Free Assessment ยท Gilbert, Arizona
The assessment you are already required to do, done properly
The HIPAA Security Rule requires a risk analysis. Most practices we meet have either never had one, or had one performed once and never repeated. Neither position is defensible if anyone asks.
What you receive
A written report, not a verbal impression
Findings in plain English, each rated red, amber or green, each mapped to the question a carrier, an auditor or a client will eventually ask you.
Alongside it, a fix first list ranked by risk and by what it costs to close, so you can decide what to do now, what to budget for, and what to leave alone.
It costs nothing, takes one visit plus remote review, and the report is yours to keep, share with your broker, or hand to the IT provider you already have.
Sample findings
- Business Associate Agreements currentComplete
- Unique user identificationVerified
- Automatic logoff on workstationsFront desk only
- Annual risk analysis on fileLast completed 2022
- Workforce training recordsIncomplete for 2025 hires
- Encrypted backup with offsite copyVerified
An illustrative extract. Green means answer yes with confidence. Amber means answer carefully. Red means fix it before you sign anything.
What the review covers
- Administrative safeguards: workforce security, access management, training records, sanction policy, and the documented policies the rule expects to exist
- Physical safeguards: facility access, workstation placement and use, device and media controls including how equipment is disposed of
- Technical safeguards: access control, unique user identification, automatic logoff, audit controls, integrity controls and transmission security
- Business Associate Agreements: which vendors touch PHI, whether an agreement exists for each, and whether it is current
- Contingency planning: data backup, disaster recovery and emergency mode operation, with evidence a restore has been tested
- Breach readiness: a written incident response and notification procedure that names people rather than roles
What you receive
- A written risk analysis with each finding rated by likelihood and impact
- A remediation plan ranked by risk, with a realistic effort and cost estimate against each item
- Documentation you can place in your compliance file and show to an auditor
- A straight answer on what is urgent, what can wait a budget cycle, and what is fine as it is
Straight answers
Questions about the assessment
Does this satisfy our annual risk analysis requirement?
It produces the documented risk analysis and remediation plan the Security Rule expects, which is what most practices are missing. Whether your overall compliance program is sufficient depends on more than the technical environment, which is why we recommend running this alongside compliance counsel rather than instead of them.
Who performs it?
One of our own engineers, from Gilbert. Not a subcontractor and not a questionnaire you fill in yourself.
Is it really free?
Yes, and the report is yours to keep regardless of what you decide afterwards. If your current IT provider has everything in place, the report says so, and you have documentation you did not have yesterday.
How disruptive is it?
One visit during a normal working day plus a remote review. We work around your schedule and nothing changes in your environment during the assessment.
Are you a compliance consultancy?
No. We are a managed IT provider that implements and documents the technical and administrative safeguards. For legal interpretation of your HIPAA obligations, work with compliance counsel. Most practices need both.
We just switched EHR. Should we wait?
No, the opposite. Right after a major change is when configuration gaps are most likely and least likely to have been checked.
Find out before somebody else does
The worst time to discover a gap is when a claim is being examined. The second worst is the week of renewal.
Orca IT Solutions provides managed IT and cyber security services. This assessment addresses the technical and administrative safeguards within our scope of work and does not constitute legal advice or a complete compliance program. Consult qualified compliance counsel regarding your obligations under HIPAA and HITECH.