Skip to main content
About

We built this because nobody else was.

The HIPAA, OCR, and cyber-insurer landscape is written for hospital systems. Small practices read it and freeze. We translate it into plain English and a printable checklist.

Why we exist

Why this exists

Small clinical practices — 1 to 25 providers — carry the same regulatory obligations as a regional health system, at a fraction of the staffing. The MSP that runs IT usually can't sign the BAA or draft the breach letter. The cyber insurer wants a Security Risk Analysis but won't help you write one. The law firm bills in 6-minute increments. HackFirstAid Medical sits in that gap.

Who's behind it

Who's behind this

HackFirstAid Medical is built by practitioners who've sat on the practice side of a cyber incident — former HIPAA privacy and security officers, healthcare-focused incident responders, and a healthcare attorney we consult with on regulatory questions. We've handled ransomware events at independent specialty practices, written OCR responses, sat across from cyber-insurer adjusters, and translated NIST 800-66 into checklists a one-person back office can actually use.

We're a small, deliberately quiet team. We don't put founder photos and LinkedIn badges on the site because the work — the playbooks, the self-check, the regulatory grid — is what should earn your trust, not credentials hanging in a frame. If you want to talk to a human before signing anything, book the free first call and you'll be on the phone with one of us.

Our editorial stance: no referral fees from any vendor we name, no kickbacks from the cyber insurers we reference, and a hard 1–25 provider ceiling on who we serve.

Guardrails

What we are not

  • Not a law firm. Nothing on this site is legal advice. We refer to counsel when you need them.
  • Not your incident-response vendor of record. Your cyber insurer chooses that. We work alongside them.
  • Not a Business Associate by default. Reading this site does not create a BAA relationship. See scope of use.
  • Not for hospitals, FQHCs, or chains. Out of scope by design — the playbooks would lie to you.
The family

The HackFirstAid family

HackFirstAid Medical is one of twelve audience-specific sites. The same calm, plain-language posture extends to individuals & families, small & mid-sized business, municipalities, K-12 districts, boards & trustees, executive leadership, IT teams & MSPs, law firms, pension administrators, family offices, and households. See the family grid on the home page.

Want to talk?

Free first call. Practice owner, administrator, MSP, or someone who's about to call their cyber insurer — we'll figure out together whether we're the right fit.

Book a call →
Built by

Travis R. Barlow.

25+ years in incident response. 580+ engagements. Founder of AtlSecCon, one of Canada's longest-running security conferences. No SDR, no junior associate — you talk to the person who has run this incident before.

25+
years IR
580+
engagements
1–25
provider ICP
Scenarios we have walked practices through

Illustrative composites drawn from practitioner conversations. No patient or practice identifiers.

  • Ransomware · Friday afternoon

    Walked the office manager of an 8-provider primary-care clinic through the first three hours — who to call, what not to touch, and what the 60-day HIPAA clock meant.

  • Cyber-insurer renewal

    A 3-provider dermatology clinic pulled the playbooks, customized two pages, and the underwriter accepted the plan — instead of a $9,000 consulting engagement.

  • BEC wire-fraud attempt

    A 5-provider OB/GYN group had read the Front-Desk Email Compromise playbook the week before. Their dual-approval rule caught the wire and prevented the loss.

  • MSP handoff to physician-owner

    The HIPAA self-check produced a one-page gap list an MSP could hand to a physician-owner — no jargon translation required.

Upgrade — vCISO

Your MIPS-ready SRA — and a named owner for the 60-day clock.

Training gets your people ready and advisory is there when something breaks. When you need someone to own the program — the HIPAA Security Rule, your annual SRA, and 405(d) “reasonable security” — and be the name your OCR, cyber insurer, EHR/clearinghouse business associates, and (in Canada) your provincial health privacy commissioner can point to, that’s the HackFirstAid vCISO: a security leader on retainer. Built for the EHR/vendor ransomware event mid-clinic-day, where the breach clock starts before the schedule clears.

We own your program

Strategy, risk register, roadmap, governance, cadenced reviews, and the OCR, cyber-insurer, EHR/clearinghouse BA, and provincial privacy commissioner conversations.

Independent partners execute

DFIR, SOC, pen-testing, tooling, legal, brokerage — coordinated by your vCISO, never sold by us.

Small Practice
CA$1,800/mo
Solo & the smallest offices — quarterly cadence
Foundations
CA$3,000/mo
Managed
CA$6,500/mo
Most chosen
Embedded
CA$12,000/mo

Billed annually. Every tier includes a named vCISO, a 90-day on-ramp, and household coverage.