ISO/IEC 17020 accredited inspection body · Cleared facility (FCL)
Home / Services / HIPAA / HITECH Assessment

Healthcare & health tech

HIPAA / HITECH Assessment

Security Rule risk analysis and safeguard testing for organizations that create, receive, maintain or transmit ePHI.

HIPAA Security Rule

The risk analysis is the requirement that gets cited most, and skipped most.

HIPAA and the HITECH Act require covered entities and business associates to safeguard electronic protected health information through administrative, physical and technical controls, and to base those controls on an accurate, organization-wide risk analysis. Enforcement actions return to that risk analysis again and again.

DASATECH assesses your safeguards against the Security Rule using evidence: interviews with the people who operate the controls, inspection of the environment, and examination of configuration and records. We test what is in place, not what a policy says should be.

You receive a report that documents your compliance position in detail, usable with regulators, with health system customers who are diligencing you, and with acquirers.

Who this is for
  • Business associates being pushed to evidence compliance by a covered entity
  • Health tech platforms handling ePHI on behalf of providers or payers
  • Data centers and hosting providers with ePHI in the environment
  • Provider organizations that have never completed a formal risk analysis
  • Any organization whose last assessment predates its current architecture
SECURITY RULE SAFEGUARDS, ASSESSMENT SCOPE Administrative45 CFR §164.308Risk analysisRisk managementSanction policyWorkforce securityAccess managementTrainingIncident proceduresContingency planEvaluationPhysical45 CFR §164.310Facility access controlsWorkstation useWorkstation securityDevice & media controlsTechnical45 CFR §164.312Access controlAudit controlsIntegrityPerson authenticationTransmission security
The three safeguard categories of the HIPAA Security Rule, and the standards tested within each.

Risk analysis sits first under §164.308, and is the requirement most often found missing entirely.

How it runs

Engagement sequence

Scoping and ePHI mapping

1 week

We identify every system, vendor and process that touches ePHI, and set the assessment boundary from that map rather than from an org chart.

Safeguard testing

2–3 weeks

Administrative, physical and technical safeguards are tested through interview, inspection and evidence examination by qualified assessors.

Risk analysis

1 week

Threats and vulnerabilities are documented against each ePHI asset, with likelihood and impact rated to support a defensible risk determination.

Reporting

1 week

You receive the assessment report, risk analysis and a remediation plan sequenced by risk to ePHI.

Remediation advisory

Optional

Support closing findings, updating policy, and preparing evidence for customer security reviews.

Deliverables

Report contents

Every document is produced in the template the receiving party expects, and is written to be read by an assessor rather than filed.

  • REPORTHIPAA / HITECH security assessment report
  • METHODTesting approach, sampling methodology and scope statement
  • FINDINGSDetailed findings with safeguard-level compliance determinations
  • RISKRisk analysis documenting threats, vulnerabilities, likelihood and impact
  • PLANRemediation plan prioritized by risk to ePHI
  • MAPePHI inventory and data flow mapping

Outcome

What compliance actually earns you

  • A documented risk analysis, the artifact most often found missing
  • Reduced exposure to penalties tied to regulatory non-compliance
  • A credible answer to the security questionnaires slowing your sales cycle
  • Competitive position against ePHI handlers who cannot evidence compliance
  • Assurance for customers whose own compliance depends on yours

Tell us what the contract requires. We’ll tell you what it takes.

A 30-minute scoping call is usually enough to size the gap, name the deliverables and give you a realistic date for authorization.