For Anchorage medical, dental & legal practices
The compliance you sign for starts with the IT underneath.
HIPAA does not certify software; it asks your practice to protect patient data with reasonable safeguards and to document that you did. We build and run the IT side: the technical safeguards, the backups, the logging, and the records that hold up.
HIPAA Security Rule
Three safeguard categories
Administrative
Risk assessment, policies, workforce training, a named security contact.
Physical
Device control, workstation security, encrypted media, safe disposal.
Technical
Access controls, MFA, encryption, audit logging, tested backups.
We implement the technical safeguards and document all three. We do not issue HIPAA certifications, no IT company can.
What HIPAA actually requires of a small practice
HIPAA's Security Rule is not a checklist you buy. It asks covered entities, the dentist's office, the clinic, the therapy practice, to put in place administrative, physical, and technical safeguards appropriate to their size and risk, and to keep documentation proving they did. Most small Anchorage practices are far closer to compliant than they fear on the policy side, and farther than they think on the technical side.
The technical safeguards, the part that lives in your IT, are where we work: access controls, encryption, audit logging, malware protection, and contingency planning. The gaps we find most often are not exotic: no enforced MFA, laptops that were never encrypted, backups nobody has tested, and a missing Business Associate Agreement with a vendor.
The technical safeguards we implement
The six technical controls HIPAA's Security Rule expects.
Access controls
Unique logins per person, MFA on everything that touches patient data, role-based access so the front desk cannot open clinical records they do not need, and same-day account disabling when someone leaves.
Encryption, at rest and in transit
Full-disk encryption on every laptop and workstation (BitLocker, FileVault), encrypted email for anything containing PHI, and TLS on every connection. A lost-but-encrypted laptop is not a reportable breach.
Audit logging
Sign-in and access logging in Microsoft 365 or Google Workspace and in your practice management system, retained and reviewable, so you can answer "who accessed what, and when" if you ever have to.
Backup and contingency
Tested, encrypted, isolated backups of patient records, plus a written contingency plan so an outage or ransomware event does not become a patient-safety or reporting problem.
Malware and threat protection
Modern endpoint detection (Huntress EDR), email filtering, and patch management, because the most common cause of a HIPAA breach at a small practice is a phished account or ransomware, not a hacker.
Workforce safeguards
Security awareness training so your team can spot the phishing email that targets a clinic, plus documented policies for devices, passwords, and remote access.
What working with us covers
The IT half of HIPAA, handled.
We are your IT and security partner for the technical and documentation requirements. For clinical compliance, legal review, or formal certification, we coordinate with the right specialists.
Security risk assessment
A documented review of where PHI lives and how it is protected, the assessment HIPAA expects you to perform and keep current.
Business Associate Agreement
As your IT provider with potential access to systems holding PHI, we sign a BAA with you, and we help you confirm your other vendors have signed theirs.
Technical safeguards, implemented
MFA, encryption, EDR, logging, and tested backups configured and verified, not just recommended.
Documentation you can show
Policies, configurations, and assessment records kept current, because in HIPAA, if it is not documented, it did not happen.
An honest word on what we are, and aren't
We help you meet HIPAA's technical requirements. We do not certify HIPAA compliance, because no IT company truthfully can: HIPAA has no government certification, and compliance is a practice-wide responsibility that includes clinical, legal, and administrative pieces well outside IT. Anyone selling you a "HIPAA certified" guarantee is overstating it. What we deliver is real and documentable: the technical safeguards implemented and verified, a current risk assessment, a signed BAA, and the records to show your good-faith effort. For formal compliance attestation or legal sign-off, we will point you to a qualified partner.
Built for these practices
Law firms
Client confidentiality, encrypted email, secure portals, document retention.
IT for law firms →
Professional services
Practices handling sensitive client records that need real safeguards.
IT for professional services →
Cybersecurity
The EDR, identity hardening, and IR that the technical safeguards rely on.
Managed cybersecurity →
See where your practice stands.
The free 30-minute IT Health Check includes a look at the HIPAA technical safeguards: whether MFA is enforced, whether devices are encrypted, and whether your backups would actually restore. Real findings, no sales pitch.