What HIPAA compliance actually requires
The HIPAA Security Rule sets standards for protecting electronic protected health information, and it binds business associates like us as directly as it binds covered entities like you. Compliance is not a certificate on a wall — it is a working set of administrative policies, physical controls over facilities and devices, and technical safeguards over systems and transmission. We execute a Business Associate Agreement with every client before any PHI moves, which puts these obligations in writing and gives you contractual recourse.
Encrypted network
Network access is restricted to authorized personnel under a strict security policy, with multi-level security applied across systems and networks. Systems are hosted on a server secured with SSL encryption, and passwords are rotated on a defined schedule rather than left standing for years. Account access is provisioned by role, so staff can reach the systems their work requires and nothing beyond them. When someone leaves an account or the company, their access is removed as part of the offboarding process.
User access control
The physical environment is controlled as tightly as the digital one. Documents cannot be carried into or out of the office premises. Image-capturing devices are prohibited in the work area. Employees are physically checked entering and exiting the office. Every staff member signs a confidentiality agreement as a condition of employment, and compliance training is mandatory and repeated on a periodic basis rather than delivered once at orientation and forgotten.
Device encryption
All office devices are encrypted at the device level, so data at rest is protected even if hardware is lost or stolen. USB drives and removable media are disabled across desktops and laptops, which closes the most common route for data to leave a building undetected. System access is limited to authorized staff, and multi-level security applies to workstations and networks alike. Personal devices are not used for client work.
Activity audits
Controls that are never checked tend to drift. Software, hardware, and configurations are actively maintained rather than left at their installed state. Data is backed up daily to protect against loss. Employees with access to client data are audited on a regular cycle, and surprise checks are conducted specifically to detect breaches of policy that a scheduled review would not catch. Findings drive corrections to the control, not just to the individual instance.