HIPAA security risk analysis
The assessment the rule requires annually, delivered as a report you can hand to a regulator, an insurer, or a buyer — plus a plain-language plan for what to fix first.
Most small offices are required to do more about security than anyone has ever told them. We tell you plainly what applies to you, what shape you're in, and what to fix first.
A two-person practice serving dental and medical offices, law firms, and manufacturers across Michiana and southwest Michigan.
Nobody starts at the right-hand end. The useful question isn't whether you have gaps — it's which ones matter and what order to close them in.
Businesses too small to hire a security director, and too regulated to ignore the question.
HIPAA requires a security risk analysis every year, and it's the first document requested after a complaint or breach. Most independent practices have never had one done.
Insurance renewals now hinge on multi-factor authentication, endpoint protection, and a written incident response plan. Corporate clients are starting to ask outside counsel the same questions.
If you supply into defense work, primes are pushing NIST 800-171 and CMMC requirements down to their suppliers. We sort out what actually applies to your contracts today.
Fixed fees, quoted before we begin. No hardware to buy, no software to license, no surprises on the invoice.
The assessment the rule requires annually, delivered as a report you can hand to a regulator, an insurer, or a buyer — plus a plain-language plan for what to fix first.
We work the renewal application with you and close the gaps behind the questions, so the answers are honest and the premium reflects it.
Your staff are already using AI tools. We find out which ones, write rules everyone can follow, and keep client and patient information out of them.
We're a married couple building this where we live, for the businesses we live among.
Five-plus years across IT governance, security leadership, and hands-on engineering — including rolling out mandatory multi-factor authentication at enterprise scale. Assessments, policy, compliance, and incident response are handled directly, not passed to a junior analyst.
Client communication, onboarding, scheduling, and the documents themselves. It's the reason working with a two-person firm feels organized rather than overloaded, and the reason you get answers the same week you ask.
We're advisors, not a managed service provider. We don't resell hardware or software, and we don't replace your IT company — we work alongside them, and we'll tell you when the answer is that you don't need us.
Twenty minutes, no charge, no pitch. We'll tell you what applies to your practice and whether it's worth doing anything about it. If it isn't, we'll say so.