Skip to content

For healthcare providers

Your security officer, without the hire.

We take HIPAA security off the plate of whoever got stuck with it — and give them proof they can hand to Medicare, Medicaid, insurers, auditors and buyers.

Access review · March

Drafted from your HR roster and 4 connected systems

Draft · needs sign-off
  • Former front-desk coordinatorStill activeEHR, emailLeft 9 days ago
  • Contract speech therapistStill activeEHRContract ended 31 days ago
  • Office managerNo 2-step sign-inEmail adminCurrent staff
  • 42 other accountsOKAll systemsMatch HR roster

3 findings → added to your issue list

CommentApprove & sign

Illustration with sample data.

Security officer program

The work a security officer should do every month — done, signed and filed.

Our engine collects evidence continuously and drafts each review. A named security officer checks it, signs it, and turns findings into one prioritized issue list.

Access review

Your HR roster against every account in every connected system. Who left but still has access, who has more than they need, who isn’t using 2-step sign-in.

Device review

Encryption, firewall, updates and antivirus on every enrolled computer, plus devices we find on your network that nobody enrolled.

Vendor review

Every business associate, their BAA, their latest security evidence, and what changed since last time.

Log review

Sign-in and admin activity from your email, EHR and cloud systems, with the unusual parts pulled out for a human to look at.

Policy review

Your policies checked against what your evidence shows you actually do — not just whether the document exists.

Plus, every year

A documented risk analysis — the document OCR asks for first — built from a year of real evidence instead of a questionnaire.

Vendor risk, done for you

Your vendors are part of your security. We’ll keep track of them.

Most small providers sign a BAA and never look at the vendor again. We build your vendor inventory, collect evidence every year, chase what’s missing and put real findings on your issue list.

For providers

Vendor risk, done for you

We track every business associate, collect their security evidence and BAAs, chase what’s missing, and flag what changes.

  • A complete vendor and BAA inventory
  • Annual reviews sent, chased and filed for you
  • Vendor findings land on your issue list, not in an inbox
Learn more →

Questions

Common questions

Do you replace our IT company?+

No. We work alongside your IT provider. They run your systems; we independently check them and keep the evidence.

Who signs the reviews?+

A named security officer — Griffin, or an HMS security officer working under the same process. Our engine drafts; a person decides.

Do you sign a BAA?+

Yes. We sign a business associate agreement with every client that shares protected health information with us.

Do you use AI on our data?+

Our engine does the collecting and drafting, and a person makes the decisions. We design our systems so patient data isn’t sent to outside AI services, and sanitize anything processed beyond our own systems.

Start with what you already have.

Send us your current policies and get a free gap analysis — or grab 30 minutes with Griffin to talk through where you stand.