Skip to content

Who we help · Dental & medical practices

HIPAA safeguards, done and documented.

Small practices are held to the same HIPAA Security Rule as hospitals. We put the safeguards in place, keep the risk analysis current, and sign the BAA — so an audit or an incident does not catch you without your paperwork.

The pressure you’re under

What’s actually being asked of you

HIPAA Security Rule

Practices that handle electronic protected health information must have administrative, physical, and technical safeguards: access control, audit controls, integrity controls, transmission security, and a documented risk analysis and risk management process.

Documented risk analysis

The single most common finding in HIPAA enforcement is the absence of an accurate, current, practice-wide risk analysis. It is not optional and it has to be written down.

Business associate agreements

Every vendor that touches PHI, including your IT provider, needs a signed BAA. We sign one with you as a matter of course.

Practice continuity

Imaging, practice-management software, and the schedule all depend on systems being up. Ransomware in a practice this size is an existential event.

What we do about it

The work, in plain terms

  • Perform and maintain a written HIPAA Security Rule risk analysis and a risk management plan.
  • Sign a Business Associate Agreement with your practice.
  • Enforce MFA and unique logins for every staff member; end shared workstations logins where possible.
  • Enable and retain audit logs across email and key systems.
  • Encrypt workstations and portable devices; confirm encryption in transit for anything carrying PHI.
  • Deploy and monitor managed EDR on every device.
  • Maintain tested backups of practice data and Microsoft 365 with a documented recovery time objective.
  • Provide workforce security awareness training and keep attendance records.
  • Maintain the required policies and an incident response plan, and be your first call.

Where practices usually start with us: a risk analysis plus a Microsoft 365 Security Baseline project, then a Secure or Secure+ monthly plan that keeps the safeguards and the documentation current.

We deliver security controls, documentation, and a BAA. We are not a HIPAA compliance attestation service or a law firm; for a formal compliance audit we will refer you to a specialist.

Get started

Find out where your firm stands

Book a short consultation. We walk through the service, what we need from you, the price and the timeline — with no obligation.