We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
hello@gritservices.io
  1. Compliance
  2. HIPAA

HIPAA compliance IT services for US healthcare: The risk analysis is required, it has to be accurate and thorough, and it is the document most practices cannot produce.

The HIPAA Security Rule applies to covered entities and to every business associate that creates, receives, maintains, or transmits protected health information for them. Its first required step is a written risk analysis of your electronic PHI, and almost everything else follows from it. We do the IT side of that work: the risk analysis, the safeguards in Microsoft 365 and on your devices, business associate oversight, audit logging, and being ready for a breach before one happens. Your counsel owns the legal interpretation.

Book a HIPAA risk analysisSee what is involved
HIPAA Security Rule compliance for US healthcare organizations
  • RequiredRisk analysis, 164.308
  • 60 daysOuter limit for notifying individuals
  • 6 yearsSecurity Rule documentation retention
  • Business associatesCovered by the rule too
What HIPAA compliance involves on the IT side

Eight pieces of work the Security Rule actually asks for.

The Security Rule is organized into administrative, physical, and technical safeguards, and it is deliberately flexible: the measures you choose can reflect your size, complexity, capabilities, and costs. That flexibility is real, and it is also why the written reasoning behind your choices matters as much as the controls themselves.

A risk analysis that is accurate and thorough

The rule marks this one Required. It means identifying where electronic PHI lives and moves, in the EHR, in email, in file shares, on laptops and phones, and assessing the risks to its confidentiality, integrity, and availability. A vendor questionnaire answered once in 2019 is not this document. We build it from what your environment actually contains, so it stands up when somebody reads it closely.

Risk management that follows from the analysis

The next required step is implementing security measures sufficient to reduce the risks you found to a reasonable and appropriate level. In practice that is a dated remediation plan with owners, worked through in order of risk, and kept current. An analysis with no plan behind it shows that you knew about a risk and did nothing about it.

Required and addressable, handled the way the rule intends

Addressable does not mean optional. For each addressable specification the rule expects you to assess whether it is reasonable and appropriate for you, then implement it, or document why it is not and implement an equivalent alternative where that is reasonable. We write those decisions down as we make them, which is the part most organizations skip.

Microsoft 365 configured for ePHI

Most practices already keep PHI in email, OneDrive, SharePoint, and Teams. We configure the tenant for it: multifactor sign-in for every account, Conditional Access, sensitivity labels and data loss prevention for PHI, encrypted email where it is needed, retention, and audit logging that is switched on and kept long enough to be useful.

Devices and access that match the policy

Encryption on laptops and phones, screen locks, managed devices for anyone who touches PHI, and access removed promptly when people leave. Encryption is an addressable specification, and it matters for a second reason: protected health information rendered unusable to unauthorized people under the Secretary's guidance is not "unsecured", which changes what a lost laptop means.

Business associates identified and covered

Anyone who creates, receives, maintains, or transmits PHI on your behalf meets the definition of a business associate: your IT provider, cloud and backup vendors, billing services, and more. We build the inventory of who touches PHI and check that each has an agreement in place before access starts, then keep the list current as vendors change.

Audit controls and activity review

The rule requires mechanisms that record and examine activity in systems containing ePHI, and an information system activity review. We switch on the logging in Microsoft 365, Entra ID, and your endpoints, decide how long it is kept, and set up a review someone actually performs, so the question of who opened a record has an answer.

Breach readiness before there is a breach

Individuals must be notified without unreasonable delay and no later than 60 calendar days after a breach is discovered, with HHS and sometimes the media notified as well depending on how many people are affected. Meeting that clock depends on knowing quickly what was accessed. We build the incident plan, the evidence capture, and the logging that make that possible.

Four points that change how the work gets done

What the regulation text actually says, in plain terms.

These come straight from 45 CFR Parts 160 and 164. They are the points we see misunderstood most often, and each one changes a decision you will make.

  • Business associates are directly covered by the Security Rule. A practice management vendor, a billing company, or an IT provider that handles PHI has its own obligations, including its own risk analysis, not just a signature on an agreement.
  • Addressable is a decision, not an exemption. Each addressable specification needs an assessment and, if you do not implement it, a documented reason and an equivalent alternative where reasonable. An undocumented gap reads as a missing control.
  • Security Rule documentation is kept for six years from when it was created or last in effect. Policies, risk analyses, and decisions that were replaced still need to exist.
  • Breach notification has fixed outer limits. Individuals within 60 calendar days of discovery at the latest; HHS at the same time for breaches affecting 500 or more people, or in an annual log for smaller ones; and prominent media outlets when more than 500 residents of a State are affected.
Ask us where your gaps are
How we work on HIPAA

Four positions we take on healthcare engagements.

HIPAA work fails in two predictable ways: a binder of policies nobody follows, or a set of tools nobody documented. We aim for the middle, where the controls run and the paperwork describes what actually happens.

We start from the risk analysis, not a product

Everything we recommend traces back to a risk we found in your environment. That keeps the spend proportionate, which the rule explicitly allows, and it means every control has a written reason when somebody asks why it is there.

We do the IT side; your counsel does the law

We are not attorneys and do not give legal advice. Breach determinations, notification decisions, and contract terms belong with your counsel. We give them what they need to decide quickly: what happened, what was accessed, and what the logs show.

We write the decisions down as we make them

Addressable specifications, risk acceptances, and exceptions get recorded at the time, with a date and an owner. Reconstructing that reasoning a year later is where most HIPAA documentation falls apart.

We stay after the project ends

The rule expects security measures to be reviewed and updated as things change, so this is ongoing work rather than a one-off. Managed clients keep the standard response commitments alongside it: five minutes on critical, ten on high, thirty on the rest, delivered remotely.

Who this is for

Six kinds of organization that need this work.

The Security Rule reaches further than most people expect, because business associates are covered directly.

Independent medical and dental practices

Small practices are covered entities like any hospital, and the rule lets the safeguards scale to your size. What does not scale away is the risk analysis. Most practices we meet have an EHR vendor's assurances and little else in writing.

Specialty clinics and multi-site groups

More locations means more devices, more shared accounts, and more vendors touching PHI. The work here is consistency: one standard applied everywhere, and one inventory of who has access to what.

Behavioral health and therapy practices

Often small, often remote-first, and often running PHI through email and video tools that were set up quickly. Getting the tenant, the devices, and the vendor agreements right matters more here because the records are among the most sensitive there are.

Digital health and health tech companies

A company that hosts or processes PHI for providers is a business associate, with its own Security Rule obligations. These companies also tend to face SOC 2 requests from the same customers, and much of the evidence serves both.

Billing, coding, and practice management services

Classic business associates. You handle PHI every day on behalf of many covered entities, and each of them will eventually ask what you do to protect it. A current risk analysis and clear controls answer that once.

Anyone who just had a scare

A phishing incident, a lost laptop, a former employee who still had access. The question then is whether it is a reportable breach, and the answer depends on what you can prove. We help you establish the facts and make sure the next incident is easier to answer.

How an engagement runs

Five stages, from inventory to an ongoing program.

The order matters. Controls chosen before the risk analysis tend to be the wrong ones, and documentation written after the fact tends to describe what people wish had happened.
  1. 1

    Find where ePHI lives and moves

    Systems, mailboxes, file shares, devices, cloud apps, and every vendor that touches PHI. This inventory is the scope for everything that follows, and it is usually larger than anyone expects.

  2. 2

    Risk analysis

    An assessment of the risks to the confidentiality, integrity, and availability of that ePHI, rated by likelihood and impact, written so a reader can follow the reasoning.

  3. 3

    Risk management plan and remediation

    A dated plan with owners, then the work itself: multifactor sign-in, device encryption and management, Microsoft 365 configuration, logging, backup protection, and access cleanup, highest risk first.

  4. 4

    Policies, decisions, and breach readiness

    Policies that describe what you actually do, documented decisions on addressable specifications, the business associate inventory, and an incident plan you have rehearsed once.

  5. 5

    Keep it current

    Periodic review of the risk analysis as systems and vendors change, log review, access reviews, and updated documentation, kept for the six years the rule requires.

Straight answers

What US healthcare organizations ask about HIPAA and IT.

Yes. The risk analysis is a Required implementation specification for every covered entity and business associate, whatever its size. What the rule does allow is for the measures you choose to reflect your size, complexity, capabilities, and costs. So a five-person practice needs a risk analysis just as a hospital does, but the resulting plan can be proportionate.

If it creates, receives, maintains, or transmits PHI on your behalf, it meets the regulatory definition of a business associate, and that includes most IT providers with administrative access to systems holding PHI. Business associates have their own obligations under the Security Rule, and an agreement should be in place before access starts. That applies to any provider you use, us included.

No. For an addressable specification you must assess whether it is reasonable and appropriate in your environment. If it is, you implement it. If it is not, you document why and implement an equivalent alternative measure where that is reasonable and appropriate. Skipping it without a written decision leaves a gap with no explanation.

Encryption of ePHI is an addressable specification, so it follows the assess, implement, or document process above. There is also a practical reason most organizations implement it: PHI that has been rendered unusable, unreadable, or indecipherable to unauthorized people in line with the Secretary's guidance is not "unsecured" protected health information, and breach notification obligations attach to unsecured PHI. Your counsel should confirm how that applies to a specific incident.

No tool does that on its own. Microsoft 365 can be configured to support the safeguards the rule describes, with multifactor sign-in, Conditional Access, encryption, data loss prevention, retention, and audit logging, but data loss prevention, sensitivity labels, and retention for PHI are not configured for you, and access policies need designing. You also need the business associate agreement in place with each cloud vendor, the risk analysis, and the policies that describe how you use it.

Individuals must be notified without unreasonable delay and in no case later than 60 calendar days after the breach is discovered. Breaches affecting 500 or more individuals are reported to HHS at the same time, and to prominent media outlets when more than 500 residents of a State are affected. Smaller breaches are logged and reported to HHS within 60 days after the end of the calendar year. Whether an incident is a reportable breach is a legal determination for your counsel; our job is to establish the facts fast.

Security Rule documentation, such as policies, procedures, and records of required actions and assessments, is retained for six years from the date it was created or the date it was last in effect, whichever is later. That includes versions you have since replaced.

With the inventory and the risk analysis. They tell you what you have, where PHI actually goes, and which gaps carry the most risk, so the rest of the spend goes where it matters. If you already have a risk analysis, we can start by reviewing it against your current environment, since systems and vendors change faster than most analyses are updated.
HIPAA Security Rule

Fifteen questions to answer before anyone else asks them.

The first set is the paperwork the rule requires. The second is the technical controls behind it. The third is whether you could respond to a breach inside the deadlines.

The required documents

  • Do you have a written risk analysis of where ePHI lives?
    Required, and the foundation for everything else.
  • Is there a dated risk management plan with owners?
    The analysis without a plan shows known, untreated risk.
  • Are addressable decisions documented?
    Including the reason and any alternative measure.
  • Is a security official named?
    One person, accountable, written down.
  • Is documentation kept for six years?
    Including superseded versions.

The technical safeguards

  • Does every account that can reach PHI use multifactor sign-in?
    Email included, not just the EHR.
  • Are laptops and phones that hold PHI encrypted and managed?
    Encryption changes what a lost device means.
  • Is audit logging on, retained, and reviewed?
    Recording activity is required; reviewing it is the point.
  • Is access removed promptly when people leave?
    Including shared mailboxes and cloud apps.
  • Is there a data backup plan, and are backups protected from ransomware?
    The backup plan is Required; offline or immutable copies, restore-tested.

Breach readiness

  • Do you know every vendor that touches PHI?
    Each is a business associate.
  • Does each one have an agreement in place?
    Before access starts, not after.
  • Is there a written incident response plan?
    Reachable when your network is not.
  • Could you tell within days what an attacker accessed?
    The 60-day clock depends on it.
  • Has the plan been rehearsed?
    A first run-through should not be the real event.
Related reading

The pages around this one.

Compliance services

How HIPAA sits alongside SOC 2, state privacy laws, and the other frameworks we cover.

Learn more

HIPAA compliance in healthcare IT

Our longer guide to the Security Rule for US healthcare providers.

Learn more

Microsoft 365 email encryption

Encrypting email that carries PHI, and setting up revocation correctly.

Learn more
Next step

Start with an honest risk analysis.

We map where your ePHI lives, assess the risks, and give you a dated plan in order of priority. If you already have an analysis, we review it against what your environment looks like today.

Book a HIPAA risk analysisSee compliance services

Related Services

Explore more solutions that work great with this service

IT Compliance

HIPAA, SOC 2, NIST, CMMC, CCPA readiness

Learn more

Cybersecurity Audit

Security assessment and compliance audit

Learn more

Microsoft 365 Email Encryption

Microsoft Purview Message Encryption configuration for US businesses:

Learn more

Microsoft Purview

Data governance and compliance solutions

Learn more

MFA Solutions

Multi-factor authentication implementation for US businesses on

Learn more

Incident Response Plan Development

Incident response plan development for US organizations: decision

Learn more

Access Rights Review and Certification

Recurring access certification your auditors accept

Learn more

SOC 2 Readiness

Get audit-ready for the report your buyers ask for

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerJamf Registered Partner

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva
  • Edge for Business

Apple

  • Apple Business
  • Apple Jamf Pro
  • Jamf Licensing
  • Apple School Licensing

IT Services

  • Managed IT Services
  • Co-Managed IT
  • IT Support USA
  • IT AMC USA
  • Remote IT Support
  • On-Call IT Support
  • Disaster Recovery & BC
  • Google Workspace
  • Cloud Migration Services
  • Active Directory
  • Server Management

Company

  • About Us
  • IT by Industry
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA