top of page
Original size.jpg

Fractional Privacy & Security Officer

Ongoing HIPAA compliance support, without adding a full-time employee.

Anchor 1

THE MOMENT THIS IS FOR

You're growing, adding systems, or expanding services that touch patient information, and HIPAA requires you to name a Privacy and Security Officer. Most practices hand that role to someone already stretched thin, or leave it unfilled. This is that role, filled by someone whose actual job it is.

THIS IS FOR YOU IF:

✔ You're growing, adding systems, or expanding services that affect protected health information.
✔ You don't have an internal HIPAA privacy or security lead, and don't want to build that role in-house.
✔ You want ongoing support so your policies, training, and controls don't go stale.

INCLUDES:

✔ A named Privacy Officer and Security Officer for your organization.
✔ Recurring compliance checks and updates to your risk register.
✔ Quarterly staff training, new-hire training, and acknowledgment tracking.
✔ Regular updates to your policy and procedure suite as your operations change.
✔ Ongoing coordination with your IT support on technical safeguards and backups.
✔ An annual leadership briefing on risk, incidents, and priorities.
✔ Audit-ready documentation maintained year-round.
✔ Support preparing materials for payers, partners, regulators, or insurers.

WHAT YOUR PRACTICE GAINS:

✔ A living HIPAA program that adapts as your practice changes.
✔ A partner who tracks what needs to happen and when, so you don't have to.
✔ Long-term peace of mind knowing you're not managing HIPAA alone.

Starts at $1,500/month - based on scope.

TWO WAYS TO START:

Already There


Completed HIPAA Essentials, or a Security Risk Assessment we've done or reviewed within the last 60 days? Start now, at the standard rate. No extra step.

Starting Fresh


A short, paid Onboarding Assessment establishes where things actually stand before your name is on the program. If it turns up major gaps, that becomes its own scoped project, never folded quietly into the monthly rate.

WHY US:

Twenty years at Boeing, Microsoft, and Costco taught us which questions on your application actually matter, what real security controls look like, and where HIPAA overlaps with what your insurer is asking. You get findings you can act on, not just a checklist.

FREQUENTLY ASKED QUESTIONS

What does a fractional HIPAA Privacy and Security Officer do?


A fractional Privacy and Security Officer fills the role HIPAA requires every practice and Business Associate to name, without a full-time hire. That means recurring compliance checks, updated policies as your operations change, staff training, and support preparing materials for insurers, regulators, or partners, all handled by someone whose actual job it is.

Do I need a full-time employee to fill the HIPAA Privacy and Security Officer role?


No. HIPAA requires the role to be filled and named, not that it be a full-time position. Most practices and smaller Business Associates can't justify a full-time compliance hire, which is exactly the gap a fractional officer fills.

Can I start without completing HIPAA Essentials first?


Yes. If a Security Risk Assessment was done or reviewed within the last 60 days, the Fractional Privacy and Security Officer service starts right away at the standard rate. Starting from somewhere else, a short onboarding assessment establishes where things actually stand first.

What happens if the onboarding assessment finds problems?


Real gaps get scoped and quoted as their own project, separate from the monthly rate. The monthly retainer is built to maintain a program, not to secretly absorb the cost of building one from scratch.

Do Business Associates need a Privacy and Security Officer too?


Yes. Any business that creates, receives, maintains, or transmits patient data on behalf of a healthcare client has the same requirement to name a privacy and security officer as the practice itself.

MOST COMMON NEXT STEP

Not sure if you qualify? Start with a Security Risk Assessment, and this becomes available as soon as it's done.


About the Security Risk Assessment 

bottom of page