Something happened and you need clear next steps
A suspicious email someone clicked, a missing laptop, an unfamiliar login. Most of these turn out to be manageable. The first job is finding out what actually occurred.
Sound familiar?
- A staff member entered credentials on a page that turned out to be fake
- A device with access to patient data went missing
- Records were emailed or faxed to the wrong recipient
- Someone spotted a login from a place nobody was working from
How we help
Establish the facts
We work through logs, accounts, and access with your IT provider to determine what was reached and by whom.
Assess notification
A documented breach risk assessment under the Breach Notification Rule, so the decision to notify or not is recorded and defensible.
Close the gap
A short list of changes that prevent the same route from being used again, plus documentation of what was done.
Initial fact-finding usually happens within days of the call. If you are in an active emergency with systems encrypted or unavailable, call rather than fill out a form: (000) 000-0000 (placeholder).
Start with the assessment. Stay with the annual program.
The $12,000 risk assessment
A complete picture in 1 to 2 weeks for a typical single-site, remote engagement: breach risk, compliance posture, privacy requirements, and the dollarized cost of inaction, with a ranked remediation plan.
The Annual Security Program, $24,000 a year
The assessment findings become a quarterly calendar of policy updates, training, vendor reviews, and board-ready reporting, so you can prepare for next year's deadline before it arrives.
Common questions
The first 48 hours checklist
What to preserve, who to call, and what to document when something looks wrong. Placeholder download.
Ready to talk?
A 30-minute scoping call covers your setup, your deadlines, and what a fixed-fee engagement would look like.