Skip to main content
245D & HCBS Providers

IT and HIPAA compliance built for Minnesota 245D providers

You need a named HIPAA Security Officer, a documented risk assessment, and someone who answers the phone when a laptop gets compromised. We do all three, for providers your size.

Why this matters now

The problem, stated plainly

DHS is re-reviewing providers during the moratorium

DHS has said it will spend the moratorium period reconnecting with providers that have not been evaluated in over three years. If your last documented security risk assessment is old or missing, that is a problem you want to solve before the review, not during it.

HIPAA names a person, not a vendor

The Security Rule requires you to designate a specific individual as your Security Officer. Most small providers assign it to an administrator who has never done a risk assessment. We take the role formally, in writing.

Your IT and your compliance are the same problem

Microsoft 365 configuration, device management, and access reviews are not separate from HIPAA. They are where most of the Security Rule is actually satisfied or failed.

What's included

A single retainer covering the security officer role, the compliance work, and the day-to-day IT that makes it real.

  • Designated HIPAA Security Officer, named in writing
  • Annual Security Risk Assessment using the HHS SRA methodology
  • Written policies and procedures mapped to the Security Rule
  • Business Associate Agreement review and tracking
  • Workforce security awareness training and documentation
  • Microsoft 365, Entra ID, and Intune administration
  • Endpoint protection, patching, and backup monitoring
  • Incident response plan, tested, with a documented breach clock
  • Helpdesk for your staff
Proof

We have done this work

We serve as designated HIPAA Security Officer for a licensed Minnesota assisted living and 245D provider, where we led a full forensic investigation of a remote-access compromise, coordinated with legal counsel on the breach determination, and delivered a 25-item corrective action plan.

Questions we get

Straight answers on how this works.

Do you replace our administrator?
No. We take the Security Officer role and the technical work. Your administrator stays responsible for operations and for the parts of HIPAA that are clinical and administrative.
We are already licensed. Does the moratorium affect us?
It does not restrict your existing license, and it means DHS is not adding new competitors to your market for two years. It also means DHS licensing capacity is being redirected toward reviewing existing providers.
What size provider is this built for?
Roughly five to fifty staff, with Microsoft 365 and no internal IT department.

Start with a free 30-minute gap check

We will walk your current HIPAA security posture against the Security Rule and tell you where the gaps are. No obligation, and you keep the findings either way.