Protected health information (PHI)
Every intake note, treatment record, billing detail, and insurance form is PHI. If it lives on a laptop, in email, or in a cloud app without the right controls, it is a reportable breach waiting to happen.
Healthcare & Counseling
Therapy groups, counseling practices, and small clinics face the same HIPAA rules as large hospitals — with fewer staff and no security team. We turn those rules into a guided checklist, a clear risk score, and a remediation plan you can act on this week.
Every intake note, treatment record, billing detail, and insurance form is PHI. If it lives on a laptop, in email, or in a cloud app without the right controls, it is a reportable breach waiting to happen.
Therapists and clinicians often access records from personal phones, home laptops, or unsecured Wi-Fi. Without encryption, access controls, and remote wipe, a lost device becomes a HIPAA incident.
AI scribes, summarizers, and chatbots can speed up documentation, but many are not HIPAA Business Associates. Pasting session notes into the wrong tool is a fast path to an OCR complaint.
Practice type, size, state, and the systems you use for scheduling, notes, billing, and telehealth. Two minutes.
Each question maps to both HIPAA safeguards and NIST CSF 2.0 functions — so one assessment covers compliance and security risk at the same time.
See where your practice stands on Identify, Protect, Detect, Respond, Recover, and Govern — with HIPAA violations translated into business risk.
An executive summary, HIPAA gap list, quick wins, and a remediation plan with owners, effort, and deadlines you can show an auditor or attorney.
Work the roadmap, update your policies, and re-run the assessment to evidence improvement for HIPAA, insurers, and business partners.
A structured review of administrative, physical, and technical safeguards, mapped to the HIPAA Security Rule and NIST CSF 2.0.
Control-by-control comparison of your current policies and workflows against what HIPAA and state privacy rules actually require.
Plain-English priorities sized for a small practice — no enterprise overhead, just the actions that reduce breach risk fastest.
Identify which vendors touch PHI, check that BAAs are in place, and flag high-risk tools like AI transcription or offshore billing services.
10 healthcare-focused questions, about 5 minutes, no payment required. See where your practice stands before committing to a full assessment.