Solution

HIPAA compliance for smbs

Between 20 and 200 people, no CISO, and a compliance burden written for organisations ten times your size.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

Between 20 and 200 people, no CISO, and a compliance burden written for organisations ten times your size.

What you get

  • A Privacy and Security Officer on retainer instead of a hire
  • Guided risk analysis your operations lead can run
  • Training that fits into an existing onboarding flow
  • Published pricing so you can budget without three sales calls

The shared responsibility line

This is where most teams get it wrong. Your provider secures the infrastructure. You secure your configuration, your identities, your data classification, your logging retention, and your workforce. Every enforcement action we have read involved the second half of that sentence, not the first.

How it fits together

LayerWho owns itHow SuperHIPAA helps
InfrastructureProvider (under BAA)We verify your BAA is current and covers the services you use
ConfigurationYouContinuous checks mapped to §164.312
Data classificationYouePHI inventory and flow mapping
WorkforceYouTraining, acknowledgement, access reviews
DocumentationYouPolicies, risk analysis, evidence, all versioned

Start where you are

Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.

Questions

Is a signed BAA from our cloud provider enough?

No. A BAA allocates responsibility; it does not implement safeguards. Your configuration, access control, logging, and workforce practices are still assessed against the Security Rule.

Can we do HIPAA and SOC 2 at the same time?

Yes, and you should. Roughly two-thirds of the control work overlaps. One control set, two outputs — that is how the platform is built.

How fast can we be ready for a customer security review?

Trust centre and questionnaire library go live in days. A defensible full program takes 8–12 weeks. We tell prospects the difference honestly, and so should you.

Do we have to hire a compliance officer?

You must name a Privacy Officer and a Security Officer, but they can be existing staff — an operations lead or practice manager holds the role at most SMBs. If nobody has the bandwidth or confidence, the Virtual HIPAA Officer service fills the seat without a hire.

What does HIPAA compliance realistically cost an organisation our size?

Platform pricing is published and locked for three years, and services are fixed-fee, so the cash cost is knowable up front. The larger cost is staff time — a few hours a week during buildout, tapering to maintenance. Budget for both and you will not be surprised.

Can our office manager actually run this without a security background?

Yes — that is who the guided risk analysis was written for. Plain-language questions, prefilled clinic-scale threat scenarios, and the technical items handed to your IT provider as specific tasks. Where judgment is genuinely needed, our team is in-house, not a chatbot.

What actually triggers OCR attention for a small organisation?

Patient complaints, a lost or stolen unencrypted device, and ransomware reports are the big three. Almost never a random audit. The investigation then starts with your risk analysis regardless of what triggered it — which is why that document being current matters more than anything else.

Our cyber insurance renewal is asking HIPAA-ish questions. Related?

Very. Insurers now ask for a risk analysis, MFA coverage, training records, and backup evidence — essentially the Security Rule with a premium attached. A maintained program answers the renewal questionnaire from the same evidence library, and some organisations see it reflected in terms.

How often does a 30-person team need training?

Annual refresher at minimum, training at hire before ePHI access, and a targeted update when something material changes — a new system, a new policy, an incident. Ours takes under an hour, and the acknowledgement records are the evidence OCR asks for.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo