Protected ePHI
Operating readiness depends on all three safeguard areas working together.
Services · HIPAA Security Readiness
We help covered entities and business associates identify ePHI risks, prioritize safeguards, improve policies and training, and build evidence of the work. We do not certify compliance or provide legal advice.
A structured review looks at what is actually configured, actually documented, and actually practised — then identifies where those three disagree.
Risk analysis
Security responsibility
Policies and procedures
Workforce practices
Incident planning
Facility access
Workstation use
Device handling
Media controls
Physical safeguards
Access control
Authentication
Audit capability
Transmission protection
Data protection
Operating readiness depends on all three safeguard areas working together.
Assessment boundaries, legal review, policy creation, technical testing, remediation work, validation, organization-size limits, travel, deliverables, and ongoing support are defined in the applicable agreement before anything begins.
The assessment
Most of the value is in stages two and three — talking to the people who do the work, and looking at what is actually configured. A report assembled without those is a description of your intentions.
Scope and data gathering. Which systems, locations, and categories of information are in scope, who we need access to, and what already exists.
Interviews. How the front desk, clinical or operational staff, and administrators actually handle information on an ordinary day.
Evidence and technical review. Existing documentation alongside the configuration of the systems it claims to describe.
Risk analysis and findings. Each gap written in terms of what it exposes and what it would take to close, not as a control-number citation.
Leadership readout. A conversation with the owner, practice manager, or operations lead in business language — plus follow-up guidance.
Remediation & maintenance
The deliverable that matters is the prioritized remediation plan: the gaps ordered by risk and effort, with an owner against each one. Some items are technical and we can implement them. Some are policy, training, or operational decisions that have to stay with your organization — the plan says which is which.
Workforce training usually appears on that list. Giving staff the practice and guidance to recognize a suspicious message and report it safely is one of the few safeguards that improves every other one.
Which remediation work we carry out, which stays with your team, validation of completed items, re-assessment cadence, and any ongoing readiness support.
Environments change. A point-in-time assessment describes the point in time it was carried out, which is why readiness is maintained rather than achieved.
Serving an organization subject to Texas requirements? ICT Solutions can include Texas-specific privacy and security readiness work in the defined scope where applicable.
This is the service where misleading marketing does the most damage, because the buyer often cannot tell the difference until an investigator asks. Here is exactly where our responsibility ends.
We assess, advise, implement safeguards, support documentation, and help improve readiness. We cannot confer compliance, and we cannot grant immunity from enforcement. Those obligations remain with your organization.
We distinguish the HIPAA Security Rule requirements currently in effect from proposals that may change before a final rule is issued. A readiness scope follows the requirements and effective dates that apply to your organization.
We do not determine which requirements apply to your organization or interpret your obligations. Where that question is live — including whether and how Texas HB 300 applies to you — it is worth qualified legal or compliance counsel.
Layered safeguards and documented, prioritized corrective action reduce risk and improve your position. They do not remove it, and an assessment does not prevent an incident from occurring. How we talk about the work
Usually in this order, and usually after a peer has had a scare.
No. Compliance is a legal obligation of your organization, not something a technology provider can confer. Any vendor telling you otherwise is describing something they cannot deliver.
What an assessment does is establish where you actually stand, document the risk, and give you an ordered plan for improving readiness. That is the thing an investigator, an insurer, or an acquirer will want to see — evidence of a genuine, documented, acted-upon process.
There is no government-recognized HIPAA certification that a provider can award to a covered entity. Plenty of companies sell seals; the seal evidences that you paid for the seal.
What holds up is documentation: a completed risk analysis, a prioritized remediation plan, records of what was fixed and when, and evidence of workforce training. We produce those rather than a logo.
It depends on the number of locations, systems, and people in scope, and on how much documentation already exists. We scope it before it starts and tell you the timeline for your organization rather than quoting an average that would not apply to you.
The one thing worth knowing up front: the interview stage needs time from people who are usually busy, and it is the stage that most affects the quality of the result.
Both, within scope. Technical remediation — access controls, encryption, configuration, backup arrangements — is work we can carry out, and it is quoted explicitly rather than assumed.
Policy decisions, staffing, workflow changes, and anything requiring legal interpretation stay with your organization. The plan names an owner for every item so nothing sits in the gap between us.
We do not make that determination. Which privacy requirements apply to your organization depends on where you operate, what information you handle, and your relationships with other entities — that is a legal question, and a costly one to get wrong on a vendor's say-so.
Tell us which requirements you or your counsel have confirmed apply, and we scope the assessment to them. If you are not sure, that is the first conversation to have, and not with us.
A readiness review establishes what is configured, what is documented, and what your team actually does — then turns the distance between those into a plan with owners and an order.
Or call (734) 772-9499 · A human answers