HIPAA Compliance
A HIPAA program that protects patients and stands up to investigation.
Every covered entity and business associate must protect PHI and be able to prove it. We run the Security Risk Analysis HIPAA requires, close the gaps it finds, build your policies and BAA inventory, train your workforce and prepare you to respond if a breach happens.
Who this is for
Built for organizations like yours
Home Health & Hospice
Agencies whose PHI lives on mobile devices, in EHRs and in paperwork carried between patient homes.
Practices & Clinics
Providers who have never completed a documented Security Risk Analysis, or haven't updated one in years.
Business Associates
Billing companies, staffing agencies and software vendors that handle PHI on behalf of providers.
The problem
Risks we address
No current Security Risk Analysis
The most frequently cited HIPAA deficiency in enforcement actions, and the foundation every other safeguard depends on.
Unmanaged business associates
Vendors handling PHI without signed BAAs or any review of how they protect it.
Breaches without a plan
Lost devices, misdirected faxes and phishing incidents handled ad hoc, missing notification deadlines.
What's included
How we help
Assessment & Program
- HIPAA Security Risk Analysis
- Privacy Rule and Security Rule gap assessment
- HIPAA policies and procedures
- Privacy and Security Officer support
- Risk management plan with tracked remediation
Operations & Response
- Business associate inventory and BAA management
- EHR access audits and minimum-necessary reviews
- Workforce HIPAA and phishing training
- Breach risk assessment and notification support
- Patient rights request procedures
Aligned with
- HIPAA Privacy Rule
- HIPAA Security Rule
- Breach Notification Rule
- HITECH
- NIST SP 800-66
- 42 CFR Part 2
Our approach
How an engagement runs
Analyze
Inventory where PHI lives and flows, and assess threats and safeguards for each.
Prioritize
Rate each risk and build a management plan with owners and deadlines.
Implement
Put administrative, physical and technical safeguards and policies in place.
Maintain
Train staff, audit access, update the analysis and keep documentation current.
Why Thornshield
Why work with us
Built for Care in the Field
Recommendations that work for clinicians in patients' homes, not just for staff in an office.
Security and Compliance Together
HIPAA safeguards, Conditions of Participation and IT security handled as one program.
Business Associate Ready
When our work involves PHI, we sign a BAA and handle data under the safeguards it requires.
Automation That Saves Hours
Where compliance work is repetitive, we automate it so your team can focus on patients.
FAQ
Common questions
How often do we need a Security Risk Analysis?
HIPAA requires an accurate and thorough risk analysis and ongoing review rather than a fixed schedule. Most organizations update it at least annually and whenever they change systems, locations or vendors.
Is there such a thing as HIPAA certification?
No. HHS does not certify organizations or products as HIPAA compliant. What matters is a documented program: risk analysis, safeguards, policies, training and evidence that you follow them.
We use a HIPAA-compliant EHR. Isn't that enough?
No. The EHR vendor protects its own platform, but you remain responsible for who has access, the devices staff use, your other systems and vendors, your policies and your workforce training.
Works well with
Related services
Talk to us about hipaa compliance
Tell us about your organization and what worries you most. We'll come back with an honest view of your risks and the most practical way to address them.
