Skip to content

HIPAA Compliance

A HIPAA program that protects patients and stands up to investigation.

Every covered entity and business associate must protect PHI and be able to prove it. We run the Security Risk Analysis HIPAA requires, close the gaps it finds, build your policies and BAA inventory, train your workforce and prepare you to respond if a breach happens.

Who this is for

Built for organizations like yours

Home Health & Hospice

Agencies whose PHI lives on mobile devices, in EHRs and in paperwork carried between patient homes.

Practices & Clinics

Providers who have never completed a documented Security Risk Analysis, or haven't updated one in years.

Business Associates

Billing companies, staffing agencies and software vendors that handle PHI on behalf of providers.

The problem

Risks we address

No current Security Risk Analysis

The most frequently cited HIPAA deficiency in enforcement actions, and the foundation every other safeguard depends on.

Unmanaged business associates

Vendors handling PHI without signed BAAs or any review of how they protect it.

Breaches without a plan

Lost devices, misdirected faxes and phishing incidents handled ad hoc, missing notification deadlines.

What's included

How we help

Assessment & Program

  • HIPAA Security Risk Analysis
  • Privacy Rule and Security Rule gap assessment
  • HIPAA policies and procedures
  • Privacy and Security Officer support
  • Risk management plan with tracked remediation

Operations & Response

  • Business associate inventory and BAA management
  • EHR access audits and minimum-necessary reviews
  • Workforce HIPAA and phishing training
  • Breach risk assessment and notification support
  • Patient rights request procedures

Aligned with

  • HIPAA Privacy Rule
  • HIPAA Security Rule
  • Breach Notification Rule
  • HITECH
  • NIST SP 800-66
  • 42 CFR Part 2

Our approach

How an engagement runs

01

Analyze

Inventory where PHI lives and flows, and assess threats and safeguards for each.

02

Prioritize

Rate each risk and build a management plan with owners and deadlines.

03

Implement

Put administrative, physical and technical safeguards and policies in place.

04

Maintain

Train staff, audit access, update the analysis and keep documentation current.

Why Thornshield

Why work with us

Built for Care in the Field

Recommendations that work for clinicians in patients' homes, not just for staff in an office.

Security and Compliance Together

HIPAA safeguards, Conditions of Participation and IT security handled as one program.

Business Associate Ready

When our work involves PHI, we sign a BAA and handle data under the safeguards it requires.

Automation That Saves Hours

Where compliance work is repetitive, we automate it so your team can focus on patients.

FAQ

Common questions

How often do we need a Security Risk Analysis?

HIPAA requires an accurate and thorough risk analysis and ongoing review rather than a fixed schedule. Most organizations update it at least annually and whenever they change systems, locations or vendors.

Is there such a thing as HIPAA certification?

No. HHS does not certify organizations or products as HIPAA compliant. What matters is a documented program: risk analysis, safeguards, policies, training and evidence that you follow them.

We use a HIPAA-compliant EHR. Isn't that enough?

No. The EHR vendor protects its own platform, but you remain responsible for who has access, the devices staff use, your other systems and vendors, your policies and your workforce training.

Talk to us about hipaa compliance

Tell us about your organization and what worries you most. We'll come back with an honest view of your risks and the most practical way to address them.