Skip to content

HIPAA

HIPAA security and privacy readiness for healthcare and healthcare-adjacent organizations handling protected health information.

Overview

For organizations that touch protected health information, HIPAA sets the bar for how it must be safeguarded. We build the administrative and technical safeguards, access controls, encryption, audit trails, backup, into your environment.

We help you assess risk, close gaps, and document your controls so you can demonstrate compliance to partners, auditors, and patients.

How We Work

1

Risk analysis

We run the security risk analysis the rule requires and rank the findings by real-world risk.

2

Safeguards

We implement the administrative, physical, and technical safeguards, from access controls to encrypted devices.

3

Ongoing compliance

We keep policies, training, and evidence current, and reassess as your systems and vendors change.

What's Included

Risk assessment

A HIPAA security risk analysis that identifies and prioritizes gaps.

Access controls

Role-based access, MFA, and least-privilege over systems that touch PHI.

Encryption

Data protected at rest and in transit across your environment.

Audit and logging

Audit trails that evidence access and changes to protected data.

Backup and recovery

Protected, tested backups to meet availability obligations.

Policy and documentation

The safeguards and documentation that demonstrate compliance.

Implementation Options

Three ways to start, depending on how much certainty you want before you commit. Estimates and rates are quoted in your proposal.

T&M Remediation

Details
  • The full remediation on time and materials, billed to actual hours as consumed
  • A written estimate up front, revisited at every phase gate
  • Design and build run in parallel: the blueprint evolves while early phases are already being delivered
  • Scope stays flexible, with changes approved through a written change order
Best fit for
  • Simpler footprints with a clear picture of their requirements
  • Teams comfortable steering scope as the work unfolds

Fixed-Fee Gap Assessment & Roadmap

Details
  • The first phase of a full remediation, run as a standalone engagement with its own deliverables (we call it Phase 0)
  • Current state documented, future state designed, and the remediation blueprint delivered
  • A fixed-fee remediation proposal, priced against confirmed scope
  • Deliverables are platform-agnostic, not tied to Microsoft or to us, and detailed enough for any qualified partner to quote a fixed fee
  • The fee is credited in full toward the remediation if you proceed with us within three months
Best fit for
  • Complex or unclear scope, where guessing is expensive
  • Boards and leadership teams that prefer the certainty of a detailed roadmap and fixed-fee scope before implementation kicks off
Learn more about Phase 0

Fixed-Fee Remediation

Details
  • Follows a completed Discovery & Design engagement
  • The remediation at a fixed price, quoted against the scope confirmed in discovery and design
  • Milestone billing tied to deliverables you can verify
  • Change orders only when the scope itself changes
Best fit for
  • Budget certainty required before kickoff
  • Regulated or board-governed purchases

Support & Training Options

Compliance is a program, and readiness fades without upkeep. Choose how much of the program we carry. The flat-fee program runs on a rolling 90-day commitment; readiness projects are standalone.

T&M readiness project

Details
  • Gap assessment against HIPAA, scoped in writing and billed hourly
  • Remediation of findings, prioritized by risk
  • A roadmap you could execute with any provider
Best fit for
  • A first engagement, or a deadline-driven push
  • Teams with internal owners who need expert hands

Flat-fee compliance program

Details
  • Reduced professional services rates for your remediation
  • Continuous monitoring of the technical controls
  • Evidence collection that stays current instead of piling up before audits
  • Policy reviews and security awareness training
  • Support during assessments and customer security questionnaires
Best fit for
  • Businesses where HIPAA is a standing customer or regulator requirement
  • Leadership that never wants to scramble before an audit again

Fully managed IT & compliance

Everything in the flat-fee compliance program option, plus managed IT services:

  • Our lowest professional services rates for your remediation, as part of a holistic ongoing engagement
  • The IT operation underneath the controls, run by the same team
  • Helpdesk, patching, backups, and vendor management
  • Security monitoring, threat response, and email security
  • SLA on system-blocking issues
Best fit for
  • Regulated companies without internal IT
  • Teams tired of compliance and IT vendors pointing at each other

Who This Is For, and Who It Is Not

A strong fit if

  • You are a covered entity or a business associate handling protected health information.
  • A payer or partner has sent you a security questionnaire, or a business associate agreement to sign.
  • You have never completed a security risk analysis, or the last one predates your current systems.
  • Health information moves through email, shared drives, or a practice system, and access has never been reviewed.
  • You are healthcare-adjacent, in software, billing, or analytics, and your customers are covered entities.

A poor fit if

  • You want a HIPAA certificate. No such certification exists, and compliance is demonstrated through controls and documentation.
  • You need clinical system or electronic health record implementation work. That is a different specialty.
  • You want the risk analysis and no remediation. The findings only help once the gaps close.

Frequently Asked Questions

All questions
What is HIPAA?

HIPAA sets federal privacy and security rules for protected health information. It covers providers and every business associate that touches patient data, and it requires you to prove your safeguards, not just have them. We build and document those safeguards on your Microsoft stack.

We signed BAAs. Is that not enough?

The common substitute is 'we signed a BAA and we use encrypted email,' which covers a fraction of the Security Rule. Real compliance is access controls, audit logs, risk analysis, and evidence, which is a program, not a signature.

Does HIPAA apply to us?

It applies to healthcare and healthcare-adjacent organizations that store or handle patient information: practices, billing companies, benefits firms, health-tech vendors selling to covered entities. If you never touch PHI, you need good security but not HIPAA scaffolding, and a short scoping conversation settles which world you are in. If your staff are already experimenting with AI, read why governed Copilot beats banning AI in a HIPAA-regulated org.

Do you run the audit or certification itself?

No. Auditors and assessors have to stay independent, so the same firm cannot build your controls and certify the result. We build the controls, assemble the evidence, and sit beside you during the assessment, so the auditor finds a running system rather than a scramble.

We think we have been compromised. Is that where you start?

Yes, and triage comes before paperwork. On a first call after an incident we audit admin roles and mailbox delegates, review sign-in logs, check for hidden forwarding rules, and enforce MFA, then talk about the engagement. Serious threats get neutralized first and invoiced after.

How does pricing work?

Managed services run at a flat monthly rate per person, which covers their primary device; shared and additional devices are a small add-on. Project work is hourly and quoted in writing before it starts, or converted to a fixed monthly fee when you want budget certainty. Microsoft licensing passes through at list price.

How do you handle training?

Role-based and timed close to go-live so it sticks: finance, operations, and quality each learn their own workflows, in your system with your data. After go-live, support sessions run as live screen shares that double as training, and flat-fee plans include training for new hires and on each Microsoft release wave.

Related Reading

All insights
Featured

Latest

Jul 16, 2026CMMC and your Microsoft 365 tenant: why GCC high changes what software can connectA defense-adjacent manufacturer heading into a CMMC mock audit learned that a government-cloud Microsoft tenant can quietly limit which apps integrate with it.Microsoft SecurityJun 5, 2026Getting off paper: ERP for small regulated manufacturersFor a small regulated manufacturer still running on paper and spreadsheets, moving to an ERP is as much a change-management project as a software one. Here is what the system needs to enforce, and how to bring the team with you.Business CentralApr 22, 2026CMMC level 2 for small defense suppliers: wall off your CUI instead of moving the whole companyWhen controlled data touches only a slice of your work, you can shrink CMMC Level 2 scope by walling CUI into a governed enclave instead of dragging the whole company in.Microsoft SecurityApr 16, 2026Your staff are already using AI. For a HIPAA-regulated org, governed Copilot beats banning it.When staff paste protected health information into public chatbots, you can't ban your way out; a governed Microsoft 365 Copilot keeps the data in your tenant.Microsoft 365Apr 7, 2026FDA validation just changed (CSV to CSA): keep your quality system out of your ERPThe FDA's move from computer system validation to Computer Software Assurance, plus keeping quality management out of the ERP, can shrink the biggest cost in a regulated ERP project.Business Central

Get ahead of the next audit, or the next incident

A gap assessment against the Security Rule, in plain language.

30 minutesNo obligationGet an initial estimate within one week