Who we serve

Healthcare runs on records nobody governs.

A clinic or practice carries the same obligations as a health system, on a fraction of the staff and with no one whose job is to hold technology, data, and risk together. The Business Architect seat is that job: one accountable seat on your leadership team, held by a firm, starting from what the organization has to be able to do and working back to the systems.

Where it actually goes wrong

The failures are never inside one system.

Every one of these crosses at least two domains, which is exactly why no single vendor is watching it. Your IT company is not wrong to ignore them. They are not its job.

The record follows the patient. The systems do not.

Scheduling, the record, billing, and whatever the referral partner uses each hold a version of the same person. Nobody owns the definition of a patient across all four, so reconciliation happens by hand, on someone's memory.

An AI feature arrives switched on

A vendor enables ambient documentation or a summarization tool inside software you already pay for. That is a clinical decision, a data exposure decision, and a policy decision at the same moment, and none of them were on an agenda.

The questionnaire arrives before the posture does

A cyber-insurance renewal asks yes-or-no questions about controls you have never inventoried. The IT provider answers about its own work. The organization signs.

Continuity lives in one person

One person knows how the interface works, which vendor to call, and where the credentials are. That is a governance gap wearing the costume of a reliable employee.

The rule that has not landed yet

Proposed, not in force. That is the useful part.

Still proposed, not final. HHS Office for Civil Rights published a notice of proposed rulemaking in the Federal Register on 6 January 2025. The comment period closed on 7 March 2025. No final rule has been issued, and the existing Security Rule remains the one in force.

What it would require

  • Encryption of electronic protected health information at rest and in transit, with limited exceptions
  • Multi-factor authentication, with limited exceptions
  • A maintained asset inventory and network map
  • Regular testing, including vulnerability scanning and penetration testing
  • Written incident response and contingency plans that are actually exercised

Why it matters before it lands

If a final rule is published, it would take effect roughly 60 days later, with a 180-day compliance window after that. That is the whole runway, and it starts on someone else's schedule.

Knowing today which of these you would already satisfy costs an afternoon. Finding out inside a 180-day window, while also running the practice, costs considerably more. The same inventory answers your cyber-insurance questionnaire, which is not waiting for a rule at all.

Source: HHS, HIPAA Security Rule NPRM fact sheet and the Federal Register notice.

How the seat works here

One seat. A firm behind it.

The seat holds the decisions. Your existing providers keep doing the work, and the seat holds them to it. Behind the person in your leadership meeting sits the firm, with people who do the data work, the risk work, and the growth work daily.

What it holds

  • Keeps a current, ranked risk register in plain language, mapped to what an incident would actually cost
  • Holds the IT provider and every other vendor to their contracts, and reads the invoices
  • Owns the AI question: an honest use-case list including the uses to skip, and a policy leadership can approve
  • Tracks the regulatory position rather than assuming it, and says what would have to change if a proposed rule lands
  • Reports to leadership in business language, on a quarterly rhythm

What it does not

  • No clinical advice, and no opinion on care decisions
  • No help desk or device support: your IT provider keeps that and we hold them to it
  • No access to patient records; we review systems and controls, not charts
  • No builds: remediation is scoped separately and you choose who does it
Fair questions

What healthcare leaders ask first.

Do you need access to our patient records?

No. We review systems, controls, contracts, and who can reach what. We do not review charts, and we do not need to. Nearly everything that determines your exposure is visible in configuration and process rather than in clinical data.

We already have an IT company that knows healthcare. Why this as well?

Keep them. Running the systems and governing them are different jobs, and the second one is the one nobody is doing. We select and oversee providers, read their invoices, and hold them to the contract. Your provider stays exactly where it is.

Are the HIPAA Security Rule changes in force yet?

No. The proposed rule was published in the Federal Register in January 2025 and the comment period closed that March. No final rule has been issued and the existing Security Rule is still the one in force. What is worth doing now is knowing which of the proposed requirements you would already meet, because the compliance window after a final rule is short and it starts without asking you.

How small is too small for this?

If a wrong decision would be genuinely expensive and no one on staff has the time or standing to hold technology, data, and risk together, the seat fits. If you are smaller than that, we will say so and point you at a fixed-scope project instead.

Find out what you would already pass.

An honest read on where your controls, contracts and records actually stand, and whether an assessment is worth your money. Sometimes it is not.

15 MINNO PREPNO CHART ACCESS
Book the call