Skip to main content
Lead magnet · No email required

5-Minute HIPAA Risk Self-Check

Ten questions. Tells you in five minutes whether your small practice would survive an OCR information request, or whether you have a documentation hole worth closing this quarter.

Answered 0 of 10
  1. 1
    An annual Security Risk Analysis has been completed and is filed.
    Required for MIPS Promoting Interoperability and the #1 OCR finding for small practices.
  2. 2
    Every vendor with PHI access has a signed, current Business Associate Agreement.
    Including the EHR, clearinghouse, billing service, MSP, backup, answering service, transcription.
  3. 3
    Every laptop, tablet, and phone with PHI is encrypted and we can prove it.
    BitLocker / FileVault / MDM encryption profile, with management-console evidence.
  4. 4
    MFA is enforced on the EHR, email, and remote-access tools.
    App-based or hardware key. SMS is acceptable as a last resort, not the default.
  5. 5
    An incident-response contact and process is identified and the staff knows who to call.
    Front-desk-readable. Posted somewhere visible. Tested at least once a year.
  6. 6
    Cyber insurance is current and the renewal questionnaire was answered accurately.
    Misrepresentation on the application is the most common reason claims are denied.
  7. 7
    Breach-notification letter templates are pre-staged for OCR, patient, and state AG.
    Drafting under deadline is how clocks get missed. Pre-stage now.
  8. 8
    All workforce members completed HIPAA training this year and attestations are on file.
    Required at hire and annually. Sanction policy referenced in the training.
  9. 9
    A written Sanction Policy exists and has been applied at least once in the last 24 months.
    OCR looks for evidence that the policy is real, not just on paper.
  10. 10
    The OCR breach portal account has been tested and credentials are stored where the privacy officer can find them.
    First-time registration during an active incident is a 4-hour delay you don't have.
Built by

Travis R. Barlow.

25+ years in incident response. 580+ engagements. Founder of AtlSecCon, one of Canada's longest-running security conferences. No SDR, no junior associate — you talk to the person who has run this incident before.

25+
years IR
580+
engagements
1–25
provider ICP
Scenarios we have walked practices through

Illustrative composites drawn from practitioner conversations. No patient or practice identifiers.

  • Ransomware · Friday afternoon

    Walked the office manager of an 8-provider primary-care clinic through the first three hours — who to call, what not to touch, and what the 60-day HIPAA clock meant.

  • Cyber-insurer renewal

    A 3-provider dermatology clinic pulled the playbooks, customized two pages, and the underwriter accepted the plan — instead of a $9,000 consulting engagement.

  • BEC wire-fraud attempt

    A 5-provider OB/GYN group had read the Front-Desk Email Compromise playbook the week before. Their dual-approval rule caught the wire and prevented the loss.

  • MSP handoff to physician-owner

    The HIPAA self-check produced a one-page gap list an MSP could hand to a physician-owner — no jargon translation required.

Upgrade — vCISO

Your MIPS-ready SRA — and a named owner for the 60-day clock.

Training gets your people ready and advisory is there when something breaks. When you need someone to own the program — the HIPAA Security Rule, your annual SRA, and 405(d) “reasonable security” — and be the name your OCR, cyber insurer, EHR/clearinghouse business associates, and (in Canada) your provincial health privacy commissioner can point to, that’s the HackFirstAid vCISO: a security leader on retainer. Built for the EHR/vendor ransomware event mid-clinic-day, where the breach clock starts before the schedule clears.

We own your program

Strategy, risk register, roadmap, governance, cadenced reviews, and the OCR, cyber-insurer, EHR/clearinghouse BA, and provincial privacy commissioner conversations.

Independent partners execute

DFIR, SOC, pen-testing, tooling, legal, brokerage — coordinated by your vCISO, never sold by us.

Small Practice
CA$1,800/mo
Solo & the smallest offices — quarterly cadence
Foundations
CA$3,000/mo
Managed
CA$6,500/mo
Most chosen
Embedded
CA$12,000/mo

Billed annually. Every tier includes a named vCISO, a 90-day on-ramp, and household coverage.