Overview
For organizations that touch protected health information, HIPAA sets the bar for how it must be safeguarded. We build the administrative and technical safeguards, access controls, encryption, audit trails, backup, into your environment.
We help you assess risk, close gaps, and document your controls so you can demonstrate compliance to partners, auditors, and patients.
How We Work
Risk analysis
We run the security risk analysis the rule requires and rank the findings by real-world risk.
Safeguards
We implement the administrative, physical, and technical safeguards, from access controls to encrypted devices.
Ongoing compliance
We keep policies, training, and evidence current, and reassess as your systems and vendors change.
What's Included
Risk assessment
A HIPAA security risk analysis that identifies and prioritizes gaps.
Access controls
Role-based access, MFA, and least-privilege over systems that touch PHI.
Encryption
Data protected at rest and in transit across your environment.
Audit and logging
Audit trails that evidence access and changes to protected data.
Backup and recovery
Protected, tested backups to meet availability obligations.
Policy and documentation
The safeguards and documentation that demonstrate compliance.
Implementation Options
Three ways to start, depending on how much certainty you want before you commit. Estimates and rates are quoted in your proposal.
T&M Remediation
- The full remediation on time and materials, billed to actual hours as consumed
- A written estimate up front, revisited at every phase gate
- Design and build run in parallel: the blueprint evolves while early phases are already being delivered
- Scope stays flexible, with changes approved through a written change order
- Simpler footprints with a clear picture of their requirements
- Teams comfortable steering scope as the work unfolds
Fixed-Fee Gap Assessment & Roadmap
- The first phase of a full remediation, run as a standalone engagement with its own deliverables (we call it Phase 0)
- Current state documented, future state designed, and the remediation blueprint delivered
- A fixed-fee remediation proposal, priced against confirmed scope
- Deliverables are platform-agnostic, not tied to Microsoft or to us, and detailed enough for any qualified partner to quote a fixed fee
- The fee is credited in full toward the remediation if you proceed with us within three months
- Complex or unclear scope, where guessing is expensive
- Boards and leadership teams that prefer the certainty of a detailed roadmap and fixed-fee scope before implementation kicks off
Fixed-Fee Remediation
- Follows a completed Discovery & Design engagement
- The remediation at a fixed price, quoted against the scope confirmed in discovery and design
- Milestone billing tied to deliverables you can verify
- Change orders only when the scope itself changes
- Budget certainty required before kickoff
- Regulated or board-governed purchases
Support & Training Options
Compliance is a program, and readiness fades without upkeep. Choose how much of the program we carry. The flat-fee program runs on a rolling 90-day commitment; readiness projects are standalone.
T&M readiness project
- Gap assessment against HIPAA, scoped in writing and billed hourly
- Remediation of findings, prioritized by risk
- A roadmap you could execute with any provider
- A first engagement, or a deadline-driven push
- Teams with internal owners who need expert hands
Flat-fee compliance program
- Reduced professional services rates for your remediation
- Continuous monitoring of the technical controls
- Evidence collection that stays current instead of piling up before audits
- Policy reviews and security awareness training
- Support during assessments and customer security questionnaires
- Businesses where HIPAA is a standing customer or regulator requirement
- Leadership that never wants to scramble before an audit again
Fully managed IT & compliance
Everything in the flat-fee compliance program option, plus managed IT services:
- Our lowest professional services rates for your remediation, as part of a holistic ongoing engagement
- The IT operation underneath the controls, run by the same team
- Helpdesk, patching, backups, and vendor management
- Security monitoring, threat response, and email security
- SLA on system-blocking issues
- Regulated companies without internal IT
- Teams tired of compliance and IT vendors pointing at each other
Who This Is For, and Who It Is Not
A strong fit if
- You are a covered entity or a business associate handling protected health information.
- A payer or partner has sent you a security questionnaire, or a business associate agreement to sign.
- You have never completed a security risk analysis, or the last one predates your current systems.
- Health information moves through email, shared drives, or a practice system, and access has never been reviewed.
- You are healthcare-adjacent, in software, billing, or analytics, and your customers are covered entities.
A poor fit if
- You want a HIPAA certificate. No such certification exists, and compliance is demonstrated through controls and documentation.
- You need clinical system or electronic health record implementation work. That is a different specialty.
- You want the risk analysis and no remediation. The findings only help once the gaps close.
Frequently Asked Questions
All questionsWhat is HIPAA?
HIPAA sets federal privacy and security rules for protected health information. It covers providers and every business associate that touches patient data, and it requires you to prove your safeguards, not just have them. We build and document those safeguards on your Microsoft stack.
We signed BAAs. Is that not enough?
The common substitute is 'we signed a BAA and we use encrypted email,' which covers a fraction of the Security Rule. Real compliance is access controls, audit logs, risk analysis, and evidence, which is a program, not a signature.
Does HIPAA apply to us?
It applies to healthcare and healthcare-adjacent organizations that store or handle patient information: practices, billing companies, benefits firms, health-tech vendors selling to covered entities. If you never touch PHI, you need good security but not HIPAA scaffolding, and a short scoping conversation settles which world you are in. If your staff are already experimenting with AI, read why governed Copilot beats banning AI in a HIPAA-regulated org.
Do you run the audit or certification itself?
No. Auditors and assessors have to stay independent, so the same firm cannot build your controls and certify the result. We build the controls, assemble the evidence, and sit beside you during the assessment, so the auditor finds a running system rather than a scramble.
We think we have been compromised. Is that where you start?
Yes, and triage comes before paperwork. On a first call after an incident we audit admin roles and mailbox delegates, review sign-in logs, check for hidden forwarding rules, and enforce MFA, then talk about the engagement. Serious threats get neutralized first and invoiced after.
How does pricing work?
Managed services run at a flat monthly rate per person, which covers their primary device; shared and additional devices are a small add-on. Project work is hourly and quoted in writing before it starts, or converted to a fixed monthly fee when you want budget certainty. Microsoft licensing passes through at list price.
How do you handle training?
Role-based and timed close to go-live so it sticks: finance, operations, and quality each learn their own workflows, in your system with your data. After go-live, support sessions run as live screen shares that double as training, and flat-fee plans include training for new hires and on each Microsoft release wave.
Related Reading
Latest