bplogo 1
Rein us in!

Documentation required by the HIPAA Security Rule

If you're a smaller practice and need help creating the documents required by the HIPAA security rule, we can help. We can assist with your annual Risk Analysis, writing procedures with security in mind, writing breach response plans, and performing network vulnerability scans.


If you are unsure where to start, the Risk Assessment is typically the best place. This is the most common thing we see smaller practices missing, and it is a firm requirement of HIPAA. It also informs many of the other documents that must be created, since the Risk Assessment maps out risk, it tells us what security controls need to be in place.   


Our risk assessment workflow

01

Initial Conversation

We begin with an in-depth consultation to understand your current procedures, system setup, and security controls. 

02

Network Scan

Once we understand what exists already, we can begin a vulnerability scan. This involves checking every device on the network for vulnerabilities that could lead to an exploit.

03

Writing the report

Now that we understand your workflows and network, we put together the official document. This includes a complete map of where all ePHI lives on your system, a prioritized list of risks ranked by severity, and a clear plan for how each risk is being mitigated along with a timeline for resolution.

04

Final Deliverable

The final deliverable is the documented, audit-ready report that OCR asks for first in any investigation.

Free HIPAA Security Checklist

If you're not sure whether you have everything in place, our free HIPAA security rule checklist is a resource. It contains all of the documentation and IT control requirements of the HIPAA Security Rule, along with a reference to the law that defines it. You can get it for free by filling in the form below. 

Share with