For dental practices · Michiana
Your HIPAA risk analysis, done properly.
HIPAA requires every dental practice to complete a security risk analysis each year. It's the first thing OCR asks for after a complaint or a breach — and the most common thing they find missing.
We do this for independent practices across South Bend, Mishawaka, Granger, Elkhart, and Niles. One site visit, a plain-language report, and a plan your office manager can actually run.
What happens next
- A 20-minute callUsually with the office manager. We ask how the practice runs and what systems hold patient information.
- One visit to the officeWe look at the practice management and imaging systems, backups, logins, and vendor agreements. We never open a chart.
- A report you keep on fileFindings ranked by what matters, a 30/60/90-day fix list, and the documentation OCR expects to see.
Two to three weeks start to finish. Your staff's time: a couple of hours.
What we find in most dental offices
None of these are unusual. They're just the things nobody had time to look at.
Shared front-desk logins
The single most common finding. Everyone signs into the practice management system as the same user, so there's no record of who did what.
An imaging server nobody manages
The X-ray or CBCT PC is often the oldest machine in the building, unencrypted, and running an operating system that stopped getting updates years ago.
No agreement with the lab
Dental labs receive patient scans every day. Most practices have never signed a Business Associate Agreement with them — which HIPAA requires.
Backups that were never tested
The backup runs. Nobody has ever tried to restore from it. After a ransomware event, that's the difference between a bad week and a closed practice.
No written policies, no training records
HIPAA requires both. When a complaint comes in, they're the first documents requested.
Where to start
Fixed fee, quoted before we begin. No hardware to buy, no software to license.
HIPAA Security Risk Analysis
- Inventory of every system that holds patient information, including cloud and vendor systems
- Review of all 45 HIPAA Security Rule implementation specifications, with the required-vs-addressable distinction documented
- Business Associate inventory and missing-agreement list
- Risk register with likelihood and impact ratings — the format OCR guidance describes
- Plain-language report you can hand to a regulator, insurer, or practice buyer
- 30/60/90-day remediation plan with owners
- Optional: a written HIPAA security policy manual sized for a small practice
Retained on file for six years, as the rule requires. Repeated annually under an ongoing plan.
Then, if you want it handled
Ongoing plans from $1,500 a month: the annual reassessment, policy upkeep, staff training, vendor agreements, and someone to call when something looks wrong. For offices that would rather not think about this again until we bring it up.
No long contract. Month to month after the first term, and we'll tell you if you've outgrown needing us.
Questions we hear
Our IT company says they handle HIPAA.
They handle the network, backups, and antivirus, and that's genuinely important. The risk analysis, written policies, staff training, and vendor agreements are separate requirements — and the dentist, not the IT company, is legally responsible for them. We work alongside your IT provider.
We did a risk analysis a few years ago.
It's an annual requirement, and it has to be updated after significant changes — new software, a new location, an incident. Ask whether you have a written report and a remediation plan from the last one. Many were checkbox exercises with nothing to show a regulator.
Do you need access to patient charts?
No. We look at systems, settings, and paperwork. We don't need to open a chart, and our agreement says so.
How much of the staff's time does this take?
A short conversation with the office manager, a walkthrough of about two hours, and maybe fifteen minutes with a front-desk and a clinical team member. The rest is on us.
What about the new HIPAA rules we keep hearing about?
A significant update to the Security Rule is proposed — mandatory MFA, encryption, and regular testing. It hasn't taken effect yet, but the current rule already requires the risk analysis. Getting it done now means you're ahead of whatever the final rule requires, rather than scrambling later.
Start with a conversation
Twenty minutes with you or your office manager, no charge. We'll tell you where the practice stands and whether it's worth doing anything about it. If you're already covered, we'll say so.
- Pick a time for a 20-minute callChoose any open slot — no phone tag
- (574) 250-4475Call or text during business hours
- info@statelinedata.comWe answer within one business day
- South Bend, Mishawaka, Elkhart, Niles, and the surrounding areaOn site when it helps, remote when it doesn't
