IT and HIPAA compliance built for Minnesota 245D providers
You need a named HIPAA Security Officer, a documented risk assessment, and someone who answers the phone when a laptop gets compromised. We do all three, for providers your size.
The problem, stated plainly
DHS is re-reviewing providers during the moratorium
DHS has said it will spend the moratorium period reconnecting with providers that have not been evaluated in over three years. If your last documented security risk assessment is old or missing, that is a problem you want to solve before the review, not during it.
HIPAA names a person, not a vendor
The Security Rule requires you to designate a specific individual as your Security Officer. Most small providers assign it to an administrator who has never done a risk assessment. We take the role formally, in writing.
Your IT and your compliance are the same problem
Microsoft 365 configuration, device management, and access reviews are not separate from HIPAA. They are where most of the Security Rule is actually satisfied or failed.
What's included
A single retainer covering the security officer role, the compliance work, and the day-to-day IT that makes it real.
- Designated HIPAA Security Officer, named in writing
- Annual Security Risk Assessment using the HHS SRA methodology
- Written policies and procedures mapped to the Security Rule
- Business Associate Agreement review and tracking
- Workforce security awareness training and documentation
- Microsoft 365, Entra ID, and Intune administration
- Endpoint protection, patching, and backup monitoring
- Incident response plan, tested, with a documented breach clock
- Helpdesk for your staff
We have done this work
We serve as designated HIPAA Security Officer for a licensed Minnesota assisted living and 245D provider, where we led a full forensic investigation of a remote-access compromise, coordinated with legal counsel on the breach determination, and delivered a 25-item corrective action plan.
Questions we get
Straight answers on how this works.
Do you replace our administrator?
We are already licensed. Does the moratorium affect us?
What size provider is this built for?
Start with a free 30-minute gap check
We will walk your current HIPAA security posture against the Security Rule and tell you where the gaps are. No obligation, and you keep the findings either way.