Compliance

Compliance you can show your work on.

How SaberGuard approaches HIPAA for medical, dental, and behavioral health practices, covered entities, and business associates: a signed risk analysis, evidence behind every finding, and monitoring that keeps it true.

SaberGuard assesses and advises; it does not warrant compliance.

01

Assess and advise, honestly

SaberGuard assesses and advises. It does not certify compliance, because no one can, and it does not promise an audit outcome. You get a defensible analysis, a plan, and a person who answers the phone.

02

Evidence over checklists

A questionnaire score is an opinion. A finding that names the configuration, the time it was observed, and the rule that fired is evidence. Every SaberGuard finding is built the second way.

03

Continuous, not annual

Compliance drifts the week after the report is signed. Monitoring keeps the baseline true, so you know when something changes instead of a year later.


What we cover

Seven ways we help healthcare organizations stay defensible

Each area says what we do and how it helps, with the Security Rule paragraph it supports where one applies.

Regulatory map

The requirements, in plain language

Every citation on this site is one of these, verified against eCFR and mass.gov. Findings in a SaberGuard report cite the specific paragraph.

  • HIPAA Security Rule

    45 CFR 164.308(a)(1)(ii)(A)

    Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. This is the risk analysis.

    Applies to
    Every covered entity and business associate, regardless of size

  • HIPAA Security Rule

    45 CFR 164.308(a)(1)(ii)(B)

    Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. This is risk management: the ongoing part.

    Applies to
    Every covered entity and business associate

  • HIPAA Security Rule

    45 CFR 164.308, 164.310, 164.312

    The administrative, physical, and technical safeguards a risk analysis is measured against. Findings in a SaberGuard report cite the specific paragraph.

    Applies to
    Every covered entity and business associate

  • Massachusetts data security regulation

    201 CMR 17.03

    Every person that owns or licenses personal information about a Massachusetts resident must develop, implement, and maintain a comprehensive written information security program (WISP).

    Applies to
    Any business holding a resident's name plus SSN, driver's license, or financial account number, whether or not HIPAA applies

What we don't do

The lines we won't cross, because crossing them would make the work worthless.

  • We do not certify compliance. There is no such thing as “HIPAA certified,” and anyone selling it is selling a sticker.
  • We do not guarantee an audit outcome. We give you a defensible analysis and the evidence behind it.
  • We never collect patient information through this website, and Ward never reads it. The contact form says so, and the access Ward is granted cannot reach it.
  • We do not replace legal counsel. Breach notification decisions belong with qualified healthcare privacy counsel; we supply the technical findings and timeline.
Questions

Compliance, answered plainly

More questions on the FAQ page

Know exactly where your practice stands.

A thirty-minute scoping call covers what the risk analysis includes for a practice your size, what the Massachusetts WISP adds, and what monitoring would look like afterward.

SaberGuard assesses and advises; it does not warrant compliance.