Skip to content

For small healthcare and the companies that serve it

HIPAA security you can prove.

A named security officer, monthly reviews drafted by our engine and signed by a person, and the evidence to show Medicare, your insurer and your clients — without hiring a security team.

Access review · March

Drafted from your HR roster and 4 connected systems

Draft · needs sign-off
  • Former front-desk coordinatorStill activeEHR, emailLeft 9 days ago
  • Contract speech therapistStill activeEHRContract ended 31 days ago
  • Office managerNo 2-step sign-inEmail adminCurrent staff
  • 42 other accountsOKAll systemsMatch HR roster

3 findings → added to your issue list

CommentApprove & sign

Illustration with sample data.

The problem

You’ve already promised you’re secure.

Small healthcare signs security commitments all the time. Almost nobody can show the evidence when someone finally asks.

Medicare

If you bill Medicare electronically, you signed an agreement to comply with the HIPAA security rules.

Medicaid

Many state Medicaid agreements make you certify HIPAA compliance — some with breach deadlines measured in hours.

Your insurer

Cyber insurance applications ask about MFA, backups and training — and increasingly want evidence, not checkboxes.

Your clients

If you serve healthcare, every client’s security questionnaire asks you to prove the same things again.

And the person holding all of it is usually an office manager or an owner — not a security professional. Small healthcare shouldn’t need a Fortune 500 security team to protect its patients.

Who’s behind it

Built by someone who’s run small healthcare — and secured big healthcare.

I’m Griffin Brown. I founded and grew Therapitas, a therapy practice in Oklahoma. I’ve also done security work for Beth Israel Lahey Health, a Harvard teaching hospital, and stood up the Defense Health Agency’s zero trust security program.

HIPAA Made Simple is what I wished I’d had as an owner: a real security officer, the work done every month, and proof you can hand to anyone who asks.

More about Griffin →

How it works

Three steps. Then it runs every month.

  1. 01

    Send us your policies

    Start with a free gap analysis of whatever you have today. No binder? That’s a finding, not a problem.

  2. 02

    Connect your systems

    We connect to your email, devices, EHR and cloud tools, and build a live inventory of who and what touches patient data.

  3. 03

    Review, sign, done

    Each month you get short, drafted reviews and one prioritized issue list. A named security officer signs off. The evidence files itself.

See how it works in detail →

What we do

Start small. Go as far as you need.

Most clients start with the free gap analysis or vendor risk, then move to the full security officer program.

Start with what you already have.

Send us your current policies and get a free gap analysis — or grab 30 minutes with Griffin to talk through where you stand.