ePHI exposure doesn't show up until OCR — or a breach — forces the question.

No documented risk analysis, missing BAAs with subcontractors, or a breach response plan that can't meet the clock are the three findings that turn a routine complaint into an enforcement action.

The "HIPAA certified in a day" pitch
  • A generic policy packet sold as a "HIPAA compliance kit"
  • No documented risk analysis covering the systems that actually touch ePHI
  • Business Associate Agreements missing or unreviewed with key subcontractors
  • A breach response plan that couldn't realistically meet the 60-day notification clock
The DarkDataLabs way
  • A §164.308 risk analysis built from your real systems and workflows, documented and defensible
  • Administrative, physical, and technical safeguards mapped to what you actually run
  • BAAs reviewed or drafted with every business associate and subcontractor touching ePHI
  • A breach notification plan built around the real 60-day deadline, with roles assigned before you need it

Three steps. No maze.

01

Free readiness scan

Tell us what ePHI you handle and where it lives. No patient data required to start.

02

We score the safeguards

Administrative, physical, and technical safeguards assessed against the Security Rule, BAA coverage checked.

03

You get a defensible plan

A prioritized remediation list and a risk analysis outline ready to document — within 24 hours.

Start free. Pay only when the next step is clear.

Always free
$0

HIPAA Readiness Scan

High-level safeguards gap summary and next-step recommendation, in 24 hours.

Request Free Scan
Fixed fee
$299–$750

Risk Analysis & Gap Assessment

Full §164.308 gap review, BAA inventory check, prioritized safeguards register, 30-minute walkthrough.

Start with Free Scan
Project
$2,500–$10k+

Full Risk Analysis & Remediation

Documented risk analysis, safeguards remediation, BAA drafting, and breach response plan built to survive an OCR review.

Start with Free Scan

HIPAA Compliance Pros — straight answers

Can you just certify us as HIPAA compliant?

No, and be wary of anyone who offers this — there is no official government HIPAA certification. What you actually need is a documented §164.308 risk analysis and safeguards that match your real environment. That's what OCR looks for, and what we build.

What's the difference between the Security Rule and the Privacy Rule?

The Privacy Rule governs how protected health information can be used and disclosed. The Security Rule specifically covers electronic PHI (ePHI) and requires administrative, physical, and technical safeguards, including the annual risk analysis under §164.308. Most of our engagements start with the Security Rule because that's where the technical gaps live.

Do we need a BAA with every vendor that touches patient data?

Yes — any business associate that creates, receives, maintains, or transmits ePHI on your behalf needs a signed Business Associate Agreement before they touch that data, not after. We inventory your vendors and flag which ones are missing coverage.

What actually happens if OCR opens an inquiry or audit?

OCR typically requests your risk analysis, policies, and evidence of safeguards first. Organizations without a documented risk analysis are the ones that end up with corrective action plans and settlements. Having the documentation ready before you're asked is the entire point of doing this now.

We're a small practice, not a hospital — does this really apply to us?

If you're a covered entity or business associate handling ePHI, the Security Rule applies regardless of size. Practices, med-tech vendors, and MSPs with healthcare clients are exactly who OCR enforcement actions have targeted in recent years — size doesn't exempt you.

Tell us what triggered the compliance question.

Business context only — no sensitive documents yet. Initial response within 24 hours.

🔒 Your information is never sold. The scan is a readiness check, not a certification or legal opinion.
✓ Thanks — your request was received. We'll respond within 24 hours.