Simplify. Strategize. Secure.

Services · HIPAA & Texas HB 300 readiness

Readiness is ongoing work, not a badge.

A risk assessment should do more than identify problems. We examine the relevant safeguards, document the risk, and turn the findings into a prioritized plan your team can actually work through.

01What gets examined

A structured review, not a questionnaire you fill in yourself.

Readiness work fails when it becomes a checklist someone completes optimistically in an afternoon. A real assessment looks at what is actually configured, actually documented, and actually practised — then says where those three disagree.

  • 01

    Administrative safeguardsWho is responsible, how access is granted and removed, what is reviewed and when

  • 02

    Physical safeguardsWhere equipment and information live, and who can reach them

  • 03

    Technical safeguardsAccess controls, encryption, audit capability, and transmission security as configured

  • 04

    Risk analysisWhere sensitive information is exposed, and how likely and severe that exposure is

  • 05

    Policies and proceduresWhat exists on paper, and whether it matches the environment

  • 06

    Day-to-day practicesHow the team actually works, which is rarely how the policy reads

  • 07

    DocumentationWhat you could produce if someone asked you to evidence it

  • 08

    Priority actionsThe gaps that matter most, ordered so the list is finishable

Assessment boundaries, legal review, policy creation, technical testing, remediation work, validation, organization-size limits, travel, deliverables, and ongoing support are defined in the applicable agreement before anything begins.

02How it runs

The assessment

Five stages, ending in a conversation rather than a PDF.

Most of the value is in stages two and three — talking to the people who do the work, and looking at what is actually configured. A report assembled without those is a description of your intentions.

  1. Scope and data gathering. Which systems, locations, and categories of information are in scope, who we need access to, and what already exists.

  2. Interviews. How the front desk, clinical or operational staff, and administrators actually handle information on an ordinary day.

  3. Evidence and technical review. Existing documentation alongside the configuration of the systems it claims to describe.

  4. Risk analysis and findings. Each gap written in terms of what it exposes and what it would take to close, not as a control-number citation.

  5. Leadership readout. A conversation with the owner, practice manager, or operations lead in business language — plus follow-up guidance.

03After the findings

Remediation & maintenance

A report nobody acts on is an expensive filing exercise.

The deliverable that matters is the prioritized remediation plan: the gaps ordered by risk and effort, with an owner against each one. Some items are technical and we can implement them. Some are policy, training, or operational decisions that have to stay with your organization — the plan says which is which.

Workforce training usually appears on that list. Giving staff the practice and guidance to recognize a suspicious message and report it safely is one of the few safeguards that improves every other one.

Awareness and phishing practice

Scoped in your agreement

Which remediation work we carry out, which stays with your team, validation of completed items, re-assessment cadence, and any ongoing readiness support.

Environments change. A point-in-time assessment describes the point in time it was carried out, which is why readiness is maintained rather than achieved.

04The compliance boundary

Read this part before you read anyone else's compliance page.

This is the service where misleading marketing does the most damage, because the buyer often cannot tell the difference until an investigator asks. Here is exactly where our responsibility ends.

We do not certify compliance

We assess, advise, implement safeguards, support documentation, and help improve readiness. We cannot confer compliance, and we cannot grant immunity from enforcement. Those obligations remain with your organization.

There is no badge to buy

No provider can issue a recognized HIPAA certification to a covered entity. If a vendor offers you a seal for your website in exchange for a subscription, that seal evidences the subscription and nothing else.

We are not your legal counsel

We do not determine which requirements apply to your organization or interpret your obligations. Where that question is live — including whether and how Texas HB 300 applies to you — it is worth qualified legal or compliance counsel.

Nothing here eliminates risk

Layered safeguards and documented, prioritized corrective action reduce risk and improve your position. They do not remove it, and an assessment does not prevent an incident from occurring. How we talk about the work

05Common questions

The questions owners actually ask us.

Usually in this order, and usually after a peer has had a scare.

01Will this make us HIPAA compliant?

No. Compliance is a legal obligation of your organization, not something a technology provider can confer. Any vendor telling you otherwise is describing something they cannot deliver.

What an assessment does is establish where you actually stand, document the risk, and give you an ordered plan for improving readiness. That is the thing an investigator, an insurer, or an acquirer will want to see — evidence of a genuine, documented, acted-upon process.

02Is there a HIPAA certification we can display?

There is no government-recognized HIPAA certification that a provider can award to a covered entity. Plenty of companies sell seals; the seal evidences that you paid for the seal.

What holds up is documentation: a completed risk analysis, a prioritized remediation plan, records of what was fixed and when, and evidence of workforce training. We produce those rather than a logo.

03How long does an assessment take?

It depends on the number of locations, systems, and people in scope, and on how much documentation already exists. We scope it before it starts and tell you the timeline for your organization rather than quoting an average that would not apply to you.

The one thing worth knowing up front: the interview stage needs time from people who are usually busy, and it is the stage that most affects the quality of the result.

04Do you fix what you find, or just report it?

Both, within scope. Technical remediation — access controls, encryption, configuration, backup arrangements — is work we can carry out, and it is quoted explicitly rather than assumed.

Policy decisions, staffing, workflow changes, and anything requiring legal interpretation stay with your organization. The plan names an owner for every item so nothing sits in the gap between us.

05Does Texas HB 300 apply to us?

We do not make that determination. Which privacy requirements apply to your organization depends on where you operate, what information you handle, and your relationships with other entities — that is a legal question, and a costly one to get wrong on a vendor's say-so.

Tell us which requirements you or your counsel have confirmed apply, and we scope the assessment to them. If you are not sure, that is the first conversation to have, and not with us.

06Start with the assessment

Find out where you actually stand.

A readiness review establishes what is configured, what is documented, and what your team actually does — then turns the distance between those into a plan with owners and an order.

Or call (734) 772-9499 · Mon–Fri, business hours