A risk assessment is not optional – it is required under 45 CFR § 164.308(a)(1)(ii)(A). Most on-site assessments take under 30 minutes per location, and if we find violations, the re-assessment is free.
A risk assessment is required, not advisory. Practices are routinely found carrying dozens of violations they were unaware of.
Physical and administrative safeguards around who can reach patient records, and how that access is recorded.
A network security review under the HITECH Act, covering the systems that actually touch ePHI.
Dormant infections sit quietly on practice networks for months. Dental practices are a known target.
Your team is the control that fails first. We show them what a real attempt looks like.
An assessment costs a fraction of a single violation, which can reach $50,000 per incident.
Finding violations is the point of the exercise. We resolve them quickly, re-assess at no cost, and hand you a certification binder with detailed notes so your documentation is as solid as your systems.
Most findings are fixed the same week they are identified.
Including a certification binder and detailed notes for your records.
We advise in your interest, not to sell you a training package you don't need.
Policy review first, then on-site or remote evaluation - often 30 minutes per location, up to two weeks end to end.
Policies, procedures, and assigned responsibility.
Facility access, workstation siting, and device control.
Access control, audit logging, integrity and transmission security.
Business associate agreements and vendor obligations.
How PHI is used, disclosed, and shared.
Whether you could actually detect and report a breach in time.
What staff have been taught, and when they were last refreshed.
The full technical control set measured against the standard.
Schedule a free remote or on-site IT consult. Tell us about your business and the services you need – response times are typically under three hours.