Active Incident? 24/7 Response →

Security & Compliance for Practices

HIPAA Security Risk Analysis for Small Practices

The risk analysis the HIPAA Security Rule requires of a two to ten person medical, dental or behavioural health practice, and the service that produces it.

The one thing the rule actually requires you to have

Most pages written for a practice of your size tell you that everything is mandatory. That is not true, and a practice manager who checks one sentence and finds it overstated stops believing the rest. So this page does the opposite. It names what the Security Rule requires, names what it leaves to your judgment, and names the controls we sell that it does not ask for at all.

Start with the one that has no discretion in it. 45 CFR 164.308(a)(1)(ii)(A) is marked Required, and it says a covered entity must conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of the electronic protected health information it holds. There is no size threshold. A practice of three people carries the same requirement as a hospital system, and either the document exists or it does not.

What follows is a description of the rule as it is written, not an assessment of your practice. We have not seen your systems and we are not in a position to tell you where you stand against any of it. You can read every section named on this page yourself, and we would rather you did.

What “accurate and thorough” has meant in practice

Those three words are where the enforcement happens. OCR has an enforcement initiative aimed specifically at this one specification, and the finding it records reads the same way each time: the entity failed to conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity and availability of the electronic protected health information it holds.

Read that finding carefully, because it is not the finding people expect. It is not that no document existed. It is that the analysis was not accurate and was not thorough. An assessment that names none of your systems, no vendor you actually use and no mailbox you actually run is a document rather than an analysis, and it is the shape of thing that escalates an investigation rather than closing one.

A behavioural health practice has a second rulebook

If your practice is a part 2 program, 42 CFR 2.16 applies on top of HIPAA. It requires formal policies and procedures to reasonably protect against unauthorized uses and disclosures of patient identifying information, and it addresses paper records and electronic records separately: transfer, destruction, secure storage, workstation access and de-identification for paper, and creation, receipt, maintenance, transmission, destruction and access for electronic. Subsection (b) applies the HIPAA breach rules to part 2 programs for breaches of unsecured records.

Two dates matter and they are recent. SAMHSA’s final rule was published on 16 February 2024 and took effect on 16 April 2024, with a two-year implementation period. OCR announced the civil enforcement program on 13 February 2026 and began accepting Part 2 complaints on 16 February 2026.

One duty in that section is worth naming on its own, because it is the part a forensics practice is better placed to serve than an IT vendor. 2.16 reaches the sanitisation of media before disposal, and it reaches paper printouts as well as drives. Wiping a device so that what was on it cannot be recovered, and writing down that it was done, is evidence work rather than helpdesk work.

What happened to two practices like yours this year

Two OCR settlements from 2026 land on this buyer exactly. Both failed the same Required specification. One is a practice and one is the vendor a practice trusted.

A behavioural health centre, 1,980 patients

On 19 February 2026 OCR announced a settlement with Top of the World Ranch Treatment Center, an Illinois substance use disorder treatment provider. The practice had filed a breach report in March 2023 after a phishing attack reached electronic protected health information through one workforce member’s email account, affecting 1,980 patients. OCR found that it had failed to conduct an accurate and thorough risk analysis. The practice paid $103,000 and agreed to a corrective action plan OCR monitors for two years. It was the eleventh action under the risk analysis initiative.

One email account. Not a sophisticated intrusion, not a targeted campaign against a treatment centre, and not a failure of a product nobody had bought. A member of staff was phished, and what turned an incident into an enforcement action was the state of the paperwork behind it.

The vendor that never told its dental clients

On 5 March 2026 OCR announced a settlement with MMG Fusion, a dental technology business associate. An unauthorized actor had reached its systems in December 2020 and taken the information of roughly 15 million people, including names, addresses, dates of birth and appointment times. OCR did not learn of it until a complaint was filed in March 2023. It found that MMG had impermissibly disclosed the information, had failed to conduct an accurate and thorough risk analysis, and had failed to notify the covered entities it served. MMG paid $10,000, with consideration given to its financial position, and agreed to a three-year corrective action plan. The company no longer operates.

This is the answer to the most common objection we hear from a practice of this size, which is that the practice management vendor handles all of this. The dental practices whose patients those 15 million people were did not find out from their vendor. They were not told at all.

The 2026 count is worth dating rather than stating. Those two were the eleventh and twelfth actions under the initiative as at March 2026. The number had reached thirteen by 23 April 2026 and continued to move, so treat any current total you read, including this one, as a figure with a date on it.

One number about practices of your size, stated with its source and its date, because it is usually quoted without either. In its 2025 healthcare data breach report, published on 13 February 2026, HIPAA Journal analysed the 710 breaches of 500 or more records on the OCR portal for that year and banded them by size: 146 affected 500 to 999 records and 309 affected 1,000 to 9,999. That is 455 of 710, or 64 percent, involving fewer than 10,000 records.

Now the two qualifications that figure needs. It is a share of the breaches that were reported, not a rate at which small practices are attacked, and no such rate exists, because nobody knows how many incidents were never reported. And it is a snapshot: the OCR portal has since listed more breaches for 2025 than the 710 that share was computed against, and the share cannot be restated against a larger total without recounting the bands. Take it as evidence that small breaches dominate the reported record as at February 2026, which is what it says, rather than as a probability about your practice, which it does not say.

This page is about protecting your practice. If you came looking for the other thing we do, the forensic examination of a device or an account as evidence in a dispute, that sits elsewhere on this site. The same offering for regulated financial firms is at managed security and compliance, where the service calendar and the control map behind that record are set out in full.

Required, addressable, and neither

The Security Rule sorts its contents into two kinds, and almost every page written about it blurs them. Required means what it says. Addressable does not mean optional, and it does not mean mandatory either: under 164.306(d)(3) you assess whether the specification is reasonable and appropriate for your practice, and where it is not, you document why and implement an equivalent alternative measure where that is reasonable. The written, reasoned decision is the thing the rule wants. Skipping the control without recording the reasoning is the failure, not skipping the control.

Below are the fourteen Required requirements that reach a practice of your size, and the sixteen Addressable specifications, listed individually so you can count them yourself rather than take our number for it. Two of the fourteen are standards rather than implementation specifications, and are marked as such.

Required: fourteen requirements, and what produces each record

Each Required requirement of the Security Rule that reaches a small practice, and the part of this offering that produces the record for it.
CitationWhat it isWhat produces the record
164.308(a)(1)(ii)(A)Risk analysisThe compliance program build, then the annual refresh
164.308(a)(1)(ii)(B)Risk managementRemediation and hardening hours, and the risk management plan they work from
164.308(a)(1)(ii)(C)Sanction policyThe policy pack, adopted by the practice with its own counsel
164.308(a)(1)(ii)(D)Information system activity reviewThe monthly control drift review and the quarterly privileged access and patch report
164.308(a)(2)Assigned security responsibility (a standard, with no implementation specifications)The practice names its own security official. We do not fill this role.
164.308(a)(4)(ii)(A)Isolating health care clearinghouse functionsUsually inapplicable to a practice of this size, and we would rather say so than pad the table
164.308(a)(6)(ii)Response and reportingThe written incident response program. The response itself is billed separately.
164.308(a)(7)(ii)(A)Data backup planBackup of every server, laptop and mailbox, with a proven restore
164.308(a)(7)(ii)(B)Disaster recovery planThe compliance program build
164.308(a)(7)(ii)(C)Emergency mode operation planThe compliance program build
164.308(a)(8)Evaluation (a standard, with no implementation specifications)The annual column of the service calendar
164.308(b)(3)Written contract or other arrangementThe vendor inventory and due diligence file, and our own business associate agreement
164.312(a)(2)(i)Unique user identificationNamed users, and the new starter, leaver and device setup work
164.312(a)(2)(ii)Emergency access procedureThe compliance program build

Addressable: sixteen specifications, and why the decision is the deliverable

Every row below is one you may reasonably decide not to implement, provided you record why and put something equivalent in its place where that is reasonable. Notice what is in this list rather than the one above. Encryption appears twice, at rest and in transmission, and both are addressable.

The sixteen Addressable implementation specifications. For each, the deliverable is the same: a documented, reasoned decision under 164.306(d)(3).
CitationSpecification
164.308(a)(3)(ii)(A)Authorization and supervision
164.308(a)(3)(ii)(B)Workforce clearance procedure
164.308(a)(3)(ii)(C)Termination procedures
164.308(a)(4)(ii)(B)Access authorization
164.308(a)(4)(ii)(C)Access establishment and modification
164.308(a)(5)(ii)(A)Security reminders
164.308(a)(5)(ii)(B)Protection from malicious software
164.308(a)(5)(ii)(C)Log-in monitoring
164.308(a)(5)(ii)(D)Password management
164.308(a)(7)(ii)(D)Testing and revision procedures
164.308(a)(7)(ii)(E)Applications and data criticality analysis
164.312(a)(2)(iii)Automatic logoff
164.312(a)(2)(iv)Encryption and decryption, for data at rest
164.312(c)(2)Mechanism to authenticate electronic protected health information
164.312(e)(2)(i)Integrity controls
164.312(e)(2)(ii)Encryption, in transmission

Neither: the controls your insurer requires and the rule does not

Multi-factor authentication is named nowhere in 45 CFR 164.312. That section has not been amended since 2013, and the phrase does not appear in it. Two of its standards carry no implementation specifications at all: 164.312(b), audit controls, and 164.312(d), person or entity authentication. Multi-factor login is one way to satisfy the authentication standard. It is not a thing the Security Rule asks for by name, and any page telling you otherwise is describing a rule that does not exist yet.

The proposal people are thinking of is real and it is still a proposal. The January 2025 notice that would make multi-factor authentication and encryption mandatory was published at 90 FR 898 under RIN 0945-AA22. It has moved to long-term actions, with final action anticipated in July 2027. Until that happens, encryption stays addressable and multi-factor login stays unnamed.

So why is multi-factor authentication on every plan on this page? Because your cyber insurer treats it as a condition of binding coverage, and because it is the single control that most reduces the exact failure that cost the treatment centre above $103,000. We would rather tell you that we include it for those two reasons than let you believe a regulator requires it. If the honesty of that sentence is the only thing you take from this page, it is doing its job.

The four plans

What each plan includes, feature by feature.
What you get
Monitor
$995 per month
Up to 10 named users and 12 protected devices
You have IT covered and your compliance paperwork is current.
Managed IT
$1,595 per month
Up to 10 named users and 12 protected devices
You want us to be your IT department, and your paperwork is current.
Monitor + Comply
$1,950 per month
Up to 10 named users and 12 protected devices
Recommended
You have IT covered but need the compliance program built and kept.
Complete
$2,495 per month
Up to 10 named users and 12 protected devices
You want one firm accountable for all of it.
Protection
Backup of every server, laptop and mailboxIncludedIncludedIncludedIncluded
Managed detection and response on every deviceIncludedIncludedIncludedIncluded
Multi-factor authentication across all five access pointsIncludedIncludedIncludedIncluded
Email filtering and security awareness trainingNot includedIncludedNot includedIncluded
Patch management to a stated targetNot includedIncludedNot includedIncluded
Proof
Dated monthly evidence pack for your recordsIncludedIncludedIncludedIncluded
Quarterly restore test, documentedIncludedIncludedIncludedIncluded
Quarterly privileged access and patch compliance reportIncludedIncludedIncludedIncluded
Cyber insurance application support, from recordsIncludedIncludedIncludedIncluded
Day-to-day IT
Helpdesk for your staffNot includedIncludedNot includedIncluded
New starters, leavers and device setupNot includedIncludedNot includedIncluded
Remediation and hardening hours included each monthNot included2 hrsNot included2 hrs
Written security program and risk analysis
Written risk analysis and risk management plan, refreshed annuallyNot includedNot includedIncludedIncluded
Patient notification decision file, including the reasons not to notifyNot includedNot includedIncludedIncluded
Written incident response program, reviewed annuallyNot includedNot includedIncludedIncluded
Vendor inventory, due diligence and business associate agreementsNot includedNot includedIncludedIncluded
Annual tabletop exercise with written after-action reportNot includedNot includedIncludedIncluded
Records schedule and a document pack you can hand to an insurerNot includedNot includedIncludedIncluded

Getting started: deployment and a first verified restore is a one time $9,500. The compliance program build is a one time $12,500, required once on the two plans that include it.

Plans start at $995 per month. Every plan price on this page is stated at the same size: up to 10 named users and 12 protected devices, on a 12 month term, billed monthly. A practice smaller than that pays the same monthly figure, so a three-person practice should weigh it against what a single incident and the corrective action plan behind it would cost, rather than against a per-seat rate.

Which plan a practice usually starts on, and the question that decides it. Monitor + Comply, at $1,950 per month, is the usual answer, for two reasons that follow from the tables above. Nine of the fourteen Required requirements produce a document rather than a running control, and all sixteen Addressable ones require a written decision, so most of what the rule asks for is the Comply half. And the systems that hold most of your patient data, the electronic health record and the practice management system, are not yours to monitor. We say what we can reach: endpoints, mailboxes, backups and the paperwork.

Complete adds the day-to-day IT, and the question that routes between the two is worth asking out loud at your next staff meeting. Who patches your workstations today, and can they show you a dated record of having done it? If someone can, Monitor + Comply sits above them and produces the record. If nobody can, the honest answer is Complete, because the patch evidence in your quarterly report has to come from somewhere.

Your insurance application, control by control

Must have

One carrier's own bind-condition sheet marks controls of this kind as required before it will bind coverage. These are the ones that stop a deal.

Changes the price

You can get a policy without it, but it costs more, or you get lower limits.

On the form

They ask, and the answer goes on file, but on its own it rarely stops anything.

What a cyber insurance application asks about, and which plan answers it.
What the application asksMonitorManaged ITMonitor + ComplyComplete
Must have
Two-step login (MFA) on emailCoveredCoveredCoveredCovered
Two-step login on any way in from outside the officeCoveredCoveredCoveredCovered
Security software on every laptop and serverCoveredCoveredCoveredCovered
Backups an attacker cannot reach or overwrite, and proven to restoreCoveredCoveredCoveredCovered
Calling to confirm a payment before you send it, and a second person approving large onesA must-have for the part of the policy that covers being tricked into sending money, rather than for the policy as a whole.CoveredCoveredCoveredCovered
Changes the price
Two-step login on the accounts that can change everything, and on the backup systemCoveredCoveredCoveredCovered
What share of devices are covered, and whether the software cuts an infected one off the network by itselfCoveredCoveredCoveredCovered
Backups kept apart from the day-to-day network, so one break-in cannot take bothCoveredCoveredCoveredCovered
Someone has actually restored a file from backup and written down that it workedCoveredCoveredCoveredCovered
Email screened before it arrives, and attachments opened somewhere safe firstNot coveredCoveredNot coveredCovered
How fast you install urgent security updates, and how often you hit that targetNot coveredCoveredNot coveredCovered
How many accounts can change anything, and why each one needs toCoveredCoveredCoveredCovered
On the form
Software the maker has stopped fixing, still in useCoveredCoveredCoveredCovered
Staff training, and test phishing emails sent to see who clicksNot coveredCoveredNot coveredCovered
A written plan for a break-in, rehearsed once a yearNot coveredNot coveredCoveredCovered
Checking the outside companies that touch your patient dataNot coveredNot coveredCoveredCovered

These are questions from real insurance applications. Where a plan does not cover something, we say so here rather than let you find out on the form.

What we do, and how often

Every month

  • Control drift reviewProduces: A triaged, recorded list of what stopped reporting and what was escalated
  • Backup verificationProduces: Confirmation that every server, laptop and mailbox is backed up
  • Evidence packProduces: A dated snapshot of every device and user, filed to your archive

Every quarter

  • Restore testProduces: A written result for a real file set restored from backup
  • Patch compliance reportProduces: Performance against a stated target, with the rolling twelve-month rate
  • Access exception reviewProduces: A record of new devices, bypass codes and administrator accounts
  • Report to your security officialProduces: One page: what changed, what lapsed, what needs a decision

Every year

  • Risk analysis refreshProduces: An updated written analysis naming your systems, and the risk management plan that follows from it
  • Privileged account reviewProduces: Every administrator account listed with a written reason it still exists
  • End-of-life inventoryProduces: A written statement of what protects anything the maker no longer supports
  • Insurance evidence packProduces: The control sections of your application or renewal, supported by dated records

The written program

Included in Monitor + Comply and Complete. The risk analysis is the centre of it, and it is built from your own inventory rather than from a template: every device, user, mailbox, server and vendor that touches electronic protected health information, what could go wrong with each, what is already in place, and what is left. The risk management plan at 164.308(a)(1)(ii)(B) is the list of what you decided to do about the gaps, with dates.

Around it sits the rest of the paperwork the tables above call for. The policy pack the practice adopts, including the sanction policy. The written incident response program, keeping assessment, containment and notification separate and visible. The patient notification decision file, which records why you decided not to notify where that was the outcome, because that is the record you would want if the decision were questioned later. The vendor inventory, the due diligence behind it and the business associate agreements the written arrangement requirement asks for. And a records schedule and document pack so an insurance renewal or an OCR request is answered from a folder rather than from a scramble.

It is refreshed every year, and that is not a subscription mechanic. The evaluation standard at 164.308(a)(8) asks for periodic evaluation, and a risk analysis describing an environment you no longer run has stopped being accurate, which is the word the requirement uses.

An honest boundary. We prepare these documents for the practice to review, revise and adopt. We are not lawyers and we do not give legal or regulatory advice. Where a judgment call belongs to the practice, we set it up so the decision is easy to make and easy to evidence, and then you make it.

What this means for you

What is in scope, and what is not

We do

  • Configure, monitor and maintain every product in your plan
  • The monthly, quarterly and annual work in the service calendar above
  • Deliver a dated evidence pack to your archive every month
  • Support one insurance application or renewal each year
  • Escalate anything we find, with a written record
  • On Managed IT and Complete: helpdesk, new starters and leavers, device setup, and two hours of remediation and hardening every month

We do not

  • Acting as your named security official under 164.308(a)(2)
  • Helpdesk on the two Monitor plans, which stays with your existing IT provider
  • Incident response and forensics inside the monthly fee, which is billed separately
  • Monitoring inside your electronic health record or practice management system, which we do not control
  • Buying or owning your hardware, software licenses, phones or cabling
  • Legal, regulatory or insurance advice
  • Writing or sending your breach notifications
  • Work on site or outside business hours, except by arrangement

You do

  • Name your security official under 164.308(a)(2), and tell us if that changes
  • Name a primary and a backup technical contact
  • Respond within four business hours when we escalate something urgent
  • Review and adopt the policies we prepare, with your own counsel
  • Own the accuracy of anything you file with a regulator, a payer or an insurer
  • Tell us before you add people, locations, systems or vendors
  • Keep your existing IT resource in place on the Monitor plans, or tell us if that ends

Written plainly here so nothing is a surprise in month three. The agreement carries the same boundaries in full.

If the worst happens

Most providers hand you off at the worst possible moment. We do not. The people who protect your practice are the same people who examine the devices and accounts and write the report, and stand behind it if it is ever challenged.

Hour one to day ten

  1. Hour one, contain and preserve. We take your call and stop the bleeding. We capture evidence to forensic standard from the first minute, with chain of custody intact. Most of what is lost in a breach is lost in the first few hours, by well-meaning people rebooting machines.
  2. Days one to five, examine. Our examiners work the images and the logs. What got in, how, what it touched, what left the building, and whether patient information was actually reached. That last question is the one your notification decision turns on, and it is the question a mailbox compromise is hardest to answer without preserved evidence.
  3. By day ten, report. A written forensic report the practice, your insurer and if necessary a regulator can all read. Written to be defensible, because we write reports that go to court.
  4. Then notify, rebuild, and if needed testify. The report feeds your notification decision and the record behind it. We rebuild the environment. If the matter is litigated, our examiners give evidence.

Who does the work

A digital forensics practice. Quinn holds a degree in cybersecurity from SANS Technology Institute and 9 active GIAC certifications across GIAC, including incident handling, intrusion analysis and mobile forensics. That credential mix is what supports qualification as an expert witness under the Daubert and Frye standards.

You can always get a second opinion. You may bring in an independent examiner at any point, for any reason, and we will hand over the images, the logs and our working papers to help them.

A great deal of what practices call us for is not an outside attacker at all. A departing employee who took a patient list. A dispute where the record sits in a mailbox or on a phone. A device that has to be wiped and certified before it leaves the building. Those are the same skills, applied before anything has gone wrong.

The first ninety days

  1. Days 1 to 10, discovery and paperwork. We inventory every device, user, mailbox and vendor, which is also the raw material of the risk analysis. You get our own due diligence pack and our business associate agreement. We hand it over before you ask, because you are about to make us one of the outside companies that touches your patient data, and you should be able to answer for us the way you would answer for any other vendor.
  2. Days 10 to 30, deployment. Backup, endpoint protection and monitoring on every device. Multi-factor login across all five access points. First backup taken and first restore proven, not assumed.
  3. Days 30 to 60, the program. On the Comply plans: the risk analysis written and the risk management plan drawn from it, incident response program drafted, notification templates prepared, vendor inventory built and the agreements put in place. The practice reviews and adopts.
  4. Days 60 to 90, proof and rehearsal. First full evidence pack delivered. First tabletop exercise run, with the written after-action report. If you are placing or renewing insurance, we assemble the control evidence for your broker.

What we need from you to start: the name of your security official, a named technical contact and a backup, administrative access to your Microsoft or Google tenant, a list of every vendor that touches patient information, and your current policies however incomplete.

Rates, growth and the small print

Project and hourly rates

Hourly rates, standard and on a plan.
WorkStandardOn a plan
Remediation beyond the included allowance$400/hr$195/hr
Security consulting, assessment and hardening$400/hr$275/hr
Incident response, containment and rebuild$400/hr$275/hr
Forensic examination and written report$400/hr$325/hr
Deposition and trial testimony, four-hour minimum$400/hr$400/hr Same as the standard rate.
Done-for-you device forensicsfrom $2,000from $2,000 Same as the standard rate.
Refundable engagement retainer$5,000Waived

All rates per hour unless stated. There is no surge for nights, weekends or holidays, on either column. Court time is never discounted, because the hour is the same hour whoever is paying for it.

As your practice grows

Additional named user

$35/mo

Additional workstation

$25/mo

Additional server

$70/mo

New user setup

$150

User departure and offboarding

$100

New device deployment

$200

Term

Twelve months, billed monthly, renewing unless either of us gives 60 days' notice.

Your data

Your tenants are yours. On exit we return your records in a usable format within 30 days and certify what we destroyed.

Our duty to you

We are your business associate, we sign a business associate agreement before we touch anything, and we will tell you within 72 hours of becoming aware of a breach affecting a system that holds your patient information. The breach notification decision, and the notice itself, stay with the practice.

Insurance

We recommend you carry cyber cover and we supply the control evidence to your broker. We are not licensed in insurance and give no insurance advice.

Growth is reviewed quarterly, effective from the date of the change. Devices count by type, because a server costs several times what a laptop does. Where a vendor sells licenses in blocks, that block is invoiced in full when it is bought.

How an engagement begins

  1. A scoping call. Forty-five minutes. We walk your environment and put a fixed number against what it would take to run it properly. There is no charge and no obligation, and we do not produce a written finding about your current state unless you ask us to.
  2. Written scope. Deliverables, timeline and price, approved by you before any work begins.
  3. Discovery, deployment and the program. The ninety days above, with a dated record at every step.

Why this work matters

A practice of six people holds the same information as a hospital wing, with none of the staff to protect it. One requirement in the Security Rule has no discretion in it, and two practices found that out this year over a phished mailbox and a vendor that never called. What we sell is the record: a risk analysis that names your systems, refreshed while it is still accurate, and a dated pack every month that proves what was actually running. If you are also seeing what a small firm buys when it has no IT department, the shape of the offering is the same and only the rulebook changes.

Plain terms

What we are, and what we are not

What we are

A private investigation agency in the making, with full digital forensics included. SleuthX is not yet a licensed private investigation agency; licensure is in progress. Credentialed examiners, documented chain of custody, explainable findings you can verify, and court-admissible reports under FRE 901/902. Where a matter needs field work today, whether backgrounds, locates or physical surveillance, we coordinate with licensed private investigators. Lawful, confidential, on your side.

What we are not

Spyware, stalkerware, or a way to secretly monitor another person. We do not “hack back,” promise guaranteed money recovery, or touch any account or device without its owner's lawful authorization. We decline engagements that ask us to.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 9 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

How We Work

A confidential, structured engagement.

01

Confidential Consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process.

02

Scoped Engagement

A clear written proposal with defined deliverables, timeline, and pricing. No hidden costs.

03

Investigation and Findings

Forensic work conducted to court-admissible standards, with regular communication and a written summary you can act on.

Certified Expertise

GIAC

Frequently asked about the security risk analysis

We already use a compliance service for about $500 a year. What is different?
Those services are real and some practices are well served by them. What they sell is a template and a portal: you answer a questionnaire, and a document comes out with your practice name on it. What 164.308(a)(1)(ii)(A) asks for is an analysis of the risks to the electronic protected health information you actually hold, on the systems you actually run. Both 2026 settlements above turned on the quality of the analysis rather than on the absence of a document. If a template names none of your systems, you have bought the paperwork without the finding, and the finding is the part OCR reads.
Does HIPAA require multi-factor authentication?
No. Multi-factor authentication appears nowhere in 45 CFR 164.312, which has not been amended since 2013. The authentication standard at 164.312(d) carries no implementation specifications at all, so multi-factor login is one way to satisfy it rather than a thing the rule names. We say this plainly because most of the market does not. What is true is that it is a bind condition for cyber insurers, and that it is the single control that most reduces email account compromise, which is exactly how the 1,980-patient breach above happened. We include it on every plan for those reasons, not because a regulator told us to.
Our practice management vendor says they are HIPAA compliant. Isn't that covered?
Their obligations are theirs, and yours stay yours. 164.308(b) makes the written arrangement with them your requirement, which is why the vendor inventory and the agreements sit in the program we build. The sharper answer is MMG Fusion. Fifteen million people's information was exposed in December 2020, and the dental practices whose patients they were did not hear it from their vendor. OCR found MMG had failed to notify the covered entities it served. A vendor telling you they are compliant is not the same as a vendor who will tell you when they are not.
We are a therapy practice. Does 42 CFR Part 2 apply to us?
It depends on whether you are a part 2 program, which is a question about how your practice is held out and funded rather than about what you treat. If you are, 2.16 sits on top of HIPAA and asks for formal policies and procedures protecting patient identifying information in both paper and electronic form, including secure storage, workstation access and the sanitisation of media before disposal. OCR began accepting Part 2 complaints on 16 February 2026, having announced the civil enforcement program on 13 February 2026. The answer determines the paperwork, so it is worth settling early rather than during an investigation.
Are we going to be fined?
That is not the shape the risk usually takes, and we would rather say so than sell you fear. The two settlements above were $103,000 and $10,000, and OCR took the second company's financial position into account in setting it. The corrective action plans were two years and three years. That is the real cost: a multi-year period in which a federal agency reviews your policies, your training and your risk analysis, and you produce documents on a schedule someone else sets. What a practice of six people actually feels is the disruption of the incident and the months of supervision that follow it.
Do you become our HIPAA security official?
No. 164.308(a)(2) requires the practice to assign that responsibility to a person, and it has to be someone inside the practice. We report to whoever that is: the quarterly report in the service calendar is addressed to them, and the decisions the risk analysis raises are theirs to make. We prepare the documents, we run the controls and we produce the record. Naming the official, adopting the policies and signing the decisions stay with you.
Quinnlan Varcoe, Founder & CEO
Quinnlan Varcoe
GIAC-certified · Founder & CEO

Schedule Your Session

Schedule a confidential consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process. Most engagements begin within 48 hours.

Free, confidential · NDA-protected · no obligation.

  1. 1. Book a 30-minute call — we scope your situation, no charge.
  2. 2. You get a written scope — deliverables, timeline, and price — before any work begins.
  3. 3. Approve it and we start; most engagements begin within 48 hours.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management