Compliance
HIPAA Compliance
No vendor can sell you HIPAA compliance. It is a position you hold and maintain, built on a risk analysis you perform.
We start with the risk analysis, because it is both the legal foundation and the only honest way to prioritize. It establishes where patient data actually lives, which is rarely only where people think it does.
Then the safeguards go in where they do not slow anyone down. Controls that add steps to a patient encounter get worked around, and a worked-around control protects nobody.
Then we keep the record. HIPAA has no certificate, so what you have instead is documentation of the analysis, the decisions, and the safeguards. That record is the thing worth maintaining, and it is what an investigator asks for.
What this covers
- A security risk analysis, documented properly.
- Administrative, physical, and technical safeguards implemented.
- Policies and procedures written in language your staff can follow.
- Business associate agreements, including ours with you.
- Annual review, so your position does not quietly decay.
Common questions
Will you sign a business associate agreement?
Yes. Any provider touching your systems in a way that could expose patient data should be signing one.
How often does the risk analysis need redoing?
It is meant to be ongoing rather than annual, and revisited whenever something material changes: a new system, a new location, a new way of working. In practice we review it yearly and update it as things change.
Part of CMMC & HIPAA Compliance
Evidence you can hand an auditor, and a plain reading of where you stand before you have to.