HIPAA security risk analysis
The assessment the rule requires annually, delivered as a report you can hand to a regulator, an insurer, or a buyer — plus a plain-language plan for what to fix first.
Security & compliance · South Bend · Elkhart · Niles
Most small offices are required to do more about security than anyone has ever told them. We tell you plainly what applies to you, what shape you're in, and what to fix first.
A two-person practice serving dental and medical offices, law firms, and manufacturers across Michiana and southwest Michigan.
Most projects run two to three weeks. Fixed fee, quoted before we start.
Businesses too small to hire a security director, and too regulated to ignore the question.
HIPAA requires a security risk analysis every year, and it's the first document requested after a complaint or breach. Most independent practices have never had one done.
For dentists →Chiropractic, physical therapy, optometry, dermatology, behavioral health — same rule, same annual requirement, and even less attention from vendors.
For practices →Insurance renewals now hinge on MFA, endpoint protection, and a written incident response plan. Corporate clients are starting to ask outside counsel the same questions.
For firms →If you supply into defense work, primes are pushing NIST 800-171 and CMMC requirements down to you. If you don't, a week of downtime is still the real risk.
For shops →Fixed fees, quoted before we begin. No hardware to buy, no software to license, no surprises on the invoice.
The assessment the rule requires annually, delivered as a report you can hand to a regulator, an insurer, or a buyer — plus a plain-language plan for what to fix first.
We work the renewal application with you and close the gaps behind the questions, so the answers are honest and the premium reflects it.
For shops supplying into defense work. What your contracts require today, where you stand, and what to fix before it costs you a bid.
Whether or not anyone approved it.
Staff are pasting patient notes into chatbots to reword them. The scheduling system added an AI feature nobody reviewed. A transcription tool is recording appointments and storing them somewhere you've never looked.
None of that is reckless — it's people trying to save time. But when the information belongs to a patient or a client, “which tool, holding what, where” becomes a question you're expected to be able to answer.
Included in ongoing plans. Available as a standalone project.
We're a married couple building this where we live, for the businesses we live among.
Co-Founder & Principal Consultant · GSEC
Five-plus years across IT governance, security leadership, and hands-on engineering — including rolling out mandatory multi-factor authentication at enterprise scale. Assessments, policy, compliance, and incident response are handled by Gary directly, not passed to a junior analyst.
Co-Founder, Client Services & Operations
Kristin runs client communication, onboarding, scheduling, and the documents themselves. It's the reason working with a two-person firm feels organized rather than overloaded, and the reason you get answers the same week you ask.
We're advisors, not a managed service provider. We don't resell hardware or software, and we don't replace your IT company — we work alongside them, and we'll tell you when the answer is that you don't need us.
Usually, yes. IT companies handle networks, backups, and antivirus — and do it well. The risk analysis, written policies, and staff training are separate requirements, and the practice owner is the one legally responsible for them. We work alongside your IT provider, not against them.
No. We review systems, settings, policies, and vendor agreements. We don't need to open a chart or a case file, and our contracts say so in writing.
Two to three weeks from kickoff to report, with one site visit or screenshare and a short staff interview or two. Your time commitment is a few hours total.
Then you'll know, which is the point. Every finding comes with a plain-language fix, ranked by what matters most, and nothing goes to anyone but you. Finding a gap now is cheap; finding it after a breach or an audit is not.
No. We don't sell or manage hardware or software. We're the advisors who tell you what to do and check that it got done — which is why we can work alongside whoever already handles your IT.
Twenty minutes, no charge, no pitch. We'll tell you what applies to your practice and whether it's worth doing anything about it. If it isn't, we'll say so.