Compliance Frameworks
HIPAA compliance that runs as an operation, not a binder
Updated September 2026
HIPAA applies to more healthcare-adjacent businesses than ever - covered entities, yes, but also the business associates that touch patient data: billing firms, IT providers, analytics vendors, dental and specialty practices with modern software stacks. The failure mode is familiar: a security risk analysis done once, policies nobody enforces, and no evidence trail when an auditor or a breach demands answers. Class IV runs HIPAA as part of your IT operations. Our fractional CISO owns the risk analysis, implements the administrative, physical, and technical safeguards inside your actual environment, manages business associate agreements, and keeps the evidence current so a breach, an audit, or a partner questionnaire finds you ready. For healthcare and healthcare-adjacent companies in Denver and Houston with 30 to 100 employees, HIPAA stops being an annual scramble and becomes a standing condition of how you operate.
Who HIPAA applies to (it is probably you)
Covered entities are the obvious group: healthcare providers, health plans, and clearinghouses that create or receive protected health information. The larger group is business associates, the companies that handle that information on a covered entity's behalf. Billing firms, IT providers, cloud hosts, analytics vendors, transcription services, and consultants all qualify the moment patient data passes through their systems. The obligation does not stop there. Business associates that hand data to their own vendors create subcontractor relationships, and those subcontractors carry the same duty to protect it. If your company stores, transmits, or can access patient data for someone else, HIPAA almost certainly applies to you, whether or not you think of yourself as a healthcare company. The first step is mapping where that data actually flows.
The security risk analysis: the first thing auditors ask for
The security risk analysis is the foundation of HIPAA's Security Rule and the first document an auditor or investigator requests. It must identify where electronic protected health information lives, the threats and vulnerabilities facing it, the likelihood and impact of each, the safeguards already in place, and the resulting level of risk. The version that fails is the one done once, filed away, and never revisited while the environment changes around it. New software, new locations, remote staff, and new vendors all change your risk. A current analysis reflects the systems you run today, ties each risk to a named owner and a remediation step, and is updated whenever something significant changes. That is the version that holds up when someone asks for proof.
Safeguards that live inside your IT environment
HIPAA groups safeguards into three categories. Administrative safeguards cover workforce training, access authorization, security management, and the policies that govern who can do what. Physical safeguards protect facilities, workstations, and devices that hold patient data. Technical safeguards cover access controls, unique user identification, audit logging, encryption, and integrity protections. Most programs describe all of this in a policy binder. Few implement it in the systems staff actually use. Because our managed services team runs your environment, the safeguards are configured where they matter: multi-factor authentication on the applications that touch patient data, encryption on endpoints and backups, logging that is reviewed, and access that is removed the day someone leaves. The policy and the configuration match, and both can be shown.
BAAs, breach response, and the evidence trail
Business associate agreements are only useful when they are current and complete. That means knowing every vendor that touches patient data, holding a signed agreement with each, and reviewing those agreements when services change. Breach response needs the same discipline. A defensible response starts with a written plan, moves quickly to contain and investigate, runs the required risk assessment to decide whether notification is triggered, and documents every decision along the way. The thread running through all of it is evidence. Access reviews, training records, risk analysis updates, incident logs, and vendor agreements should be collected as part of normal operations, not assembled after the fact. When a breach, an audit, or a partner questionnaire arrives, the proof is already there.
One partner from gap to audit
Most HIPAA programs break at the handoff between the people who write the policies and the people who run the systems. The 10-day Stabilization Sprint is the entry point: it maps where patient data lives, surfaces the gaps, and turns them into a prioritized plan with owners. From there, your fractional CISO and our managed services team carry the program from gap to audit.
Frequently asked questions
- Does HIPAA apply to my IT vendor?
- Yes, if your IT vendor can access, store, or transmit protected health information on your behalf. That makes them a business associate, which requires a signed business associate agreement and their own safeguards. It also means their security practices become part of your risk, so vendor due diligence belongs in your HIPAA program, not outside it.
- What triggers a HIPAA risk analysis?
- HIPAA expects the risk analysis to be ongoing, not a one-time event. Beyond a regular review cycle, it should be updated whenever something significant changes: new systems or software, a new location, a move to the cloud, new vendors handling patient data, a security incident, or changes in how staff access information. A stale analysis is a common audit finding.
- What happens after a HIPAA breach is discovered?
- The first priority is containment and investigation to understand what data was involved and how. Next comes a documented risk assessment to decide whether the incident is a reportable breach. If it is, affected individuals, regulators, and sometimes the media must be notified within required timeframes. Every decision along the way should be documented as evidence.
- Is a signed BAA enough to be compliant?
- No. A business associate agreement defines responsibilities, but it does not implement a single safeguard. Compliance requires a current security risk analysis, administrative, physical, and technical safeguards running in your environment, workforce training, breach response procedures, and evidence that all of it works. The BAA is one required document within a much larger operating program.
- Do you support healthcare practices in Houston as well as Denver?
- Yes. Denver and Houston are both primary markets for Class IV, and we support healthcare practices and business associates in each. Fractional CISO leadership and managed services are delivered remotely nationwide, so risk analysis, safeguard implementation, BAA management, and evidence work run the same way in either city, with on-site support when needed.