For business associates
Stop answering the same security questionnaire for every client.
For billing companies, IT providers, staffing agencies and software vendors that serve healthcare.
What we hear
Sound familiar?
Every client asks again
Each healthcare client sends its own questionnaire, BAA and evidence request — and they all ask for the same proof.
Security is a sales blocker
Deals stall while a provider’s compliance person waits on answers you have to assemble by hand.
You’re a business associate now
Signing a BAA makes you directly responsible for HIPAA security. Most small vendors have never had a risk analysis.
Why it matters now
What’s different for you
One link instead of a weekend
A trust site shows the controls you actually run, backed by live evidence, and shares sensitive documents only with approved requesters.
Reviewed once, reused everywhere
When we manage vendor risk for providers, a vendor with a current trust site answers once instead of to each client.
How we help
Where to start
For providers & vendors
Trust site
A public security page backed by live evidence. Answer the next questionnaire with a link instead of a weekend.
- Shows the controls you actually run, not boilerplate
- Updates itself as your evidence changes
- Share sensitive documents only with approved requesters
For providers & vendors
FreePolicy gap analysis
Send us the policies you have today. You get back a plain-English report of what’s missing against the HIPAA Security Rule.
- Works with whatever you have — a binder, a template pack, or nothing
- Each gap ranked by risk, with the fix spelled out
- Yours to keep, whether or not we work together
For providers
CoreSecurity officer program
A named HIPAA security officer backed by our engine. Your inventory, monitoring, monthly reviews and annual risk analysis — with evidence for every one.
- Automated asset inventory across devices, accounts and cloud systems
- Monthly access, device, vendor, log and policy reviews, drafted for you and signed by a person
- Annual risk analysis and an evidence locker kept for six years
- One short issue list — what to fix, in what order
For providers & vendors
À la carteSecurity testing
Scoped vulnerability assessments and penetration testing, sized for small organizations, with findings tracked to closure.
- External and internal vulnerability assessment
- Scoped penetration testing on request
- Findings go straight onto your issue list
Questions
Common questions
Will you rate us differently if we’re a customer?+
No. Reviews we run for providers are the same whether or not a vendor works with us, and we disclose the relationship. Our signature is only worth something if it can’t be bought.
We’re not a healthcare company. Does HIPAA really apply?+
If you create, receive, store or transmit PHI for a covered entity, you’re a business associate, and the Security Rule applies to you directly.
Start with what you already have.
Send us your current policies and get a free gap analysis — or grab 30 minutes with Griffin to talk through where you stand.