On this page
Service Overview
Many businesses face security and privacy compliance requirements. Understanding the path to compliance can be difficult and a lack of clarity can lead to controls that are too expensive, overbearing, or on the opposite end of the spectrum, simply not adequate or reasonable. These gaps may cause minor inconveniences or significant damages and they may result in severe financial penalties, loss of public trust, and damage to corporate reputation.
This HIPAA Privacy Assessment will provide a comprehensive evaluation of the Client's compliance and a plan for effectively mitigating those gaps.
Objectives
The objectives of this initiative are as follows:
- Assess the need for, the timing of, and gaps to comply with the HIPAA Privacy Rule sections (§164.502 to §164.530).
- Review policies, processes, and procedures for regulatory compliance.
- Evaluate the organization's ability to operationalize regulatory requirements.
- Develop a preliminary set of findings, with actionable, reasonable recommendations to address any gaps identified.
Methodology
This HIPAA Privacy Assessment consists of the following phases:
- PLANNING
- Identify key resources required for the project and anticipated level of effort
- Develop a project plan and calendar, including agreement from the organization on project tasks and timeline
- Conduct a formal project kickoff meeting to gain an understanding of the current organizational structure that supports decision-making around privacy-related matters
- INFORMATION GATHERING
- Identify key areas for improvement relative to HIPAA Privacy Rule
- Meet with the Client to gain an understanding of current controls and procedures throughout the organization's systems subject to the HIPAA Privacy Rule, and understand:
- How the organization operates, where data is collected, and why
- Current privacy governance structure within the organization
- What policies, procedures, processes, and frameworks exist within the organization for storage, collection, protection, transfer, backup, and deletion of protected data
- When, and under what circumstances, is HIPAA data disclosed
- The documentation of the relevant process and controls
- Conduct interviews with key data and process owners to understand the organization's current data privacy controls and procedures
- ANALYSIS AND REPORTING
- Establish a baseline of HIPAA Privacy Rule
- Analyze information, gathered via documentation reviews and interviews, to validate that the organization's policies and procedures address the requirements of the HIPAA Privacy Rule
- Identify and prioritize gaps and optimization opportunities in processes, policies, procedures, and documentation
- Develop a written report outlining our observations, opportunities for improvement, and summaries of findings
- Develop recommendations for remediation of any gaps or non-compliance
- PRESENTATION - Presentation of findings to Client
Deliverables
DeepSeas will produce the following deliverables:
- KICKOFF MEETING - DeepSeas will host a kickoff meeting to conduct introductions and familiarize the Client with the initiative. This meeting will be no longer than sixty (60) minutes and it is intended to review the objectives, methodology, scope, and deliverables in the Statement of Work.
- SUMMARY FINDINGS - DeepSeas will deliver a report summarizing the findings, with mitigation recommendations related to the initiative.
Client Responsibilities
The client is responsible for the completion of the following tasks, in accordance with agreed-upon timelines established as part of the project plan.
- Client to assign a point of contact (POC) responsible for client coordination and logistics.
- The client is responsible for scheduling and coordination of internal client resources for all project work.
- The client is responsible for the approval and implementation of draft documents within their organization.

Back to Service Library