Southfield, Michigan, USA · Mon–Fri, 8:00 AM – 6:00 PM ET info@globalclinicaleducation.com
Global Clinical Education Healthcare consulting Request a consultation

HIPAA Privacy & Security

Security risk analysis, policy and BAA review, workforce training, and breach response readiness — the areas OCR investigations consistently turn on.

Most HIPAA enforcement does not begin with a hacker. It begins with a complaint, a lost laptop or a small breach report, and then the investigation asks one question that decides everything that follows: show us your current security risk analysis.

Security risk analysis

The Security Rule requires an accurate, organization-wide risk analysis, kept current. A vendor scan is not one. A checklist is not one. We conduct an analysis that covers every system and location where electronic protected health information is created, received, maintained or transmitted, rates each risk, and produces a risk management plan with owners and dates — the document an investigator will ask for first.

Privacy Rule and operations

  • Notice of Privacy Practices, and whether your actual acknowledgement process matches it
  • Minimum necessary standards applied to real workflows, not just stated in policy
  • Patient right of access — the single most-enforced provision in recent years, and the one most organizations quietly fail on timelines
  • Accounting of disclosures, amendment requests and restriction requests
  • Business Associate Agreements: which vendors need one, whether yours are current, and what your agreements actually obligate you to

Workforce training that counts

Training is required and is almost always the weakest evidence in the file. We build role-specific training — front desk, clinical, billing, IT — with completion tracking that will hold up, rather than one annual module assigned to everyone.

Breach response

The four-factor risk assessment, the notification clock, the documentation of a decision not to notify. These are much easier to get right before an incident than during one. We build the response procedure, then test it against a realistic scenario.

42 CFR Part 2

Behavioral health and substance use programs carry confidentiality obligations that go beyond HIPAA, and the interaction between the two rules causes real operational confusion. We work through both together rather than treating Part 2 as a footnote.

Next step

Tell us what you are up against.

A 30-minute call is usually enough for us to tell you whether you need a full readiness assessment, a focused correction, or nothing at all. We will say so either way. If you are working against a survey deadline or an immediate jeopardy clock, say so and we will call you back the same day.