The short version.
The full rates are on the pricing page. How we bill, respond and hand off is on the plain-English terms.
ePHI is any electronic information that can identify a patient and relates to their health, care, or payment, charts in the EHR, appointment notes, scanned insurance cards, emailed referrals, voicemails, X-ray files, even the billing spreadsheet. If your practice creates, stores, or sends it electronically, the HIPAA Security Rule applies, and it requires administrative, physical, and technical safeguards around all of it.
Your HIPAA Security Rule, covered without the jargon.
You’re the covered entity. We’re the technical partner that does the heavy lifting, runs the safeguards, and backs it with a signed BAA.
Security Risk Assessment
The annual risk assessment the Security Rule requires. We assess your whole environment and document every gap.
Technical Safeguards
We put the required controls in place, access control, encryption, MFA and audit logging, as our default stack, not an upgrade.
Evidence & Log Monitoring
Continuous log monitoring and evidence collection, so you can prove your safeguards, not just claim them.
Endpoint MDR
Managed detection & response on every workstation and server, threats caught and contained 24/7.
Email ITDR
Identity threat detection & response for Microsoft 365 and Google, your mailboxes and logins protected.
Backup & Disaster Recovery
Restore-tested backups of workstations, servers, email and drives, with a recovery plan that actually works.
Awareness Training
HIPAA-aligned staff training with completion records, so your team becomes your first line of defense, not your weakest link.
We Sign Your BAA
A business associate agreement isn’t a favor. It’s required, and we don’t hesitate. We stand behind the safeguards we run.
Policies & Templates
Ready-to-use HIPAA policy and procedure library tailored to your practice. Notice of Privacy Practices, Privacy/Security Officer designation, access and sanction policies, breach procedures.
The Security Rule doesn’t stop at software. Physical safeguards, cameras and door access on records areas, workstation privacy, and certified destruction of retired drives and copiers, are part of the same requirement, and we install and document those too. Surveillance & Access Control · Medical & Dental Offices.
There is no such thing as “HIPAA certified.”
If a vendor tells you they’re “HIPAA certified”, or that a certificate will make your practice compliant, walk away. HHS does not recognize or endorse any HIPAA certification, for practices or for the vendors who serve them.
Compliance is an ongoing program: safeguards you implement, maintain, and document. When the Office for Civil Rights investigates, usually after a breach or a patient complaint. They ask for evidence: your risk analysis, your policies, your training records, your logs. A practice with decent security but no paper trail is treated as non-compliant.
We also track HHS rulemaking so you don’t have to. HHS has proposed a Security Rule update that would make safeguards like MFA and encryption explicitly mandatory. It isn’t final yet, but our standard stack already meets it, so our clients won’t be scrambling when it lands.
That’s the standard we build to. Not “certified”, provable, and current.
Compliance that runs, not a binder on a shelf.
Most practices treat HIPAA as a once-a-year scramble. We make it continuous, so you’re ready the day an auditor, an insurer, or a breach comes knocking.
Assess
We run your Security Risk Assessment and map every gap against the HIPAA Security Rule, in plain English. If you attest under MIPS, this is the risk analysis you’re attesting to.
Implement
We put the technical safeguards in place, roll out MDR and ITDR, and sign your BAA.
Monitor
Detection, log monitoring, patching and restore-tested backups run continuously in the background.
Prove
Evidence, reports and training records are kept organized and current, so if anyone asks, you can show your work. If a breach ever happens, HIPAA gives you 60 days to notify affected patients. We make sure you have the facts documented to meet it.
Who’s responsible for what.
Under HIPAA, your practice is the covered entity, legal responsibility for compliance stays with you and can’t be signed away. Any vendor who says otherwise is misleading you. What can move to us is nearly all of the work: the safeguards, the monitoring, the documentation, the training, the annual risk assessment. What stays on your side is short, designating a Privacy/Security Officer, adopting the policies we provide, making sure staff complete the training, and we hand you the tools for each item. The vendors in our stack that handle your data operate under BAAs with us, so the chain of accountability doesn’t break at your IT company.
Responsibility stays with you. Nearly all of the work moves to us, with proof for everything that’s been done.
HIPAA compliance, straight answers.
Let's make sure we're a fit, both ways.
You see how we work. We see if your office is a fit.
Offices with 5 to 50 people in NY, NJ and CT. Book a call.
Rated 5.0 on Google · Pelham, NY · (914) 714-4312