threat detection & response for Microsoft 365 and Google — your mailboxes and logins protected.

Backup & Disaster Recovery

Restore-tested backups of workstations, servers, email and drives — with a recovery plan that actually works.

Awareness Training

HIPAA-aligned staff training with completion records, so your team becomes your first line of defense — not your weakest link.

We Sign Your BAA

A business associate agreement isn’t a favor — it’s required, and we don’t hesitate. We stand behind the safeguards we run.

Policies & Templates

Ready-to-use HIPAA policy and procedure library tailored to your practice — Notice of Privacy Practices, Privacy/Security Officer designation, access and sanction policies, breach procedures.

The Security Rule doesn’t stop at software. Physical safeguards — cameras and door access on records areas, workstation privacy, and certified destruction of retired drives and copiers — are part of the same requirement, and we install and document those too. Surveillance & Access Control · Medical & Dental Offices.

The honest version

There is no such thing as “HIPAA certified.”

If a vendor tells you they’re “HIPAA certified” — or that a certificate will make your practice compliant — walk away. HHS does not recognize or endorse any HIPAA certification, for practices or for the vendors who serve them.

Compliance is an ongoing program: safeguards you implement, maintain, and document. When the Office for Civil Rights investigates — usually after a breach or a patient complaint — they ask for evidence: your risk analysis, your policies, your training records, your logs. A practice with decent security but no paper trail is treated as non-compliant.

We also track HHS rulemaking so you don’t have to. HHS has proposed a Security Rule update that would make safeguards like MFA and encryption explicitly mandatory. It isn’t final yet — but our standard stack already meets it, so our clients won’t be scrambling when it lands.

That’s the standard we build to. Not “certified” — provable, and current.

Compliance as a service

Compliance that runs — not a binder on a shelf.

Most practices treat HIPAA as a once-a-year scramble. We make it continuous, so you’re ready the day an auditor, an insurer, or a breach comes knocking.

01

Assess

We run your Security Risk Assessment and map every gap against the HIPAA Security Rule — in plain English. If you attest under MIPS, this is the risk analysis you’re attesting to.

02

Implement

We put the technical safeguards in place, roll out MDR and ITDR, and sign your BAA.

03

Monitor

Detection, log monitoring, patching and restore-tested backups run continuously in the background.

04

Prove

Evidence, reports and training records stay audit-ready — so if anyone asks, you can show your work. If a breach ever happens, HIPAA gives you 60 days to notify affected patients — we make sure you have the facts documented to meet it.

Straight talk

Who’s responsible for what.

Under HIPAA, your practice is the covered entity — legal responsibility for compliance stays with you and can’t be signed away. Any vendor who says otherwise is misleading you. What can move to us is nearly all of the work: the safeguards, the monitoring, the documentation, the training, the annual risk assessment. What stays on your side is short — designating a Privacy/Security Officer, adopting the policies we provide, making sure staff complete the training — and we hand you the tools for each item. The vendors in our stack that handle your data operate under BAAs with us, so the chain of accountability doesn’t break at your IT company.

Responsibility stays with you. Nearly all of the work moves to us — with proof for everything that’s been done.

Common questions

HIPAA compliance — straight answers.

Is Novaj Tech HIPAA certified?

No — and neither is anyone else. HHS doesn’t recognize any HIPAA certification. What we do instead: maintain our own HIPAA compliance program as a business associate, sign a BAA with your practice, and document the safeguards on your systems so you can prove compliance rather than just claim it.

Who is this service for?

Any covered entity or business associate handling patient data: medical and dental offices, behavioral health, physical therapy and chiropractic, home health, labs, and the vendors that serve them. If you touch ePHI, the Security Rule applies to you. Running a medical or dental office? See the Medical & Dental Offices page for the full practice-IT picture.

Will this make my practice HIPAA compliant?

No vendor can honestly promise that — responsibility legally stays with the covered entity. What we do: implement and monitor the required safeguards, document everything, and supply the policies, training, and annual risk assessment your side requires. The responsibility stays yours; nearly all of the work becomes ours.

What happens in the free assessment?

We walk your environment, flag the gaps against the Security Rule, and hand you a clear plan and an honest quote. No obligation, no scare tactics.

Do you sign a business associate agreement?

Yes — standard with every healthcare client, before we touch systems containing patient information. The vendors in our stack that handle your data operate under BAAs with us, so the chain of accountability doesn’t break at your IT company.

Is compliance an add-on charge?

No. The safeguards, monitoring, documentation, template policies, staff training, and the annual risk assessment are all included in the managed plan. No compliance surcharge, no per-document fees.

Make the HIPAA workload someone else’s job.

Book a free assessment — we’ll walk your environment, flag the gaps, and hand you a clear plan and an honest quote.

Book a free assessment
Run a medical practice? See how this fits your practice →