Technical Safeguards
The controls that decide who can reach PHI and whether you would even know if something went wrong.
- Access controls and unique logins
- Encryption at rest and in transit
- Audit logging and automatic logoff
HIPAA Audit
A structured review of how your practice actually handles protected health information - access controls, audit logs, vendor agreements, offboarding. You get a written risk analysis and a prioritized plan to close the gaps. From $1,500.
What We Review
HIPAA compliance is not a binder of policies - it is whether your safeguards actually hold up. This audit finds the gaps. If you want them fixed, that is the HIPAA and PCI Compliance Setup. Many practices audit first, then decide.
The controls that decide who can reach PHI and whether you would even know if something went wrong.
The process side of the Security Rule - including whether the required written risk analysis actually exists.
How the devices and locations that touch PHI are controlled day to day.
Where quiet exposure builds up: shared logins, over-broad access, and credentials that outlive the employee.
Every vendor that handles your PHI - EHR, billing, cloud, email - needs a signed BAA and the right data practices.
Whether you could actually produce evidence if the HHS Office for Civil Rights asked - not just say you are compliant.
Priced as a fixed-fee engagement, scoped to the size and complexity of your practice and agreed before we start. Never metered by the hour. You walk away with the written HIPAA risk analysis the Security Rule actually requires - plus a plan you can act on.
How It Runs
A short intake on how your practice runs, read access to the systems that touch PHI, and a schedule. We confirm the fixed fee before any work begins.
We work through the administrative, physical, and technical safeguards against your actual environment - how PHI really moves through your systems, not a checklist someone fills in from memory.
You receive a written HIPAA risk analysis and a prioritized remediation plan, walked through live. You can close the gaps yourself, hand the plan to your team, or have us implement the fixes.
Tell us about your practice and we will scope the audit and confirm the fixed fee. A real review of how PHI moves through your systems - not a checklist that misses the point.