HIPAA Security Rule
The risk analysis is the requirement that gets cited most, and skipped most.
HIPAA and the HITECH Act require covered entities and business associates to safeguard electronic protected health information through administrative, physical and technical controls, and to base those controls on an accurate, organization-wide risk analysis. Enforcement actions return to that risk analysis again and again.
DASATECH assesses your safeguards against the Security Rule using evidence: interviews with the people who operate the controls, inspection of the environment, and examination of configuration and records. We test what is in place, not what a policy says should be.
You receive a report that documents your compliance position in detail, usable with regulators, with health system customers who are diligencing you, and with acquirers.
- Business associates being pushed to evidence compliance by a covered entity
- Health tech platforms handling ePHI on behalf of providers or payers
- Data centers and hosting providers with ePHI in the environment
- Provider organizations that have never completed a formal risk analysis
- Any organization whose last assessment predates its current architecture
Risk analysis sits first under §164.308, and is the requirement most often found missing entirely.
How it runs
Engagement sequence
Scoping and ePHI mapping
We identify every system, vendor and process that touches ePHI, and set the assessment boundary from that map rather than from an org chart.
Safeguard testing
Administrative, physical and technical safeguards are tested through interview, inspection and evidence examination by qualified assessors.
Risk analysis
Threats and vulnerabilities are documented against each ePHI asset, with likelihood and impact rated to support a defensible risk determination.
Reporting
You receive the assessment report, risk analysis and a remediation plan sequenced by risk to ePHI.
Remediation advisory
Support closing findings, updating policy, and preparing evidence for customer security reviews.
Deliverables
Report contents
Every document is produced in the template the receiving party expects, and is written to be read by an assessor rather than filed.
- REPORTHIPAA / HITECH security assessment report
- METHODTesting approach, sampling methodology and scope statement
- FINDINGSDetailed findings with safeguard-level compliance determinations
- RISKRisk analysis documenting threats, vulnerabilities, likelihood and impact
- PLANRemediation plan prioritized by risk to ePHI
- MAPePHI inventory and data flow mapping
Outcome
What compliance actually earns you
- A documented risk analysis, the artifact most often found missing
- Reduced exposure to penalties tied to regulatory non-compliance
- A credible answer to the security questionnaires slowing your sales cycle
- Competitive position against ePHI handlers who cannot evidence compliance
- Assurance for customers whose own compliance depends on yours
Tell us what the contract requires. We’ll tell you what it takes.
A 30-minute scoping call is usually enough to size the gap, name the deliverables and give you a realistic date for authorization.
