Monday to Friday, 8am to 6pm CT832-907-5594
ServicesHIPAA Security Official

HIPAA security official

Your security official has a program behind them.

HIPAA requires your practice to identify a security official and to keep a documented risk analysis. Naming the person is the easy part, so we support that person with the written risk assessment, the controls, and the evidence behind them. This is a plan, not a compliance guarantee.

Proof beneath: 45 CFR 164.308(a)(2); 45 CFR 164.308(a)(1)(ii)(A); OCR Risk Analysis Initiative.

What the HIPAA Security Rule requires a security official to do

The Security Rule requires the practice to identify the security official who is responsible for developing and implementing the required policies and procedures (45 CFR 164.308(a)(2)). It is a named person, not a department and not a vendor. Most small practices assign it to an owner-physician or the practice manager, and the gap is what that person has to work with.

The same rule requires a documented risk analysis. 45 CFR 164.308(a)(1)(ii)(A) calls for an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information. It is the foundation the rest of the program stands on, and the detail on what it covers is on the physician practices page.

The HHS Office for Civil Rights has made that document its enforcement focus. The OCR Risk Analysis Initiative targets the most common failing OCR sees, which is a practice that cannot produce a current, documented risk analysis. Your security official should be able to reach for the analysis and hand it over, with the work of keeping it current already assigned.

Arain Systems supports the security official your practice designates. It does not act as that official, and the practice remains responsible for compliance.

Five questions to ask any provider

Ask these five before you sign anything, including with us. Each one has a document or a control behind it, so a vague answer is itself the answer. Ours are below, mapped to the plan that includes each item.

Question 1

Do you produce the written policies and procedures the Security Rule requires?

Ask to see the documents, not a promise. The Security Rule makes the security official responsible for developing and implementing written policies and procedures, so a provider working underneath that person should be producing paper you can read. Tier 2 Comply includes a written risk assessment refreshed on a schedule, an incident response plan rehearsed with a tabletop, access reviews with sign-off you can show an auditor, and vendor and third-party risk reviews. If a provider cannot name the documents it writes and keeps current, it is selling monitoring, not a program.

Question 2

Do you support the security official our practice designates?

Yes, and the distinction matters. Arain Systems supports the security official your practice designates. It does not act as that official and does not take on your legal accountability, because the practice remains responsible for compliance. The support is specific: Tier 1 Manage includes plain-English reporting and a quarterly review, and Tier 2 Comply adds virtual CISO advisory, the annual report to ownership, and audit support. Your official gets the findings, the evidence, and reporting they can take to the owners.

Question 3

Is the risk analysis documented, and how often is it refreshed?

It must be documented, and once is not enough. 45 CFR 164.308(a)(1)(ii)(A) requires an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information. Tier 2 Comply includes a written risk assessment refreshed on a schedule. Tier 1 Manage adds vulnerability scanning with fixes tracked, so the analysis is fed by what is actually found on your network instead of a form filled in once and filed.

Question 4

What evidence do we get for an audit or a cyber-insurance application?

Evidence you can hand over, collected before anyone asks for it. Tier 2 Comply includes access reviews with sign-off you can show an auditor, log monitoring through a 24/7 SOC partner, independent penetration testing arranged annually, cyber-insurance readiness with an evidence pack, and audit support. Ask any provider what it gives you the week a carrier questionnaire or an investigation arrives. A dashboard login is not evidence.

Question 5

Are MFA, endpoint detection, encryption, email security, and backup included or extra?

All five are included, starting at Tier 1 Manage. That tier covers MFA with least-privilege roles and conditional access, endpoint protection (EDR) with always-on monitoring, disk and file encryption enforced, email security (SPF, DKIM, DMARC) with phishing filtering, and encrypted offsite backup with tested recovery. It also includes security awareness training with phishing tests. Ask any provider which of the five sit in the monthly price and which are quoted on top.

Does this apply to a small practice?

Yes. HIPAA has no small-practice exemption. The Security Rule applies to covered entities regardless of size, so a two-provider office carries the same requirement to identify a security official and keep a documented risk analysis as a hospital system does. Size changes the scale of the work, not the obligation. A small practice has fewer systems to assess and fewer people to train, which makes the job smaller, never optional.

In practice the small office is the one that needs the structure most. There is no compliance department, no security team, and the person holding the title is also running the schedule. That is why the support is built to carry the paperwork and the controls, and to leave your official with decisions instead of homework.

Works with the systems your practice already runs

Nothing clinical gets replaced. Your electronic health record, your practice management system, your email, and your imaging keep working the way they do today. We secure what they run on, we do not fight them.

The controls attach to the layer underneath: the accounts and identities that reach patient data, the workstations and devices in the operatories and the front office, the network and the backups, and the vendors with access. That is where the Security Rule questions actually get answered, and it is where a risk analysis finds its findings.

You keep ownership of your Microsoft tenant, your credentials, and your backups, with a documented runbook. You are never locked in, including to us.

What it costs

The program sits in Tier 2 Comply, from $103 per user per month. That tier carries the documentation and evidence side: the written risk assessment refreshed on a schedule, access reviews with sign-off you can show an auditor, the incident response plan rehearsed with a tabletop, vendor and third-party risk reviews, log monitoring through a 24/7 SOC partner, cyber-insurance readiness with an evidence pack, virtual CISO advisory with the annual report to ownership, and audit support.

Tiers are progressive, so Tier 2 also includes everything in the tiers below it. That is where MFA, endpoint protection, enforced encryption, email security, encrypted offsite backup with tested recovery, and staff training live.

Tier 3 Accelerate, from $124 per user per month, adds the AI side: an AI-use policy with staff guardrails, a list of vetted approved tools, and flagging when staff paste client data into AI tools. Practices adopting scribes or chat tools are the ones that need it.

Each tier includes unlimited in-scope support. Work outside your plan is quoted separately. Full pricing for every tier is on the plans page.

If your practice is regulated somewhere else

If you also run a business that answers to the FTC Safeguards Rule, the financial-side version of this page is Qualified Individual support.

Where we work

Arain Systems serves practices across the Houston metro, including Houston, Katy, Sugar Land, Pearland, Cypress, The Woodlands, Spring, Bellaire, Richmond, Missouri City. Most of this work is remote, because the documents, the reviews, and the controls do not need a visit. We come on-site when the office calls for it, which usually means the network, the servers, or a new location.

Practices in Houston, Katy, Sugar Land, The Woodlands, Bellaire, Richmond, Missouri City have a page of their own. The rest of the metro is covered on the service-area pages.

Scope note

Arain Systems provides a gap assessment and a remediation plan. This is not a certification or a guarantee of compliance. Content here is educational, not legal advice.

Get a free HIPAA gap report

We check where your practice stands against the Security Rule, starting with whether a security official is named and a current risk analysis exists, then give you written findings.

Get a free gap report

Written by Hammad Arain, founder of Arain Systems. CCNA, CompTIA Security+, Microsoft AZ-104. Updated June 2026. Educational, not legal advice.