For small healthcare and the companies that serve it
HIPAA security you can prove.
A named security officer, monthly reviews drafted by our engine and signed by a person, and the evidence to show Medicare, your insurer and your clients — without hiring a security team.
Access review · March
Drafted from your HR roster and 4 connected systems
- Former front-desk coordinatorStill activeEHR, emailLeft 9 days ago
- Contract speech therapistStill activeEHRContract ended 31 days ago
- Office managerNo 2-step sign-inEmail adminCurrent staff
- 42 other accountsOKAll systemsMatch HR roster
3 findings → added to your issue list
Illustration with sample data.
The problem
You’ve already promised you’re secure.
Small healthcare signs security commitments all the time. Almost nobody can show the evidence when someone finally asks.
Medicare
If you bill Medicare electronically, you signed an agreement to comply with the HIPAA security rules.
Medicaid
Many state Medicaid agreements make you certify HIPAA compliance — some with breach deadlines measured in hours.
Your insurer
Cyber insurance applications ask about MFA, backups and training — and increasingly want evidence, not checkboxes.
Your clients
If you serve healthcare, every client’s security questionnaire asks you to prove the same things again.
And the person holding all of it is usually an office manager or an owner — not a security professional. Small healthcare shouldn’t need a Fortune 500 security team to protect its patients.
Who’s behind it
Built by someone who’s run small healthcare — and secured big healthcare.
I’m Griffin Brown. I founded and grew Therapitas, a therapy practice in Oklahoma. I’ve also done security work for Beth Israel Lahey Health, a Harvard teaching hospital, and stood up the Defense Health Agency’s zero trust security program.
HIPAA Made Simple is what I wished I’d had as an owner: a real security officer, the work done every month, and proof you can hand to anyone who asks.
More about Griffin →How it works
Three steps. Then it runs every month.
- 01
Send us your policies
Start with a free gap analysis of whatever you have today. No binder? That’s a finding, not a problem.
- 02
Connect your systems
We connect to your email, devices, EHR and cloud tools, and build a live inventory of who and what touches patient data.
- 03
Review, sign, done
Each month you get short, drafted reviews and one prioritized issue list. A named security officer signs off. The evidence files itself.
What we do
Start small. Go as far as you need.
Most clients start with the free gap analysis or vendor risk, then move to the full security officer program.
For providers & vendors
FreePolicy gap analysis
Send us the policies you have today. You get back a plain-English report of what’s missing against the HIPAA Security Rule.
Learn more →For providers
Vendor risk, done for you
We track every business associate, collect their security evidence and BAAs, chase what’s missing, and flag what changes.
Learn more →For providers & vendors
Trust site
A public security page backed by live evidence. Answer the next questionnaire with a link instead of a weekend.
Learn more →For providers & vendors
À la carteSecurity testing
Scoped vulnerability assessments and penetration testing, sized for small organizations, with findings tracked to closure.
Learn more →Who we serve
Made for organizations without a security team.
Hospice →
Security and evidence for hospices with field staff, phones in the car, and no IT department.
Home health →
Device, account and vendor security for agencies whose staff work everywhere but the office.
Vendors to healthcare →
For billing companies, IT providers, staffing agencies and software vendors that serve healthcare.
Healthcare networks & groups →
For therapy networks, management companies and groups running many small practices.
PT, OT & speech therapy →
For physical, occupational and speech therapy practices — from one clinic to a growing group.
Start with what you already have.
Send us your current policies and get a free gap analysis — or grab 30 minutes with Griffin to talk through where you stand.