The HIPAA security risk assessment

A documented look at where your practice keeps patient information, what could go wrong with it, and what to do first. Written for the people who run the practice, with enough detail for your IT provider to act on.

What you receive

Delivered as a PDF, with a one-hour review meeting.

  • The written risk analysisWhere electronic patient information lives, the threats and weaknesses that apply to it, how likely and how damaging each one is, and an overall risk rating. This is the document the Security Rule requires and the one an investigator or insurer will ask for.
  • A prioritized fix listEvery finding ranked High, Medium or Low, with a plain-English explanation and a specific fix. The High items come first, so you know what to spend on this month and what can wait.
  • An inventory of systems and vendorsComputers, software and cloud services that touch patient data, and which vendors need a business associate agreement on file.
  • A one-page summary for the ownerWhere the practice stands and the three to five decisions that matter, without the technical detail.
  • A review meetingOne hour, in person or by video, to go through the findings with you and your IT provider and answer questions.

What I look at

The areas where small practices most often have gaps.

  • Accounts and passwordsShared logins, former staff, multi-factor sign-in, admin access.
  • EmailPhishing protection, sign-in security, how records are sent to patients and labs.
  • Backups and recoveryWhether a ransomware attack could reach them, and whether a restore has ever been tested.
  • Computers and devicesUpdates, encryption, antivirus, laptops and phones that leave the office.
  • Network and Wi-FiGuest separation, the router and firewall, remote access for staff and vendors.
  • VendorsEHR, imaging, billing and cloud services, and their business associate agreements.
  • The physical officeScreens, printers, server closets and paper that becomes digital.
  • Policies and trainingWhat's written down, what staff are actually taught, and what happens when something goes wrong.

What it asks of your practice

  • About an hour of your office manager's time for the questionnaire.
  • Two hours of access to the office for the walkthrough, before opening, after close, or on a Saturday.
  • Someone who can log in to your main systems during the walkthrough, or your IT provider on a call.
  • An hour for the review meeting.

What it isn't

  • It isn't a certification. HHS doesn't certify practices as compliant, and nobody else can either.
  • It isn't legal advice. If a finding raises a legal question, I'll tell you so you can take it to your attorney.
  • It isn't a sales pitch for hardware or software. I don't resell products, so recommendations are based only on what your practice needs.
  • It doesn't replace your IT provider. They do the fixes; I tell you both what to fix and in what order.

Who it's for

Dental offices, family and specialty medical practices, physical therapy, chiropractic, behavioral health and optometry practices, typically with 3 to 40 staff, in Norfolk, Virginia Beach, Chesapeake, Portsmouth, Suffolk, Hampton and Newport News.

Larger or more complex? Tell me about it and I'll say honestly whether I'm the right fit.

Start with a 15-minute call

You'll leave the call with a fixed price and a start date, or an honest answer that you don't need this yet.