US privacy operations: the risk analysis, BAAs, the breach clock and workforce training.
Offered in: United States only.HIPAA as running registers rather than a binder. The security risk analysis is kept here: each risk by administrative, physical or technical safeguard, with its likelihood, impact, owner and due date, closed only as mitigated (what was done) or accepted (why the practice lives with it), and the date of the last full analysis with a flag when a year has passed. So is the business associate register: every vendor that handles PHI, what it handles, when its BAA was signed and is reviewed or ends — a vendor with no signed BAA shows as a gap — and how the agreement ended. The breach clocks are IncidentIQ’s: a US practice’s data breach opens the notice to the people affected and the report to HHS, each on a 60-day default with its source named. Access requests run in the Security Centre on HIPAA’s 30 days with one 30-day extension. Workforce training is read from the TrainingMatrix course the practice names as its HIPAA training, against every active member of staff.
What it does not do, by design. A listing with only benefits is an advertisement.
Read out of the code, not the brochure: each app below is here because one service queries the other’s tables. Install either side and the hand-over is already wired.
Tell us what you run and we will show you this app inside a practice shaped like yours — or answer the question the page above did not.