HIPAA compliance IT services for US healthcare: The risk analysis is required, it has to be accurate and thorough, and it is the document most practices cannot produce.
The HIPAA Security Rule applies to covered entities and to every business associate that creates, receives, maintains, or transmits protected health information for them. Its first required step is a written risk analysis of your electronic PHI, and almost everything else follows from it. We do the IT side of that work: the risk analysis, the safeguards in Microsoft 365 and on your devices, business associate oversight, audit logging, and being ready for a breach before one happens. Your counsel owns the legal interpretation.

- RequiredRisk analysis, 164.308
- 60 daysOuter limit for notifying individuals
- 6 yearsSecurity Rule documentation retention
- Business associatesCovered by the rule too
Eight pieces of work the Security Rule actually asks for.
A risk analysis that is accurate and thorough
The rule marks this one Required. It means identifying where electronic PHI lives and moves, in the EHR, in email, in file shares, on laptops and phones, and assessing the risks to its confidentiality, integrity, and availability. A vendor questionnaire answered once in 2019 is not this document. We build it from what your environment actually contains, so it stands up when somebody reads it closely.
Risk management that follows from the analysis
The next required step is implementing security measures sufficient to reduce the risks you found to a reasonable and appropriate level. In practice that is a dated remediation plan with owners, worked through in order of risk, and kept current. An analysis with no plan behind it shows that you knew about a risk and did nothing about it.
Required and addressable, handled the way the rule intends
Addressable does not mean optional. For each addressable specification the rule expects you to assess whether it is reasonable and appropriate for you, then implement it, or document why it is not and implement an equivalent alternative where that is reasonable. We write those decisions down as we make them, which is the part most organizations skip.
Microsoft 365 configured for ePHI
Most practices already keep PHI in email, OneDrive, SharePoint, and Teams. We configure the tenant for it: multifactor sign-in for every account, Conditional Access, sensitivity labels and data loss prevention for PHI, encrypted email where it is needed, retention, and audit logging that is switched on and kept long enough to be useful.
Devices and access that match the policy
Encryption on laptops and phones, screen locks, managed devices for anyone who touches PHI, and access removed promptly when people leave. Encryption is an addressable specification, and it matters for a second reason: protected health information rendered unusable to unauthorized people under the Secretary's guidance is not "unsecured", which changes what a lost laptop means.
Business associates identified and covered
Anyone who creates, receives, maintains, or transmits PHI on your behalf meets the definition of a business associate: your IT provider, cloud and backup vendors, billing services, and more. We build the inventory of who touches PHI and check that each has an agreement in place before access starts, then keep the list current as vendors change.
Audit controls and activity review
The rule requires mechanisms that record and examine activity in systems containing ePHI, and an information system activity review. We switch on the logging in Microsoft 365, Entra ID, and your endpoints, decide how long it is kept, and set up a review someone actually performs, so the question of who opened a record has an answer.
Breach readiness before there is a breach
Individuals must be notified without unreasonable delay and no later than 60 calendar days after a breach is discovered, with HHS and sometimes the media notified as well depending on how many people are affected. Meeting that clock depends on knowing quickly what was accessed. We build the incident plan, the evidence capture, and the logging that make that possible.
What the regulation text actually says, in plain terms.
These come straight from 45 CFR Parts 160 and 164. They are the points we see misunderstood most often, and each one changes a decision you will make.
- Business associates are directly covered by the Security Rule. A practice management vendor, a billing company, or an IT provider that handles PHI has its own obligations, including its own risk analysis, not just a signature on an agreement.
- Addressable is a decision, not an exemption. Each addressable specification needs an assessment and, if you do not implement it, a documented reason and an equivalent alternative where reasonable. An undocumented gap reads as a missing control.
- Security Rule documentation is kept for six years from when it was created or last in effect. Policies, risk analyses, and decisions that were replaced still need to exist.
- Breach notification has fixed outer limits. Individuals within 60 calendar days of discovery at the latest; HHS at the same time for breaches affecting 500 or more people, or in an annual log for smaller ones; and prominent media outlets when more than 500 residents of a State are affected.
Four positions we take on healthcare engagements.
We start from the risk analysis, not a product
Everything we recommend traces back to a risk we found in your environment. That keeps the spend proportionate, which the rule explicitly allows, and it means every control has a written reason when somebody asks why it is there.
We do the IT side; your counsel does the law
We are not attorneys and do not give legal advice. Breach determinations, notification decisions, and contract terms belong with your counsel. We give them what they need to decide quickly: what happened, what was accessed, and what the logs show.
We write the decisions down as we make them
Addressable specifications, risk acceptances, and exceptions get recorded at the time, with a date and an owner. Reconstructing that reasoning a year later is where most HIPAA documentation falls apart.
We stay after the project ends
The rule expects security measures to be reviewed and updated as things change, so this is ongoing work rather than a one-off. Managed clients keep the standard response commitments alongside it: five minutes on critical, ten on high, thirty on the rest, delivered remotely.
Six kinds of organization that need this work.
Independent medical and dental practices
Small practices are covered entities like any hospital, and the rule lets the safeguards scale to your size. What does not scale away is the risk analysis. Most practices we meet have an EHR vendor's assurances and little else in writing.
Specialty clinics and multi-site groups
More locations means more devices, more shared accounts, and more vendors touching PHI. The work here is consistency: one standard applied everywhere, and one inventory of who has access to what.
Behavioral health and therapy practices
Often small, often remote-first, and often running PHI through email and video tools that were set up quickly. Getting the tenant, the devices, and the vendor agreements right matters more here because the records are among the most sensitive there are.
Digital health and health tech companies
A company that hosts or processes PHI for providers is a business associate, with its own Security Rule obligations. These companies also tend to face SOC 2 requests from the same customers, and much of the evidence serves both.
Billing, coding, and practice management services
Classic business associates. You handle PHI every day on behalf of many covered entities, and each of them will eventually ask what you do to protect it. A current risk analysis and clear controls answer that once.
Anyone who just had a scare
A phishing incident, a lost laptop, a former employee who still had access. The question then is whether it is a reportable breach, and the answer depends on what you can prove. We help you establish the facts and make sure the next incident is easier to answer.
Five stages, from inventory to an ongoing program.
- 1
Find where ePHI lives and moves
Systems, mailboxes, file shares, devices, cloud apps, and every vendor that touches PHI. This inventory is the scope for everything that follows, and it is usually larger than anyone expects.
- 2
Risk analysis
An assessment of the risks to the confidentiality, integrity, and availability of that ePHI, rated by likelihood and impact, written so a reader can follow the reasoning.
- 3
Risk management plan and remediation
A dated plan with owners, then the work itself: multifactor sign-in, device encryption and management, Microsoft 365 configuration, logging, backup protection, and access cleanup, highest risk first.
- 4
Policies, decisions, and breach readiness
Policies that describe what you actually do, documented decisions on addressable specifications, the business associate inventory, and an incident plan you have rehearsed once.
- 5
Keep it current
Periodic review of the risk analysis as systems and vendors change, log review, access reviews, and updated documentation, kept for the six years the rule requires.
What US healthcare organizations ask about HIPAA and IT.
Fifteen questions to answer before anyone else asks them.
The required documents
- Do you have a written risk analysis of where ePHI lives?Required, and the foundation for everything else.
- Is there a dated risk management plan with owners?The analysis without a plan shows known, untreated risk.
- Are addressable decisions documented?Including the reason and any alternative measure.
- Is a security official named?One person, accountable, written down.
- Is documentation kept for six years?Including superseded versions.
The technical safeguards
- Does every account that can reach PHI use multifactor sign-in?Email included, not just the EHR.
- Are laptops and phones that hold PHI encrypted and managed?Encryption changes what a lost device means.
- Is audit logging on, retained, and reviewed?Recording activity is required; reviewing it is the point.
- Is access removed promptly when people leave?Including shared mailboxes and cloud apps.
- Is there a data backup plan, and are backups protected from ransomware?The backup plan is Required; offline or immutable copies, restore-tested.
Breach readiness
- Do you know every vendor that touches PHI?Each is a business associate.
- Does each one have an agreement in place?Before access starts, not after.
- Is there a written incident response plan?Reachable when your network is not.
- Could you tell within days what an attacker accessed?The 60-day clock depends on it.
- Has the plan been rehearsed?A first run-through should not be the real event.
The pages around this one.
Compliance services
How HIPAA sits alongside SOC 2, state privacy laws, and the other frameworks we cover.
HIPAA compliance in healthcare IT
Our longer guide to the Security Rule for US healthcare providers.
Microsoft 365 email encryption
Encrypting email that carries PHI, and setting up revocation correctly.
Start with an honest risk analysis.
We map where your ePHI lives, assess the risks, and give you a dated plan in order of priority. If you already have an analysis, we review it against what your environment looks like today.
Related Services
Explore more solutions that work great with this service
IT Compliance
HIPAA, SOC 2, NIST, CMMC, CCPA readiness
Learn moreCybersecurity Audit
Security assessment and compliance audit
Learn moreMicrosoft 365 Email Encryption
Microsoft Purview Message Encryption configuration for US businesses:
Learn moreMicrosoft Purview
Data governance and compliance solutions
Learn moreMFA Solutions
Multi-factor authentication implementation for US businesses on
Learn moreIncident Response Plan Development
Incident response plan development for US organizations: decision
Learn moreAccess Rights Review and Certification
Recurring access certification your auditors accept
Learn moreSOC 2 Readiness
Get audit-ready for the report your buyers ask for
Learn more