We'll have a separate page on the site explaining this next week, but we break compliance management down into 5 main areas:
- Risk Assessment
- Policies and Procedures
- Training
- Ops
- Incident Response
Conceptually, they form a cycle. Each area feeds the next, with ops/incident response feeding back into risk analysis.
We have a suite of tools to help with each stage of the cycle. Each step requires a different mix of:
1. Automation
2. Manual work on our part, and
3. Manual work by our customers
Our overall goal is to drastically reduce #3 while helping our customers run amazing compliance programs that reduce risk and give everyone involved (devs, management, their customers, federal regulators) insight into what is going on inside their organization.
One interesting feature to add at some point would be helping companies incorporate their BAA into their user agreement (this is how Practice Fusion does it - http://www.practicefusion.com/pages/user-agreement.html).
Preparing training materials is a good example. Each of our customers get three types of training: basic HIPAA privacy and security training for everyone; developer training, specific to their stack; and security officer training. We customize that training. We may modularize it later, but only if we can maintain the quality and experience.
We spend as much time with each customer as they want, but we don't bill for support and we don't bill for consulting. At first it seems higher-priced than some options, but there are no hidden costs.