Client support portal Pay invoice Sales(615) 555-0110 Support(615) 555-0111
Chartline Health IT
HIPAA Compliance Program

The thing practices get penalized for is a documentation failure.

The single most-cited finding in HIPAA enforcement is not a missing firewall. It is the absence of an accurate and thorough risk analysis under §164.308(a)(1)(ii)(A), and increasingly the absence of a documented risk management plan under §164.308(a)(1)(ii)(B). Documentation is exactly what a generalist IT company does not produce, because it is not part of the managed services product they sell.

Included in: Included in Chartline Compliant. Available standalone as a risk analysis or vCISO retainer.

What this actually is

Six things, described plainly.

No capability matrix and no maturity model. This is what we do, why it matters in a clinical environment, and where the number comes from.

01

A real risk analysis, not a questionnaire

Enterprise-wide, every location, every system, every ePHI repository, conducted against NIST SP 800-66 Rev. 2 and mapped to Security Rule citations. A completed HHS SRA Tool questionnaire has repeatedly failed to satisfy investigators, and OCR settlements say so explicitly.

02

A dated risk management plan with owners

Prioritized remediation, assigned to a person, with evidence of completion. OCR Director Paula Stannard has confirmed the Risk Analysis Initiative expands in 2026 to cover risk management, not just risk analysis. A completed analysis with no evidenced remediation is now its own exposure.

03

Recognized Security Practices, documented for twelve rolling months

Under the HITECH amendment signed January 5, 2021, OCR must consider Recognized Security Practices in place enterprise-wide for the previous 12 months as a mitigating factor — reducing penalties, narrowing scope, and shortening corrective action plan terms. It is a statutory discount that costs nothing but disciplined recordkeeping, and almost no small organization has the twelve months of documentation to claim it.

04

A policy library that reflects how you actually operate

Written, maintained, versioned, healthcare-specific. A policy that describes a workflow nobody follows is worse than no policy, because it documents the deviation.

05

An annual tabletop with minutes

An incident response plan that exists only as a stale Word document is the most common finding after the risk analysis. The tabletop produces the minutes, the after-action items, and the 60-day notification workflow you will need under time pressure.

06

OCR and payer response support

When a data request, a questionnaire, or an investigation arrives, we assemble the response. We have supported four to date. Zero penalties have been assessed against a Chartline client.

The evidence file

This is the deliverable.

A maintained, audit-ready package with a date on every artifact. Reviewed quarterly, formatted for an OCR data request, and assembled before anybody asks for it rather than after.

In our OCR engagement the request covered eleven document categories. All eleven already existed as dated artifacts. Nothing was produced after the request arrived, which matters more than it sounds: an investigator reading a risk analysis dated two weeks after the data request understands exactly what happened.

Read that engagement
Evidence file

Client name redactedOrthopaedics · 4 locations

Current
  • Risk analysis §164.308(a)(1)(ii)(A) 14 May 2026
  • Risk management plan §164.308(a)(1)(ii)(B) 14 May 2026
  • Asset and ePHI-flow inventory §164.310(d)(2)(iii) 01 Jul 2026
  • Encryption status attestation §164.312(a)(2)(iv) 30 Jun 2026
  • MFA coverage report §164.312(d) 19 Jul 2026
  • Workforce training records §164.308(a)(5) 30 Jun 2026
  • Business associate register §164.308(b)(1) 02 Apr 2026
  • Access review and terminations §164.308(a)(3)(ii)(C) 01 Jul 2026
  • Backup restore test results §164.308(a)(7)(ii)(D) 01 Jul 2026
  • Incident response tabletop minutes §164.308(a)(6)(ii) 11 Mar 2026
  • Vulnerability scan and remediation history §164.308(a)(1)(ii)(B) 20 Jul 2026
  • Recognized Security Practices attestation HITECH §13412 12 mo rolling
Reviewed quarterly. Delivered in OCR data-request format. Illustrative. Client identifiers redacted.
Where it sits

Which tier includes this.

Our rates are published. If a service you need is only in a higher tier, this page says so rather than making you find out in a proposal.

Chartline Core  $135 / user / month Not included
Chartline Secure  $189 / user / month Not included
Chartline Compliant  $255 / user / month Included
Next step

See where you actually stand.

Fifteen questions, each mapped to a Security Rule citation. You get a scored result naming the specific §164 requirement behind every gap. No call required to see it.

Under attack right now? (615) 555-0119

Our incident line is answered 24/7/365 by a security engineer, not a queue. Clients and non-clients both. If you are mid-incident, call before you email.