For hospice agencies
Your patients’ last chapter deserves the same protection as the rest.
Security and evidence for hospices with field staff, phones in the car, and no IT department.
What we hear
Sound familiar?
Your clinicians chart from the road
Tablets and phones in homes, cars and facilities — often personal devices — each one a place patient data lives.
Aide turnover never stops
Every hire and every departure is an account to open or close in the EHR, email and anywhere else. The closing part is where breaches start.
Your vendors hold the keys
EHR, pharmacy, equipment and billing vendors all touch PHI. Recent Texas breaches started with stolen logins on vendor platforms.
Scrutiny is rising
CMS has tightened oversight of hospices, and buyers doing due diligence ask for your risk analysis, MFA and incident history.
Why it matters now
What’s different for you
You’ve already certified it to Medicare
Billing Medicare electronically means you signed CMS’s EDI enrollment agreement, which commits you to HIPAA security compliance. We produce the evidence behind that signature.
CMS-10164B, EDI Enrollment Agreement
Texas Medicaid’s breach clock is short
Texas Medicaid’s provider agreement requires notice to HHSC within one hour of discovering certain incidents involving Medicaid member information. That only works if someone is watching.
Texas HHSC Medicaid Provider Agreement (F00110), §11
Ready when someone wants to buy you
A documented risk analysis, a clean access history and a vendor inventory are the first things a buyer’s diligence team asks for.
How we help
Where to start
For providers & vendors
FreePolicy gap analysis
Send us the policies you have today. You get back a plain-English report of what’s missing against the HIPAA Security Rule.
- Works with whatever you have — a binder, a template pack, or nothing
- Each gap ranked by risk, with the fix spelled out
- Yours to keep, whether or not we work together
For providers
Vendor risk, done for you
We track every business associate, collect their security evidence and BAAs, chase what’s missing, and flag what changes.
- A complete vendor and BAA inventory
- Annual reviews sent, chased and filed for you
- Vendor findings land on your issue list, not in an inbox
For providers
CoreSecurity officer program
A named HIPAA security officer backed by our engine. Your inventory, monitoring, monthly reviews and annual risk analysis — with evidence for every one.
- Automated asset inventory across devices, accounts and cloud systems
- Monthly access, device, vendor, log and policy reviews, drafted for you and signed by a person
- Annual risk analysis and an evidence locker kept for six years
- One short issue list — what to fix, in what order
For providers & vendors
Trust site
A public security page backed by live evidence. Answer the next questionnaire with a link instead of a weekend.
- Shows the controls you actually run, not boilerplate
- Updates itself as your evidence changes
- Share sensitive documents only with approved requesters
Questions
Common questions
We use a cloud EHR. Isn’t security their job?+
They secure their platform. Who can log into your account, from which devices, and whether former staff still can — that part is yours, and it’s where most hospice incidents start.
Do our aides need to install anything?+
For company devices, a small agent gives us inventory and health checks. For personal phones we focus on account security and access reviews rather than taking over the device.
How long until we’re in good shape?+
The gap analysis takes days. Your first monthly review happens in your first month, and the inventory fills in from there.
Start with what you already have.
Send us your current policies and get a free gap analysis — or grab 30 minutes with Griffin to talk through where you stand.