IT Compliance & Readiness

A team reviewing technology controls and readiness evidence.

Protect information. Support your people. Show the work.

Compliance is part of caring for your patients and protecting your business. ETS helps turn privacy and security responsibilities into clear policies, practical safeguards, and records your team can maintain—with Compliance Scorecard supporting the work.

HIPAA is about people—not just paperwork

Patients share information they expect you to protect. A misplaced record, an account left open after an employee leaves, or an unavailable system can affect privacy, trust, and everyday care.

Protect patient privacy

The HIPAA Privacy Rule addresses how protected health information is used and shared, and individuals’ rights over that information. Protection extends beyond electronic records to paper and spoken information.

Keep electronic information protected

The Security Rule covers electronic protected health information. It calls for safeguards involving people, workplaces, and technology—not simply buying security software.

Be ready when something goes wrong

The Breach Notification Rule requires notifications after a breach of unsecured protected health information. A clear response process helps the right people assess events and meet applicable duties.

HIPAA applies to covered entities, including health plans, healthcare clearinghouses, and healthcare providers that conduct certain standard electronic transactions. It also imposes responsibilities on business associates handling protected health information for regulated organizations. Size alone does not decide whether the rules apply.

Start by confirming your organization’s role and obligations with qualified advisers. See HHS guidance on who HIPAA covers, privacy, security, and breach notification.

Make good practices part of the working day

A written policy only helps when it reflects what people actually do. ETS can help connect your compliance priorities to the systems and routines your team relies on.

  • Understand the risks: identify where electronic patient information is stored, received, used, and shared. Review weaknesses and track the work needed to address them.
  • Manage access: give staff access appropriate to their responsibilities, review it when roles change, and remove access when it is no longer needed.
  • Prepare people: establish usable procedures, provide relevant training, and make it clear who handles privacy or security concerns.
  • Review vendors: identify services handling protected information and work with your advisers on appropriate business associate agreements and responsibilities.
  • Prepare for disruption: review backup, recovery, and incident-response arrangements, then practice the steps your team will need.
  • Keep useful records: retain policies, approvals, reviews, and corrective actions so your organization can explain both its decisions and its follow-through.

A HIPAA security risk analysis is broader than a device scan. It considers potential risks to electronic protected health information across the organization, including how people and processes handle it. Findings should inform risk management and be revisited as circumstances change.

HHS guidance on risk analysis. The right safeguards depend on your environment and applicable requirements; this page is an introduction, not a complete HIPAA checklist.

Compliance Scorecard: bring the work into one place

ETS uses Compliance Scorecard to help organize policies, assessments, and ongoing governance. It gives your team a clearer way to review what is documented, what needs attention, and what happens next.

Policies people can find and follow

Manage documents in a central location, review revisions, obtain approvals, and track acknowledgments. Keep the current version easier to find when staff need guidance.

A clearer view of risk and gaps

Use assessments and risk-matrix tools to discuss weaknesses and prioritize improvements. The platform lists HIPAA Privacy, HIPAA Security, and HIPAA Security Risk Assessment among its supported frameworks.

Shared oversight and follow-through

Organize asset governance, risk records, and action milestones. Bring documentation and progress into review conversations so management and ETS can agree on the next steps.

Available modules, templates, and integrations depend on your subscription and agreed service scope. A score or completed template is not proof of compliance; people must validate the information and operate the safeguards. Explore Compliance Scorecard and its supported frameworks.

Start with what actually applies

Not every organization has the same obligations. We look at your information, contracts, systems, customers, and risks before proposing the work.

Requirements and scope

Map the frameworks, contracts, insurance expectations, and customer commitments that may shape technology controls and evidence.

Risk and gap reviews

Identify where access, endpoints, backups, networks, vendors, policies, or response practices need attention and prioritize the work by impact.

Vendor and data review

Document who processes important information, what access they have, which agreements matter, and how support or incidents are handled.

Build evidence people can maintain

ETS helps connect expectations to repeatable technical and operational habits, so preparation does not become a last-minute search for documents.

Policies and procedures

Translate technology decisions into usable acceptable-use, access, backup, change, incident, and review procedures.

Access and activity evidence

Improve account lifecycle, permissions, logging, review cadence, and documentation so the organization can show what happened and who owns it.

Continuity and incident exercises

Test recovery and response assumptions, record outcomes, and turn gaps into tracked improvements rather than last-minute evidence gathering.

Connect this work with cybersecurity protection and backup and disaster recovery planning. Technology and governance should support each other.

Common questions about compliance

Clear expectations before you choose a platform or start a project.

Is HIPAA only a concern for large hospitals?

No. Small practices and organizations serving covered entities can have HIPAA responsibilities. Your role, activities, and handling of protected information matter—not simply your headcount.

Does buying Compliance Scorecard make us compliant?

No. It supports organization and oversight. Your business still needs appropriate policies, implemented safeguards, trained people, accurate records, and ongoing review.

Can we use policies and assessments we already have?

Yes—those are useful starting points for a review. ETS can help identify what still fits, where documentation and actual practices differ, and which gaps need attention. Existing documents should be reviewed, not accepted without checking.

Do you provide legal advice or guarantee an audit result?

No. ETS provides technical and operational readiness support. Your organization’s designated leaders and qualified legal or compliance advisers remain responsible for confirming obligations. No platform, template, or service guarantees compliance or a particular assessment result.

Make compliance part of the way work runs

Tell us about your organization, the information you handle, and the areas where you need support. We can help identify a practical starting point and an agreed scope of work.

Do not send patient information, passwords, or confidential records through the contact form.

Discuss your compliance priorities

UPCOMING OFFERING · STILL IN DEVELOPMENT

PolicyWizard: a more organized policy lifecycle

PolicyWizard is being developed to help organizations draft or import policies, route them for approval, track employee acknowledgments, and maintain version history and audit evidence in one workspace. The aim is clearer ownership and less manual document chasing as policies move from creation to everyday use.

PolicyWizard is still in development and is not generally available. Features and availability may change; it is not a substitute for legal review or a guarantee of compliance.

Explore the PolicyWizard preview