For healthcare practices
An assessment your compliance officer can read.
Tidebreak performs a practitioner-grade assessment of your IT environment, mapped to the security framework your auditors and carriers already recognize and to the HIPAA Security Rule requirements your compliance officer already tracks.
CIS CONTROLS v8.1.2 × HIPAA SECURITY RULE
What the rule actually asks for
The HIPAA Security Rule's administrative, physical, and technical safeguards at 45 CFR §§164.308, 164.310, and 164.312 describe *what* must be in place, not *how* to verify that it is. OCR's 2024 NPRM is narrowing the "addressable" latitude on several specifications, and state AGs are increasingly citing Security Rule deficiencies as unfair practice acts. Your compliance officer tracks all of this. What she does not always have is a practitioner who can walk the environment, test the controls against CIS Safeguards, and hand her documentation a surveyor, a carrier, or OCR will recognize. If that role is you at your practice, this gives you the documentation you do not currently have.
Why the Security Rule rewards evidence
The Security Rule's structure rewards evidence and punishes assumption. The §164.308(a)(1) risk analysis is the keystone administrative safeguard, and OCR enforcement actions return to it again and again: not because practices fail to claim they have one, but because the analysis is stale, narrow, or never reconciled against the environment as it actually runs. The technical safeguards at §164.312 (access control, audit controls, integrity, transmission security) read as outcomes the practice must achieve, leaving the practice to demonstrate how. A practitioner reading against CIS Controls v8.1.2 can show that an access control is not just configured but reviewed, that audit logging is not just enabled but examined, that the encryption a vendor reports is the encryption actually in force. That gap between the represented state and the operating state is where breach risk concentrates, and it is the gap a configuration screen cannot close on its own.
The addressable-versus-required distinction is narrowing under the 2024 NPRM, and practices that have leaned on addressable latitude for encryption at rest, multifactor authentication on remote access to systems holding electronic protected health information, or a defined risk-analysis cadence will find that latitude removed when the rule finalizes. A practice does not need to wait for the final rule to know where it stands. An independent reading now, mapped to the specifications the rule already names, tells the compliance officer which of those specifications rest on latitude that is about to disappear, and gives her the documentation to plan the work before it becomes a deadline.
What the compliance officer can defend
In practice, the assessment gives the compliance officer a reading she can defend in the rooms where defensibility is tested. Each finding carries its evidence reference, the CIS Controls v8.1.2 safeguard it implicates, and the HIPAA requirement it touches, so the Full Assessment Report can move from her desk to the IT provider's remediation queue without a translation layer in between. We test a risk-based sample of the controls most likely to fail under Security Rule pressure, we document the sampling logic, and we reconcile what the environment shows against what vendors and the IT provider report. The line we do not cross is the one the rule draws: the covered entity owns the formal risk analysis, and the practice's counsel makes the compliance calls. Our work is the independent input those decisions rest on, not a substitute for them.
Worked example
Representative finding
BAA with unmonitored vendor standing access
CIS Safeguard 15.1 Inventory of Service Providers · HIPAA §164.308(a)(4) Information Access Management
The practice's imaging vendor held a signed BAA and standing remote access. No periodic access review had been performed since onboarding four years prior. The vendor's subcontractor disclosures had changed twice without BAA amendment. No log review identified after-hours administrative sessions from the vendor subnet.
This is one of the most common findings in healthcare IT assessments. The BAA is the legal instrument; the access practice is the operational one; the gap between them is where breach risk lives. A surveyor will ask for the access review log before they ask for the BAA.
What Tidebreak does, and what it does not
A Tidebreak assessment delivers an Executive Report your compliance officer can forward to your carrier or regulator and a Full Assessment Report your IT provider can remediate against. The methodology is documented procedurally and maps directly to the Security Rule specifications you already track. See the methodology
Tidebreak is independent. Tidebreak does not perform the §164.308(a)(1) formal risk analysis that the covered entity is obligated to complete, is not a HITRUST CSF assessor, and is not your IT provider. We perform a practitioner-grade assessment of your IT environment. Our findings inform your risk analysis; they do not replace it.
Why this matters
For a healthcare practice, an IT gap is a patient-trust problem and a regulatory-posture problem at the same time. OCR investigations almost always open with a request for the current risk analysis and the evidence behind it, and a practice that can produce an independent, dated, framework-mapped reading is in a categorically different position from one that produces a binder no one has opened since onboarding. A cyber carrier underwriting a practice that handles electronic protected health information prices the absence of evidence as risk; the practice that can show its work negotiates from a stronger seat. A breach that traces back to a vendor whose access was never reviewed becomes a notification event, a state AG inquiry, and a line in the practice's reputation that does not fade quickly. The compliance officer carries that exposure personally, and the practice's leadership carries it institutionally. An independent assessment is how a practice turns "we believe our MSP has this covered" into documentation a surveyor, a carrier, or OCR will actually accept.
Who runs the assessment
We assess MSPs. I used to run one.
Jeff White has spent twenty-five years in the IT business. Enterprise infrastructure architecture. Eight years at Microsoft Consulting Services. Most recently, VP of Engineering Services at a mid-market MSP, where he built out the service delivery organization and a 24/7 security operations center from the ground up.
Now he works for you, not your provider. Tidebreak exists to give firms like yours a read most don't have a way to get: an independent look at whether the IT you pay for is actually the IT you're getting.
VP Engineering Services, MSP · 8 years Microsoft Consulting Services · Azure Solutions Architect Expert · Assessments mapped to CIS Controls v8.1.2 and NIST CSF 2.0