Compliance / Audits
Know what you have, and who can get to it.
Clear documentation and regular access reviews for the technical side of HIPAA, cyber insurance questionnaires and client security requirements.
Compliance usually shows up as a form: an insurance renewal, a client's vendor questionnaire, a HIPAA risk assessment. The questions are simple. Answering them honestly is harder if nobody's sure what's actually set up.
We audit what you have, document it, fix the gaps and give you the evidence to back up your answers.
What's included
- Inventory of computers, servers, network gear and software
- Microsoft 365 access reviews: accounts, admin roles, MFA status, external sharing and forwarding rules
- Former employee and shadow IT cleanup
- The technical safeguards side of HIPAA: encryption, access controls, audit logs, backups
- Help answering cyber insurance and client security questionnaires
- End-of-life tracking so aging systems get replaced on your schedule
- Written documentation in plain English, kept current
What we're not
We handle the technical side. We're not attorneys or certified auditors, and we'll tell you when a question needs one. For HIPAA, that means we work alongside your compliance officer or consultant, not in place of them.
FAQ
IT Compliance & Audits: common questions
Can you do a HIPAA risk assessment?
We handle the technical safeguards portion and the documentation that supports it, and work alongside whoever owns your overall HIPAA program.
What's an access review?
A check of who can get into what: which accounts exist, who's an admin, who has MFA, what's shared outside the company and what should be shut off. It's where we usually find former employees who still have access.
Find out where your IT stands.
A free assessment is a walk-through of your computers, network, email and backups, followed by a plain-English list of what's fine, what's risky and what we'd fix first. No obligation, no scare tactics.