FAQ

Common questions. Straight answers.

Everything independent healthcare providers ask about HIPAA compliance, the Patient Protect platform, pricing, and how to get started.

About Patient Protect

What is Patient Protect?

Patient Protect is a security-first HIPAA compliance platform built for independent healthcare providers. It provides automated security risk assessments, real-time threat monitoring, policy management, staff training, and secure communication tools — without enterprise pricing or complexity.

Who is Patient Protect designed for?

Independent healthcare providers including dental practices, medical offices, behavioral health and therapy practices, chiropractic offices, physical therapy centers, optometry practices, and dermatology clinics. It is not designed for large hospital systems or enterprise organizations with dedicated IT departments.

Is Patient Protect suitable for solo practices?

Yes. The platform is specifically designed for independent healthcare practices — dental offices, medical practices, behavioral health clinics, and specialty providers — that carry enterprise-grade HIPAA obligations without enterprise-grade resources.

How long does it take to get started with Patient Protect?

Start with the free risk assessment (5 minutes, no login). If you move to the platform, onboarding takes less than a day — no consultants, no implementation projects, no contracts. You can cancel anytime.

How quickly can my practice get set up?

Most practices complete initial setup in under two hours. The SRA wizard guides you through every required assessment step, policies auto-generate from your answers, and BAA templates are ready to send on day one. No consultants, no implementation projects.

Do small practices need to be HIPAA compliant?

Yes — every healthcare provider that transmits health information electronically is a covered entity under HIPAA, regardless of practice size. A solo dentist has the same legal obligations as a 500-bed hospital.

Does Patient Protect replace my IT company?

No. Patient Protect handles the compliance layer — risk assessments, policy management, training documentation, BAA tracking, and audit evidence. Your IT provider handles infrastructure (firewalls, networking, hardware). The platform complements managed IT services; it does not duplicate them.

Pricing & Plans

How much does Patient Protect cost?

Patient Protect offers two plans: Core at $39/month for essential SaaS compliance, and Pro at $99/month for complete operational visibility including advanced monitoring, training, and secure messaging. Both include a 14-day free trial.

How much does HIPAA compliance software cost?

Pricing varies widely across vendors — some charge flat rates, some per employee, some require annual contracts. Patient Protect publishes pricing directly: $39/month for Core, $99/month for Pro.

What is the difference between HIPAA compliance software and doing it manually?

Manual compliance relies on spreadsheets, Word documents, and annual consultant visits. HIPAA compliance software like Patient Protect automates risk assessments, tracks training completion, monitors BAA status, and documents everything continuously.

How much does HIPAA compliance cost?

Total HIPAA compliance costs depend on your approach. Hiring a consultant runs $5,000–$25,000 per year. Patient Protect delivers continuous compliance starting at $39/month.

Are there hidden fees or per-provider charges?

No. Patient Protect pricing is flat-rate: $39/month for Core, $99/month for Pro.

Platform & Features

What features does Patient Protect include?

Twenty integrated modules across five layers — System, Defense, Operations, Network, and Intelligence. Core includes 14 modules at $39/month, Pro unlocks all 20 with unlimited AI and expanded training at $99/month.

Does Patient Protect help with the HIPAA Security Risk Assessment?

Yes. Patient Protect includes an automated Security Risk Assessment (SRA) tool mapped to the NIST Cybersecurity Framework.

What free HIPAA tools does Patient Protect offer?

Several free tools with no login required: a real-time HIPAA Breach Dashboard, an abbreviated HIPAA Risk Assessment, a comprehensive HIPAA Compliance Roadmap and Checklist, an ePHI Flow Risk Mapper, and a HIPAA Risk Calculator.

Is Patient Protect's AI assistant HIPAA compliant?

Yes. It runs entirely on-premises — zero PHI exposure by architecture, not by policy.

How does Patient Protect handle BAA management?

Full lifecycle: create, send for e-signature, track status, renewal alerts.

What security standards does Patient Protect follow?

Built against OWASP Top 10 and NIST CSF. AES-256-GCM encryption, TLS 1.3, browser fingerprinting, AppSensor on every endpoint.

What is a HIPAA risk assessment?

It is a mandatory evaluation of potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) in your practice. OCR requires it annually.

Does Patient Protect integrate with my EHR?

Patient Protect operates alongside your EHR without requiring direct integration.

HIPAA Compliance

How do I know if my practice is actually HIPAA compliant?

Most practices assume they are compliant due to policies on paper. Actual compliance requires continuous risk assessments, documented training, and breach detection capabilities.

Is HIPAA compliance a one-time project or an ongoing requirement?

Ongoing. HIPAA requires continuous assessments and active monitoring.

What happens if my practice is breached and I am not compliant?

The average healthcare data breach costs $9.8 million. Penalties range from $100 to $50,000 per violation.

Do I need a Business Associate Agreement with every vendor?

Yes. Every vendor that handles ePHI must have a signed BAA.

Do I need to hire a consultant to become compliant?

Not necessarily. Patient Protect automates much of the work done by consultants.

What is the HIPAA breach notification requirement?

Covered entities must notify affected individuals within 60 days of discovering a breach.

What happens if you violate HIPAA?

Violations carry civil penalties from $100 to $50,000 per violation. Ignorance is not a defense.

Can you be fined for accidental HIPAA violations?

Yes. Penalties include violations where the covered entity did not know and could not have reasonably known about the breach.

What is the difference between HIPAA Privacy and Security Rules?

The Privacy Rule governs how PHI can be used and disclosed. The Security Rule applies specifically to electronic PHI and mandates safeguards.

Messaging & Communication

Can I text patients from my personal phone?

No. SMS and other non-compliant channels are not HIPAA-compliant for sending ePHI.

Is texting patients a HIPAA violation?

Yes, if the text contains PHI and is sent via standard text messaging.

Can I use WhatsApp to communicate with patients?

No. WhatsApp does not meet HIPAA compliance requirements.

What makes messaging HIPAA compliant?

Requires end-to-end encryption, user authentication, role-based access, audit logging, and a signed BAA.

What is a Business Associate Agreement?

A legally binding contract required under HIPAA between a covered entity and any third party that handles PHI.

Can I use regular email to send patient information?

Standard email is not HIPAA compliant. Use secure messaging instead.

Breach Data & Research

What is the average cost of a healthcare data breach in 2024?

The average cost was $9.8 million.

How much is stolen medical data worth on the dark web?

A full-package PHI record commands a median dark-market value of $280–$310 per record.

How long does it take healthcare organizations to detect a data breach?

Healthcare organizations take an average of 93 days.

What percentage of Americans had their health data exposed in 2024?

Over 276 million Americans had their protected health information exposed.

How does AI affect healthcare cybersecurity risk?

AI has increased voice-cloning attacks and improved phishing yield.

How often do independent practices get audited by OCR?

OCR conducts both complaint-driven investigations and random audits.

What are the most common causes of healthcare data breaches?

The top three causes are hacking/IT incidents, unauthorized access by internal actors, and theft or loss of unencrypted devices.

Resources & Downloads

Are these resources really free?

Yes. Every resource is free to download.

Who created these guides?

Resources are authored by the Patient Protect team — certified HIPAA consultants and experts.

Do I need an account to download?

No. Just provide your name and email once, and resources unlock immediately.

How often do you need HIPAA training?

HIPAA requires initial training upon hiring and periodic annual refreshers.

Are Patient Protect's training certificates accepted by auditors?

Yes. Completion certificates are generated and stored for the mandatory 6-year retention period.