The one thing the rule actually requires you to have
Most pages written for a practice of your size tell you that everything is mandatory. That is not true, and a practice manager who checks one sentence and finds it overstated stops believing the rest. So this page does the opposite. It names what the Security Rule requires, names what it leaves to your judgment, and names the controls we sell that it does not ask for at all.
Start with the one that has no discretion in it. 45 CFR 164.308(a)(1)(ii)(A) is marked Required, and it says a covered entity must conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of the electronic protected health information it holds. There is no size threshold. A practice of three people carries the same requirement as a hospital system, and either the document exists or it does not.
What follows is a description of the rule as it is written, not an assessment of your practice. We have not seen your systems and we are not in a position to tell you where you stand against any of it. You can read every section named on this page yourself, and we would rather you did.
What “accurate and thorough” has meant in practice
Those three words are where the enforcement happens. OCR has an enforcement initiative aimed specifically at this one specification, and the finding it records reads the same way each time: the entity failed to conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity and availability of the electronic protected health information it holds.
Read that finding carefully, because it is not the finding people expect. It is not that no document existed. It is that the analysis was not accurate and was not thorough. An assessment that names none of your systems, no vendor you actually use and no mailbox you actually run is a document rather than an analysis, and it is the shape of thing that escalates an investigation rather than closing one.
A behavioural health practice has a second rulebook
If your practice is a part 2 program, 42 CFR 2.16 applies on top of HIPAA. It requires formal policies and procedures to reasonably protect against unauthorized uses and disclosures of patient identifying information, and it addresses paper records and electronic records separately: transfer, destruction, secure storage, workstation access and de-identification for paper, and creation, receipt, maintenance, transmission, destruction and access for electronic. Subsection (b) applies the HIPAA breach rules to part 2 programs for breaches of unsecured records.
Two dates matter and they are recent. SAMHSA’s final rule was published on 16 February 2024 and took effect on 16 April 2024, with a two-year implementation period. OCR announced the civil enforcement program on 13 February 2026 and began accepting Part 2 complaints on 16 February 2026.
One duty in that section is worth naming on its own, because it is the part a forensics practice is better placed to serve than an IT vendor. 2.16 reaches the sanitisation of media before disposal, and it reaches paper printouts as well as drives. Wiping a device so that what was on it cannot be recovered, and writing down that it was done, is evidence work rather than helpdesk work.
What happened to two practices like yours this year
Two OCR settlements from 2026 land on this buyer exactly. Both failed the same Required specification. One is a practice and one is the vendor a practice trusted.
A behavioural health centre, 1,980 patients
On 19 February 2026 OCR announced a settlement with Top of the World Ranch Treatment Center, an Illinois substance use disorder treatment provider. The practice had filed a breach report in March 2023 after a phishing attack reached electronic protected health information through one workforce member’s email account, affecting 1,980 patients. OCR found that it had failed to conduct an accurate and thorough risk analysis. The practice paid $103,000 and agreed to a corrective action plan OCR monitors for two years. It was the eleventh action under the risk analysis initiative.
One email account. Not a sophisticated intrusion, not a targeted campaign against a treatment centre, and not a failure of a product nobody had bought. A member of staff was phished, and what turned an incident into an enforcement action was the state of the paperwork behind it.
The vendor that never told its dental clients
On 5 March 2026 OCR announced a settlement with MMG Fusion, a dental technology business associate. An unauthorized actor had reached its systems in December 2020 and taken the information of roughly 15 million people, including names, addresses, dates of birth and appointment times. OCR did not learn of it until a complaint was filed in March 2023. It found that MMG had impermissibly disclosed the information, had failed to conduct an accurate and thorough risk analysis, and had failed to notify the covered entities it served. MMG paid $10,000, with consideration given to its financial position, and agreed to a three-year corrective action plan. The company no longer operates.
This is the answer to the most common objection we hear from a practice of this size, which is that the practice management vendor handles all of this. The dental practices whose patients those 15 million people were did not find out from their vendor. They were not told at all.
The 2026 count is worth dating rather than stating. Those two were the eleventh and twelfth actions under the initiative as at March 2026. The number had reached thirteen by 23 April 2026 and continued to move, so treat any current total you read, including this one, as a figure with a date on it.
One number about practices of your size, stated with its source and its date, because it is usually quoted without either. In its 2025 healthcare data breach report, published on 13 February 2026, HIPAA Journal analysed the 710 breaches of 500 or more records on the OCR portal for that year and banded them by size: 146 affected 500 to 999 records and 309 affected 1,000 to 9,999. That is 455 of 710, or 64 percent, involving fewer than 10,000 records.
Now the two qualifications that figure needs. It is a share of the breaches that were reported, not a rate at which small practices are attacked, and no such rate exists, because nobody knows how many incidents were never reported. And it is a snapshot: the OCR portal has since listed more breaches for 2025 than the 710 that share was computed against, and the share cannot be restated against a larger total without recounting the bands. Take it as evidence that small breaches dominate the reported record as at February 2026, which is what it says, rather than as a probability about your practice, which it does not say.
This page is about protecting your practice. If you came looking for the other thing we do, the forensic examination of a device or an account as evidence in a dispute, that sits elsewhere on this site. The same offering for regulated financial firms is at managed security and compliance, where the service calendar and the control map behind that record are set out in full.
- A direct line to Quinn, the founder, not a sales pipeline.
- Worked in-house by the examiner who scoped it.
- Explainable findings you can verify, with the methodology shown.
Required, addressable, and neither
The Security Rule sorts its contents into two kinds, and almost every page written about it blurs them. Required means what it says. Addressable does not mean optional, and it does not mean mandatory either: under 164.306(d)(3) you assess whether the specification is reasonable and appropriate for your practice, and where it is not, you document why and implement an equivalent alternative measure where that is reasonable. The written, reasoned decision is the thing the rule wants. Skipping the control without recording the reasoning is the failure, not skipping the control.
Below are the fourteen Required requirements that reach a practice of your size, and the sixteen Addressable specifications, listed individually so you can count them yourself rather than take our number for it. Two of the fourteen are standards rather than implementation specifications, and are marked as such.
Required: fourteen requirements, and what produces each record
| Citation | What it is | What produces the record |
|---|---|---|
| 164.308(a)(1)(ii)(A) | Risk analysis | The compliance program build, then the annual refresh |
| 164.308(a)(1)(ii)(B) | Risk management | Remediation and hardening hours, and the risk management plan they work from |
| 164.308(a)(1)(ii)(C) | Sanction policy | The policy pack, adopted by the practice with its own counsel |
| 164.308(a)(1)(ii)(D) | Information system activity review | The monthly control drift review and the quarterly privileged access and patch report |
| 164.308(a)(2) | Assigned security responsibility (a standard, with no implementation specifications) | The practice names its own security official. We do not fill this role. |
| 164.308(a)(4)(ii)(A) | Isolating health care clearinghouse functions | Usually inapplicable to a practice of this size, and we would rather say so than pad the table |
| 164.308(a)(6)(ii) | Response and reporting | The written incident response program. The response itself is billed separately. |
| 164.308(a)(7)(ii)(A) | Data backup plan | Backup of every server, laptop and mailbox, with a proven restore |
| 164.308(a)(7)(ii)(B) | Disaster recovery plan | The compliance program build |
| 164.308(a)(7)(ii)(C) | Emergency mode operation plan | The compliance program build |
| 164.308(a)(8) | Evaluation (a standard, with no implementation specifications) | The annual column of the service calendar |
| 164.308(b)(3) | Written contract or other arrangement | The vendor inventory and due diligence file, and our own business associate agreement |
| 164.312(a)(2)(i) | Unique user identification | Named users, and the new starter, leaver and device setup work |
| 164.312(a)(2)(ii) | Emergency access procedure | The compliance program build |
Addressable: sixteen specifications, and why the decision is the deliverable
Every row below is one you may reasonably decide not to implement, provided you record why and put something equivalent in its place where that is reasonable. Notice what is in this list rather than the one above. Encryption appears twice, at rest and in transmission, and both are addressable.
| Citation | Specification |
|---|---|
| 164.308(a)(3)(ii)(A) | Authorization and supervision |
| 164.308(a)(3)(ii)(B) | Workforce clearance procedure |
| 164.308(a)(3)(ii)(C) | Termination procedures |
| 164.308(a)(4)(ii)(B) | Access authorization |
| 164.308(a)(4)(ii)(C) | Access establishment and modification |
| 164.308(a)(5)(ii)(A) | Security reminders |
| 164.308(a)(5)(ii)(B) | Protection from malicious software |
| 164.308(a)(5)(ii)(C) | Log-in monitoring |
| 164.308(a)(5)(ii)(D) | Password management |
| 164.308(a)(7)(ii)(D) | Testing and revision procedures |
| 164.308(a)(7)(ii)(E) | Applications and data criticality analysis |
| 164.312(a)(2)(iii) | Automatic logoff |
| 164.312(a)(2)(iv) | Encryption and decryption, for data at rest |
| 164.312(c)(2) | Mechanism to authenticate electronic protected health information |
| 164.312(e)(2)(i) | Integrity controls |
| 164.312(e)(2)(ii) | Encryption, in transmission |
Neither: the controls your insurer requires and the rule does not
Multi-factor authentication is named nowhere in 45 CFR 164.312. That section has not been amended since 2013, and the phrase does not appear in it. Two of its standards carry no implementation specifications at all: 164.312(b), audit controls, and 164.312(d), person or entity authentication. Multi-factor login is one way to satisfy the authentication standard. It is not a thing the Security Rule asks for by name, and any page telling you otherwise is describing a rule that does not exist yet.
The proposal people are thinking of is real and it is still a proposal. The January 2025 notice that would make multi-factor authentication and encryption mandatory was published at 90 FR 898 under RIN 0945-AA22. It has moved to long-term actions, with final action anticipated in July 2027. Until that happens, encryption stays addressable and multi-factor login stays unnamed.
So why is multi-factor authentication on every plan on this page? Because your cyber insurer treats it as a condition of binding coverage, and because it is the single control that most reduces the exact failure that cost the treatment centre above $103,000. We would rather tell you that we include it for those two reasons than let you believe a regulator requires it. If the honesty of that sentence is the only thing you take from this page, it is doing its job.
The four plans
| What you get | Monitor $995 per month Up to 10 named users and 12 protected devices You have IT covered and your compliance paperwork is current. | Managed IT $1,595 per month Up to 10 named users and 12 protected devices You want us to be your IT department, and your paperwork is current. | Monitor + Comply $1,950 per month Up to 10 named users and 12 protected devices Recommended You have IT covered but need the compliance program built and kept. | Complete $2,495 per month Up to 10 named users and 12 protected devices You want one firm accountable for all of it. |
|---|---|---|---|---|
| Protection | ||||
| Backup of every server, laptop and mailbox | Included | Included | Included | Included |
| Managed detection and response on every device | Included | Included | Included | Included |
| Multi-factor authentication across all five access points | Included | Included | Included | Included |
| Email filtering and security awareness training | Not included | Included | Not included | Included |
| Patch management to a stated target | Not included | Included | Not included | Included |
| Proof | ||||
| Dated monthly evidence pack for your records | Included | Included | Included | Included |
| Quarterly restore test, documented | Included | Included | Included | Included |
| Quarterly privileged access and patch compliance report | Included | Included | Included | Included |
| Cyber insurance application support, from records | Included | Included | Included | Included |
| Day-to-day IT | ||||
| Helpdesk for your staff | Not included | Included | Not included | Included |
| New starters, leavers and device setup | Not included | Included | Not included | Included |
| Remediation and hardening hours included each month | Not included | 2 hrs | Not included | 2 hrs |
| Written security program and risk analysis | ||||
| Written risk analysis and risk management plan, refreshed annually | Not included | Not included | Included | Included |
| Patient notification decision file, including the reasons not to notify | Not included | Not included | Included | Included |
| Written incident response program, reviewed annually | Not included | Not included | Included | Included |
| Vendor inventory, due diligence and business associate agreements | Not included | Not included | Included | Included |
| Annual tabletop exercise with written after-action report | Not included | Not included | Included | Included |
| Records schedule and a document pack you can hand to an insurer | Not included | Not included | Included | Included |
Getting started: deployment and a first verified restore is a one time $9,500. The compliance program build is a one time $12,500, required once on the two plans that include it.
Plans start at $995 per month. Every plan price on this page is stated at the same size: up to 10 named users and 12 protected devices, on a 12 month term, billed monthly. A practice smaller than that pays the same monthly figure, so a three-person practice should weigh it against what a single incident and the corrective action plan behind it would cost, rather than against a per-seat rate.
Which plan a practice usually starts on, and the question that decides it. Monitor + Comply, at $1,950 per month, is the usual answer, for two reasons that follow from the tables above. Nine of the fourteen Required requirements produce a document rather than a running control, and all sixteen Addressable ones require a written decision, so most of what the rule asks for is the Comply half. And the systems that hold most of your patient data, the electronic health record and the practice management system, are not yours to monitor. We say what we can reach: endpoints, mailboxes, backups and the paperwork.
Complete adds the day-to-day IT, and the question that routes between the two is worth asking out loud at your next staff meeting. Who patches your workstations today, and can they show you a dated record of having done it? If someone can, Monitor + Comply sits above them and produces the record. If nobody can, the honest answer is Complete, because the patch evidence in your quarterly report has to come from somewhere.
Your insurance application, control by control
Must have
One carrier's own bind-condition sheet marks controls of this kind as required before it will bind coverage. These are the ones that stop a deal.
Changes the price
You can get a policy without it, but it costs more, or you get lower limits.
On the form
They ask, and the answer goes on file, but on its own it rarely stops anything.
| What the application asks | Monitor | Managed IT | Monitor + Comply | Complete |
|---|---|---|---|---|
| Must have | ||||
| Two-step login (MFA) on email | Covered | Covered | Covered | Covered |
| Two-step login on any way in from outside the office | Covered | Covered | Covered | Covered |
| Security software on every laptop and server | Covered | Covered | Covered | Covered |
| Backups an attacker cannot reach or overwrite, and proven to restore | Covered | Covered | Covered | Covered |
| Calling to confirm a payment before you send it, and a second person approving large onesA must-have for the part of the policy that covers being tricked into sending money, rather than for the policy as a whole. | Covered | Covered | Covered | Covered |
| Changes the price | ||||
| Two-step login on the accounts that can change everything, and on the backup system | Covered | Covered | Covered | Covered |
| What share of devices are covered, and whether the software cuts an infected one off the network by itself | Covered | Covered | Covered | Covered |
| Backups kept apart from the day-to-day network, so one break-in cannot take both | Covered | Covered | Covered | Covered |
| Someone has actually restored a file from backup and written down that it worked | Covered | Covered | Covered | Covered |
| Email screened before it arrives, and attachments opened somewhere safe first | Not covered | Covered | Not covered | Covered |
| How fast you install urgent security updates, and how often you hit that target | Not covered | Covered | Not covered | Covered |
| How many accounts can change anything, and why each one needs to | Covered | Covered | Covered | Covered |
| On the form | ||||
| Software the maker has stopped fixing, still in use | Covered | Covered | Covered | Covered |
| Staff training, and test phishing emails sent to see who clicks | Not covered | Covered | Not covered | Covered |
| A written plan for a break-in, rehearsed once a year | Not covered | Not covered | Covered | Covered |
| Checking the outside companies that touch your patient data | Not covered | Not covered | Covered | Covered |
These are questions from real insurance applications. Where a plan does not cover something, we say so here rather than let you find out on the form.
What we do, and how often
Every month
- Control drift reviewProduces: A triaged, recorded list of what stopped reporting and what was escalated
- Backup verificationProduces: Confirmation that every server, laptop and mailbox is backed up
- Evidence packProduces: A dated snapshot of every device and user, filed to your archive
Every quarter
- Restore testProduces: A written result for a real file set restored from backup
- Patch compliance reportProduces: Performance against a stated target, with the rolling twelve-month rate
- Access exception reviewProduces: A record of new devices, bypass codes and administrator accounts
- Report to your security officialProduces: One page: what changed, what lapsed, what needs a decision
Every year
- Risk analysis refreshProduces: An updated written analysis naming your systems, and the risk management plan that follows from it
- Privileged account reviewProduces: Every administrator account listed with a written reason it still exists
- End-of-life inventoryProduces: A written statement of what protects anything the maker no longer supports
- Insurance evidence packProduces: The control sections of your application or renewal, supported by dated records
The written program
Included in Monitor + Comply and Complete. The risk analysis is the centre of it, and it is built from your own inventory rather than from a template: every device, user, mailbox, server and vendor that touches electronic protected health information, what could go wrong with each, what is already in place, and what is left. The risk management plan at 164.308(a)(1)(ii)(B) is the list of what you decided to do about the gaps, with dates.
Around it sits the rest of the paperwork the tables above call for. The policy pack the practice adopts, including the sanction policy. The written incident response program, keeping assessment, containment and notification separate and visible. The patient notification decision file, which records why you decided not to notify where that was the outcome, because that is the record you would want if the decision were questioned later. The vendor inventory, the due diligence behind it and the business associate agreements the written arrangement requirement asks for. And a records schedule and document pack so an insurance renewal or an OCR request is answered from a folder rather than from a scramble.
It is refreshed every year, and that is not a subscription mechanic. The evaluation standard at 164.308(a)(8) asks for periodic evaluation, and a risk analysis describing an environment you no longer run has stopped being accurate, which is the word the requirement uses.
An honest boundary. We prepare these documents for the practice to review, revise and adopt. We are not lawyers and we do not give legal or regulatory advice. Where a judgment call belongs to the practice, we set it up so the decision is easy to make and easy to evidence, and then you make it.
What this means for you
- Written scope before any work. You see a written scope covering deliverables, timeline, and price, and you approve it before we begin. You are never billed for work you did not authorize.
- We commit to findings, not outcomes. We tell you up front what the evidence can and cannot establish. Recovery, attribution, and prosecution are decided by banks, platforms, insurers, and courts. We produce the record they act on, and we put that distinction in writing.
- Every case is investigated, not just scanned. A credentialed examiner reviews every case before findings leave the practice. You get a documented investigation to court-admissible standards, not a single automated scan and a one-line answer.
- We will tell you if you do not need us. If a free or simpler step would resolve your situation, whether a police report, an IC3 filing, or a platform's own recovery flow, we point you there first.
What is in scope, and what is not
We do
- Configure, monitor and maintain every product in your plan
- The monthly, quarterly and annual work in the service calendar above
- Deliver a dated evidence pack to your archive every month
- Support one insurance application or renewal each year
- Escalate anything we find, with a written record
- On Managed IT and Complete: helpdesk, new starters and leavers, device setup, and two hours of remediation and hardening every month
We do not
- Acting as your named security official under 164.308(a)(2)
- Helpdesk on the two Monitor plans, which stays with your existing IT provider
- Incident response and forensics inside the monthly fee, which is billed separately
- Monitoring inside your electronic health record or practice management system, which we do not control
- Buying or owning your hardware, software licenses, phones or cabling
- Legal, regulatory or insurance advice
- Writing or sending your breach notifications
- Work on site or outside business hours, except by arrangement
You do
- Name your security official under 164.308(a)(2), and tell us if that changes
- Name a primary and a backup technical contact
- Respond within four business hours when we escalate something urgent
- Review and adopt the policies we prepare, with your own counsel
- Own the accuracy of anything you file with a regulator, a payer or an insurer
- Tell us before you add people, locations, systems or vendors
- Keep your existing IT resource in place on the Monitor plans, or tell us if that ends
Written plainly here so nothing is a surprise in month three. The agreement carries the same boundaries in full.
If the worst happens
Most providers hand you off at the worst possible moment. We do not. The people who protect your practice are the same people who examine the devices and accounts and write the report, and stand behind it if it is ever challenged.
Hour one to day ten
- Hour one, contain and preserve. We take your call and stop the bleeding. We capture evidence to forensic standard from the first minute, with chain of custody intact. Most of what is lost in a breach is lost in the first few hours, by well-meaning people rebooting machines.
- Days one to five, examine. Our examiners work the images and the logs. What got in, how, what it touched, what left the building, and whether patient information was actually reached. That last question is the one your notification decision turns on, and it is the question a mailbox compromise is hardest to answer without preserved evidence.
- By day ten, report. A written forensic report the practice, your insurer and if necessary a regulator can all read. Written to be defensible, because we write reports that go to court.
- Then notify, rebuild, and if needed testify. The report feeds your notification decision and the record behind it. We rebuild the environment. If the matter is litigated, our examiners give evidence.
Who does the work
A digital forensics practice. Quinn holds a degree in cybersecurity from SANS Technology Institute and 9 active GIAC certifications across GIAC, including incident handling, intrusion analysis and mobile forensics. That credential mix is what supports qualification as an expert witness under the Daubert and Frye standards.
You can always get a second opinion. You may bring in an independent examiner at any point, for any reason, and we will hand over the images, the logs and our working papers to help them.
A great deal of what practices call us for is not an outside attacker at all. A departing employee who took a patient list. A dispute where the record sits in a mailbox or on a phone. A device that has to be wiped and certified before it leaves the building. Those are the same skills, applied before anything has gone wrong.
The first ninety days
- Days 1 to 10, discovery and paperwork. We inventory every device, user, mailbox and vendor, which is also the raw material of the risk analysis. You get our own due diligence pack and our business associate agreement. We hand it over before you ask, because you are about to make us one of the outside companies that touches your patient data, and you should be able to answer for us the way you would answer for any other vendor.
- Days 10 to 30, deployment. Backup, endpoint protection and monitoring on every device. Multi-factor login across all five access points. First backup taken and first restore proven, not assumed.
- Days 30 to 60, the program. On the Comply plans: the risk analysis written and the risk management plan drawn from it, incident response program drafted, notification templates prepared, vendor inventory built and the agreements put in place. The practice reviews and adopts.
- Days 60 to 90, proof and rehearsal. First full evidence pack delivered. First tabletop exercise run, with the written after-action report. If you are placing or renewing insurance, we assemble the control evidence for your broker.
What we need from you to start: the name of your security official, a named technical contact and a backup, administrative access to your Microsoft or Google tenant, a list of every vendor that touches patient information, and your current policies however incomplete.
Rates, growth and the small print
Project and hourly rates
| Work | Standard | On a plan |
|---|---|---|
| Remediation beyond the included allowance | $400/hr | $195/hr |
| Security consulting, assessment and hardening | $400/hr | $275/hr |
| Incident response, containment and rebuild | $400/hr | $275/hr |
| Forensic examination and written report | $400/hr | $325/hr |
| Deposition and trial testimony, four-hour minimum | $400/hr | $400/hr Same as the standard rate. |
| Done-for-you device forensics | from $2,000 | from $2,000 Same as the standard rate. |
| Refundable engagement retainer | $5,000 | Waived |
All rates per hour unless stated. There is no surge for nights, weekends or holidays, on either column. Court time is never discounted, because the hour is the same hour whoever is paying for it.
As your practice grows
Additional named user
$35/mo
Additional workstation
$25/mo
Additional server
$70/mo
New user setup
$150
User departure and offboarding
$100
New device deployment
$200
Term
Twelve months, billed monthly, renewing unless either of us gives 60 days' notice.
Your data
Your tenants are yours. On exit we return your records in a usable format within 30 days and certify what we destroyed.
Our duty to you
We are your business associate, we sign a business associate agreement before we touch anything, and we will tell you within 72 hours of becoming aware of a breach affecting a system that holds your patient information. The breach notification decision, and the notice itself, stay with the practice.
Insurance
We recommend you carry cyber cover and we supply the control evidence to your broker. We are not licensed in insurance and give no insurance advice.
Growth is reviewed quarterly, effective from the date of the change. Devices count by type, because a server costs several times what a laptop does. Where a vendor sells licenses in blocks, that block is invoiced in full when it is bought.
How an engagement begins
- A scoping call. Forty-five minutes. We walk your environment and put a fixed number against what it would take to run it properly. There is no charge and no obligation, and we do not produce a written finding about your current state unless you ask us to.
- Written scope. Deliverables, timeline and price, approved by you before any work begins.
- Discovery, deployment and the program. The ninety days above, with a dated record at every step.
Why this work matters
A practice of six people holds the same information as a hospital wing, with none of the staff to protect it. One requirement in the Security Rule has no discretion in it, and two practices found that out this year over a phished mailbox and a vendor that never called. What we sell is the record: a risk analysis that names your systems, refreshed while it is still accurate, and a dated pack every month that proves what was actually running. If you are also seeing what a small firm buys when it has no IT department, the shape of the offering is the same and only the rulebook changes.
















