5 Pheasant Dr, Mt Laurel, NJ 08054 Mon-Sat 9:00 am - 5:00 pm (856) 580-0801 Make an Appointment

HIPAA Privacy & Security

Risk analysis, safeguards, workforce training and breach notification for practices of every size.

Privacy Rule

  • Notice of Privacy Practices, acknowledged and posted
  • Minimum necessary use and disclosure standard
  • Patient rights: access, amendment, accounting of disclosures
  • Designated Privacy Officer

Security Rule

  • Documented security risk analysis and management plan
  • Administrative, physical and technical safeguards
  • Access control, audit controls, encryption at rest and in transit
  • Contingency plan and data backup

Breach Notification

  • Four-factor risk assessment for any impermissible use
  • Individual notice without unreasonable delay, within 60 days
  • HHS reporting - immediate for 500+, annual below that
  • Documented incident response procedure

Business Associate Agreements

Every vendor that creates, receives, maintains or transmits PHI on your behalf needs a signed BAA. We review your vendor list and flag the gaps.

Request a HIPAA Review