The thing practices get penalized for is a documentation failure.
The single most-cited finding in HIPAA enforcement is not a missing firewall. It is the absence of an accurate and thorough risk analysis under §164.308(a)(1)(ii)(A), and increasingly the absence of a documented risk management plan under §164.308(a)(1)(ii)(B). Documentation is exactly what a generalist IT company does not produce, because it is not part of the managed services product they sell.
Included in: Included in Chartline Compliant. Available standalone as a risk analysis or vCISO retainer.
Six things, described plainly.
No capability matrix and no maturity model. This is what we do, why it matters in a clinical environment, and where the number comes from.
A real risk analysis, not a questionnaire
Enterprise-wide, every location, every system, every ePHI repository, conducted against NIST SP 800-66 Rev. 2 and mapped to Security Rule citations. A completed HHS SRA Tool questionnaire has repeatedly failed to satisfy investigators, and OCR settlements say so explicitly.
A dated risk management plan with owners
Prioritized remediation, assigned to a person, with evidence of completion. OCR Director Paula Stannard has confirmed the Risk Analysis Initiative expands in 2026 to cover risk management, not just risk analysis. A completed analysis with no evidenced remediation is now its own exposure.
Recognized Security Practices, documented for twelve rolling months
Under the HITECH amendment signed January 5, 2021, OCR must consider Recognized Security Practices in place enterprise-wide for the previous 12 months as a mitigating factor — reducing penalties, narrowing scope, and shortening corrective action plan terms. It is a statutory discount that costs nothing but disciplined recordkeeping, and almost no small organization has the twelve months of documentation to claim it.
A policy library that reflects how you actually operate
Written, maintained, versioned, healthcare-specific. A policy that describes a workflow nobody follows is worse than no policy, because it documents the deviation.
An annual tabletop with minutes
An incident response plan that exists only as a stale Word document is the most common finding after the risk analysis. The tabletop produces the minutes, the after-action items, and the 60-day notification workflow you will need under time pressure.
OCR and payer response support
When a data request, a questionnaire, or an investigation arrives, we assemble the response. We have supported four to date. Zero penalties have been assessed against a Chartline client.
This is the deliverable.
A maintained, audit-ready package with a date on every artifact. Reviewed quarterly, formatted for an OCR data request, and assembled before anybody asks for it rather than after.
In our OCR engagement the request covered eleven document categories. All eleven already existed as dated artifacts. Nothing was produced after the request arrived, which matters more than it sounds: an investigator reading a risk analysis dated two weeks after the data request understands exactly what happened.
Read that engagementClient name redactedOrthopaedics · 4 locations
- Risk analysis §164.308(a)(1)(ii)(A) 14 May 2026
- Risk management plan §164.308(a)(1)(ii)(B) 14 May 2026
- Asset and ePHI-flow inventory §164.310(d)(2)(iii) 01 Jul 2026
- Encryption status attestation §164.312(a)(2)(iv) 30 Jun 2026
- MFA coverage report §164.312(d) 19 Jul 2026
- Workforce training records §164.308(a)(5) 30 Jun 2026
- Business associate register §164.308(b)(1) 02 Apr 2026
- Access review and terminations §164.308(a)(3)(ii)(C) 01 Jul 2026
- Backup restore test results §164.308(a)(7)(ii)(D) 01 Jul 2026
- Incident response tabletop minutes §164.308(a)(6)(ii) 11 Mar 2026
- Vulnerability scan and remediation history §164.308(a)(1)(ii)(B) 20 Jul 2026
- Recognized Security Practices attestation HITECH §13412 12 mo rolling
Which tier includes this.
Our rates are published. If a service you need is only in a higher tier, this page says so rather than making you find out in a proposal.
The rest of what we run.
Managed IT and help desk
The day-to-day. Tickets answered by a named pod, not a rotating queue.
Cybersecurity and 24/7 detection and response
24/7 monitored detection with contractual authority to contain, not just to alert.
vCISO
A named security officer with a monthly working session and a quarterly board report.