AccuSights
PartnersBlogAbout
Book my 30-minute demo

Healthcare & Dental · Cybersecurity, compliance and GRC, in plain English

Protect patient records, stay operational, stay HIPAA compliant.

For practice owners, hospital decision makers and the people who custody patient data: one program that keeps your HIPAA risk analysis current every day, your safeguards provable, and your systems watched around the clock, so care never stops.

Led by a CRISC and CISA certified practitionerPublic pricingSee your score immediately

The test is scored against CIS Controls v8.1 IG1 and the CIS Community Defense Model. You see your score immediately, then we talk if you want to.

A story we hear too often

The doctor who wanted to stop worrying about the thing he could not see

a 62-year-old internist who owns a four-provider practice

Dr. Okafor is 62. He has owned the practice on Devon Avenue for twenty-six years, four providers and eleven staff, and he still reads every lab result himself. He has started thinking about the beach. A week, the first in six years.

What keeps him from booking it is the thing he cannot see. The EHR is in the cloud, the imaging server is in the closet, the billing runs through a vendor, and a laptop with the schedule goes home with the office manager. He reads about practices that lost twenty years of records over a weekend and cannot say that his would not.

Tuesday at 6:50 a.m. the front desk opens an email from ‘the imaging vendor’ with an invoice attached. The attachment tries to run. In the version that ends badly it runs, the imaging server encrypts by noon, patients are turned away for three weeks, and OCR’s first question is where the risk analysis is.

In Dr. Okafor’s version the attachment is stopped on the front-desk PC, the engineer on watch confirms nothing spread, and the risk analysis, current as of last week, already lists the vendor and the control. He books the week in March. He tells his wife it is the first time in years he is not taking the worry with him.

The attachment tries to run.

What changes the ending

  1. Email and endpoint protection on every PC, including the front desk (CIS Controls 9 and 10, Email Protections and Malware Defenses)
  2. Offline, tested backups of the EHR extract and the imaging server (CIS Control 11, Data Recovery)
  3. A current risk analysis that names every system and vendor, kept true every day (CIS Controls 1, 2 and 15, and the HIPAA Security Rule)
Show me this running for my business

The questions owners are afraid to ask

Ask them anyway. Here are the answers.

If the EHR is in the cloud, is the vendor responsible for HIPAA, not me?

The vendor is responsible for their side under the business associate agreement; you are responsible for your risk analysis, your staff, your devices and how you use their system. OCR fines the covered entity when the risk analysis is missing, regardless of where the data sits.

I am 62 and I own the practice. Can I hand this off and stop thinking about it?

Yes, that is the design: the assessment builds the risk analysis and the safeguards, then Protect runs them with a named engineer who watches the practice day and night. You get a monthly one-page readout, and you take the week in March.

What if a staff member clicks the wrong attachment on a Tuesday morning?

Someone will, so the plan assumes it: the attachment is blocked on the device, the session is contained in seconds and the engineer confirms nothing spread. Training lowers the clicks; the controls make the click survivable.

What you hold, and why someone wants it

Your data protection needs, by the data.

Patient records in the EHR, imaging and billing

Worth more than card data on the criminal market and the trigger for OCR, the state and your license. Encryption, access limits, MFA and a current risk analysis protect them.

Front-desk and billing inboxes

The door for the fake vendor invoice and the diverted insurance payment. Email protection, MFA and monitoring protect them.

Laptops and the imaging server in the closet

Unencrypted devices and an unpatched server are the two findings OCR sees most. Encryption, patching and offline backups protect them.

Vendors and business associates

Billing, transcription, imaging and IT vendors with access to patient data; a third of healthcare breaches start there. BAAs, access review and monitoring protect you.

Card payments at the front desk

Copays and balances under PCI DSS v4.0.1. Segmented terminals and hardened payment pages protect them.

1,438
confirmed healthcare breaches in the latest DBIR; vulnerability exploitation (20%) and phishing (14%) lead the way in
Source: Verizon 2026 Data Breach Investigations Report, Healthcare snapshot
772
large breaches reported to HHS in 2025, a record, affecting about 61 million people
Source: HIPAA Journal, 2025 Healthcare Data Breach Report (HHS OCR portal data)
34 to 38%
higher in-hospital mortality among patients admitted while a ransomware attack is underway
Source: Neprash, McGlave and Nikpay, American Economic Journal: Economic Policy, February 2026

What applies to you

The rules, in one page, with the dates that matter.

HIPAA Security Rule
HHS Office for Civil Rights
Administrative, physical and technical safeguards for ePHI, anchored on a documented, accurate risk analysis.
The January 2025 proposed update (mandatory MFA, encryption, 72-hour restoration) is not final; HHS projects July 2027.
HIPAA Breach Notification Rule
HHS OCR
Notify affected individuals within 60 days of discovery; breaches of 500 or more go to HHS and the media.
HITECH and the 2021 amendment
HHS OCR
Business associates carry the Security Rule; recognized security practices in place for 12 months (NIST CSF, 405(d)) count in your favor at enforcement.
State breach notification laws
State attorneys general
All 50 states, many with clocks shorter than HIPAA and their own medical-information definitions.
PCI DSS v4.0.1
PCI Security Standards Council
If the front desk takes cards, the future-dated requirements became mandatory March 31, 2025.

Verified September 2026 from the regulators' own publications. We map all of it to one control set so evidence is produced once.

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.

The threat picture

What actually goes wrong, and what we do about it.

  • Ransomware crews target small practices because records are valuable and defenses are thin; OCR treats a missing risk analysis as the violation itself.
  • Phishing and stolen credentials open the door; a single compromised inbox exposes every patient it ever emailed.
  • Vendors and business associates are in a third of healthcare breaches. Their gap becomes your notification.

It happened to businesses like yours

The February 2024 ransomware attack on Change Healthcare stopped claims and payments for practices across the country for weeks and, by the company’s 2025 update to HHS, affected about 192.7 million people, the largest healthcare breach on record.

February 2024 · HHS Office for Civil Rights, Change Healthcare FAQ

A May 2024 ransomware attack on Ascension, which began with an employee downloading a malicious file, forced 140 hospitals onto paper records and exposed the data of 5.6 million patients and employees.

May 2024 · Fierce Healthcare

Public incidents, listed to show the pattern, never to shame a victim.

Protect, for a healthcare business

We protect your people, every device, the servers and the website. Day and night.

  • We protect your front desk, billing and provider inboxes, where the fake vendor invoice and the spoofed referral arrive.
  • Every laptop, workstation and the office manager’s home device that touches the schedule.
  • The imaging server in the closet, the on-site file share and the EHR connection.
  • The website and the patient portal, including appointment and payment forms.
  • The cloud apps: the EHR, practice management, billing, email and telehealth.
  • Day and night, with an AI agent that contains a threat in seconds and a named human engineer watching.

Think of it as a per-employee service, like payroll. Except that this is the one corner that, if you cut it, can empty the account and take the business with it. We have your back.

How Protect works →

Where we start

Cybersecurity and Data Protection Assessment for Healthcare

Built on the CIS Controls v8.1 IG1 and the HIPAA Security Rule, scoped from what a practice stands to lose: patient records, the schedule and the license. The output is the risk analysis OCR asks for first, the safeguards set up rather than recommended, and a plan an owner can read in ten minutes.

  • HIPAA security risk analysis documented to the HHS guidance, naming every system, vendor and business associate (CIS Controls 1, 2 and 15)
  • On-site engineer visit in major cities to set up the critical controls (MFA, encryption, email and endpoint protection, backups) and install the protection agent
  • Account audit: shared front-desk logins, ex-staff access, MFA on the EHR, email and the patient portal (CIS Controls 5 and 6)
  • Backup and restore test for the EHR extract, imaging and practice-management data (CIS Control 11)
  • Vendor and BAA review for billing, imaging, transcription and IT providers, with access limits set (CIS Control 15)
  • Breach response plan rehearsed with the practice, plus a ranked remediation plan and a cyber health score
Start with the 3-minute test

Packages

Built for healthcare businesses, with the price on the page.

Practice Cybersecurity, Data Protection and HIPAA Package

A risk analysis that holds up in front of OCR, safeguards implemented rather than promised, policies your staff actually follow, and a breach plan you have rehearsed.

Fixed feescoped in 30 minutes
2 to 4 weeks to a delivered risk analysis and plan; continuous from there
Details →

Mock Audit Package: SOC 2, HIPAA or CMMC

We run your audit before your auditor does: the same evidence requests, the same interviews, the same sampling, the same findings language.

Fixed feescoped in 30 minutes
1 to 3 weeks depending on framework and scope
Details →

Cyber and Data Protection Assessment

A complete read on your exposure: every endpoint, server, cloud account and identity inventoried, controls tested against CIS and NIST CSF 2.0, threats mapped to your industry, and a plan ranked by what would actually hurt.

Fixed feescoped in 30 minutes
1 to 3 weeks
Details →

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.

A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.

Questions owners ask

Straight answers.

Does a small dental or medical practice really need a HIPAA risk analysis?
Yes. The Security Rule requires an accurate and thorough risk analysis regardless of size, and OCR has resolved a string of investigations where the missing analysis was the finding. Our Practice package produces one that holds up, then keeps it current.
What changed in the HIPAA Security Rule in 2025 and 2026?
HHS proposed a major update in January 2025 (mandatory MFA and encryption, asset inventories, 72-hour restoration, annual audits). As of September 2026 it is not final; HHS lists July 2027 as the projected action. The proposed controls are good practice today and we build to them.
How fast can you get a practice protected?
The free score takes five minutes. A Practice package runs two to four weeks from kickoff to a delivered risk analysis, policies and remediation plan. Protect, the 24/7 watch, is live within days.

People also search: HIPAA risk assessment near me · cybersecurity for dental practices in Chicago · for a four-provider medical practice · for a dental office with two locations · HIPAA compliance help in the suburbs · cybersecurity for a surgery center · for a physical therapy practice · healthcare cybersecurity services in the Midwest

Never too big or too small

Let's talk about your cyber anxieties. Thirty minutes with an engineer.

3-min test