Assessment & advisory
HIPAA Risk Assessment & Compliance Advisory
HIPAA readiness for covered entities and business associates: ePHI risk analysis, safeguard review, privacy workflows, and practical remediation planning.
Discuss your HIPAA requirementsWhat we assess
We map electronic protected health information and assess risks to its confidentiality, integrity, and availability. The review connects administrative, physical, and technical safeguards with your actual environment, while privacy and breach-response workflows are scoped to the engagement and reviewed with counsel where needed.
Evidence to prepare
- ePHI inventories, data flows, risk analysis, and risk-management decisions.
- Access controls, audit logging, workforce training, and incident-response procedures.
- Business associate arrangements, vendor safeguards, and records showing that required activities are performed.
Keep design evidence separate from operating evidence. An approved procedure shows how a control is designed; dated records show whether it ran consistently over the review period. Evidence should identify its source, owner, scope, and collection date.
What you receive
- Documented risk findings and a prioritized safeguard remediation plan.
- Ownership and evidence requirements for recurring compliance activities.
- Recommendations for privacy, vendor, and breach-response workflows based on the agreed scope.
The assessment outcome
A defensible view of gaps and corrective actions for your health-data environment. HHS does not issue a general HIPAA compliance certificate; an assessment is part of an ongoing compliance program.
Common questions
Can a SOC 2 report replace HIPAA compliance?
A SOC 2 report can support customer assurance, but it does not replace HIPAA obligations. Map shared safeguards while reviewing health-data risks and HIPAA-specific responsibilities separately.
What determines the engagement timeline and cost?
The system boundary, number of entities and locations, existing control maturity, evidence availability, and assessment pathway determine the effort. Share your customer requirements and target milestone so we can define a realistic scope before proposing a schedule.
Framework reference: HHS — HIPAA Security Rule guidance. Guidance reviewed October 4, 2026; confirm current requirements when scoping an engagement.
