Cybersecurity for healthcare providers.
Protect patient and customer data, comply with HIPAA and HITECH, and satisfy the business associate agreements you have signed.
Protect what people trust you with
A four-clinician practice, a behavioral health agency, and a disability services provider are covered entities exactly as a hospital system is. OrbitalFire helps smaller healthcare providers protect the records people trust them with, satisfy HIPAA and HITECH, and answer the partners who ask for proof, so you can stay focused on the people you serve.
After 20 years, the HIPAA Security Rule is expected to be rewritten, and cyber insurance is increasingly tied to the controls you actually have in place. We help smaller providers through the changing landscape, including the compliance, the audits, and the breach notification requirements. Not sure where you stand today? That is where we start.
Healthcare solutions overview (PDF)What we help with
The risk analysis, kept current
HIPAA wants an accurate and thorough assessment of risks to ePHI (electronic protected health information). It is the item most often found missing, because it tends to be done once and then filed.
Policies that match how you run
Policy and Plan Development that reflects how you actually run, rather than a template that describes somebody else.
A named security official
HIPAA requires you to designate one. Our vCISO does that job's work. The designation, and the responsibility, stay with you.
Training your people will finish
Awareness Training and Phishing Testing, sized for staff to complete between appointments.
Your business associates
Third Party Risk Management for the agreements you sign and the ones you issue, and for knowing which vendors are business associates at all.
Safeguards that keep running
Vulnerability Management and Intrusion and Threat Detection, which have to keep working rather than pass once.
Ready before the call comes
Incident Response planning, with the breach notification clock built into the plan rather than looked up during it.
Practice the response
Incident Response Tabletops, because rehearsing the response matters more than owning a document that describes it.
Does our EHR vendor's certification cover us?
No. Their certification covers their software. The Security Rule applies to you as a covered entity, which means your risk analysis, your training records, your policies, and the decisions you documented.
Do we need a security officer if we only have a few staff?
Yes. The rule requires you to designate a security official regardless of headcount. Our vCISO does that job's work: the risk analysis, the policies, and the training records. The designation, and the responsibility, stay with you.
How often does the risk analysis need to be redone?
HIPAA asks for it to be accurate, thorough, and current, which in practice means revisiting it whenever the organization changes. A new location, a new EHR, a new telehealth platform, or a new business associate are all reasons to look at it again. Our Assessments cover the Security Rule control by control, and we revisit the analysis as the organization changes.
Does HIPAA expect less of a smaller practice?
Less in the how, not in the whether. The Security Rule asks you to weigh your size, your complexity, your technical capability, and what a measure costs when you decide how to meet a standard, and the addressable specifications exist so a smaller provider can document why a particular approach is not reasonable for them. What none of that changes is whether the rule applies to you. There is no small-provider exemption in HIPAA. Deciding how to meet a standard, and writing down why, is the part we do with you.
Do we have to be perfect?
No. The Office for Civil Rights is looking for continuous improvement, accountability, and documentation rather than a perfect score. That is a far more reachable target for an organization your size, and a very different exercise from trying to close every control at once.
We are a nonprofit. Is this the right page?
It depends on where your obligations come from. If they arrive mainly through grant agreements, state contracts, and funder conditions, start with Human Services. If you deliver behavioral health or care management, HIPAA follows the data and this page applies to you as well.
Is HIPAA mostly a technology problem?
No, and that surprises people. The administrative safeguards, meaning the risk analysis, the workforce training, the sanction policy, and the documented decisions, are where the rule spends most of its words and where reviews spend most of their attention.
Where do smaller providers struggle?
Rarely with buying the right tools. It is the everyday things: holding signed agreements with every business associate, removing access when someone leaves, producing evidence that training happened, and explaining in writing why a particular workaround is reasonable for an organization of your size.
We do not treat patients, but we handle their records. Does HIPAA apply to us?
Very likely, as a business associate. Billing companies, IT providers, shredding services, answering services, and software vendors all fall under it. It usually reaches you as a business associate agreement someone asks you to sign, which is part of Third Party Risk Management. Signing it is the part people notice. The Security Rule work behind it is the part that gets skipped. With the HIPAA Security Rule expected to be rewritten, we are here to help you work out whether it applies to your business.
Tell us about your business.
A half-hour conversation about what you're being asked for and where you actually stand. If we can help, you'll have a proposal usually within a day.
Not ready to talk? Check your readiness in five minutes and see where to start.