Colington Consulting

Colington Consulting Helping Organizations Achieve HIPAA Compliance™ All assessments will include an action plan to prevent unauthorized access, tampering and theft.

HIPAA RISK ASSESSMENTS
The risk analysis is the first step to identify vulnerabilities and risks; determine the potential impact and provide a gap analysis. Our assessment is formatted to cover all the addressable and required specifications in the Code of Federal Regulations for the HIPAA Security Rule. HIPAA RISK MANAGEMENT PLAN
We develop and help your practice or business implement a Risk Mana

gement Plan. Think of your risk plan as your overall policies and procedures manual on how to make decisions to address security risk and vulnerabilities for HIPAA Security Rule compliance. Your completed plan will address all the required topics to include administrative, technical, and physical safeguards. Regardless of practice or business size, a Risk Management Plan is required. This may be one of the first documents OCR will request if there is a breach of electronic patient records or if a compliance audit is conducted. HIPAA PRIVACY POLICIES AND PROCEDURES MANUAL
The HIPAA Privacy Rule establishes national standards to protect individuals’ medical records and other personal health information and applies to healthcare providers that conduct certain healthcare related transactions. The Rule requires appropriate safeguards to protect the privacy of personal health information, and sets limits and conditions on the uses and disclosures that may be made of such information without authorization. The best way to ensure your staff is familiar with the appropriate safeguards is by having a HIPAA Privacy Policies and Procedures Manual. We develop and help your practice or business implement a Privacy Manual. HIPAA SECURITY AWARENESS & PRIVACY TRAINING
We can develop security awareness & privacy training specifically for your practice or business office environment. We offer web based HIPAA training available through our website. HIPAA DOCUMENTATION REVIEW
If your practice or business already has documentation in place, we can conduct a review of those documents to ensure you are meeting the current HIPAA Security Rule and HITECH compliance requirements for patient electronic health records. This cost effective review can determine if all high risk areas for compliance are being properly addressed.

"Our IT company handles our HIPAA compliance." It's one of the most common things we hear from healthcare practices, and...
08/25/2026

"Our IT company handles our HIPAA compliance." It's one of the most common things we hear from healthcare practices, and one of the most understandable, since a good managed service provider really does handle a lot: firewalls, patching, backups, monitoring.

Here's the catch. HIPAA compliance isn't only a technical question. It also requires your practice's own risk analysis, written policies, workforce training, and a signed business associate agreement with every vendor touching patient data, including your IT partner. None of that transfers from your MSP, no matter how good they are.

A recent survey found that 98% of IT leaders and practice managers believed their email was encrypted by default, and over 80% were confident in their HIPAA compliance posture. That gap between confidence and reality is exactly where practices get caught off guard.

We break down where a good MSP's job ends and your practice's own compliance obligations begin, and why Colington Consulting only refers clients to MSP partners who genuinely understand HIPAA's requirements.

Not sure where your practice stands? Get a free HIPAA Risk Review. You can schedule using the link on our website homepage.

A good MSP isn't automatically a HIPAA compliant MSP. See what still falls on your practice, and where the compliance gaps really hide.

HIPAA has been federal law since 1996, but a lot of small and midsize healthcare practices are still confused about what...
08/19/2026

HIPAA has been federal law since 1996, but a lot of small and midsize healthcare practices are still confused about what it actually requires, and it is usually not because anyone is being careless.

Most practice owners and office managers never got formal HIPAA training. They picked up bits and pieces from a previous job, a software vendor's website, or an online forum, and a surprising amount of that secondhand information turns out to be wrong.

We just published a breakdown of the five HIPAA myths we run into most often with small and midsize practices, including the belief that a "HIPAA compliant" EHR means the whole practice is covered, and the confusion around which patient disclosures actually need a signed authorization versus which ones do not.

Regulators are not only paying attention to big hospital systems either. Small and midsize practices accounted for the majority of OCR's financial penalties in a recent reporting year.

Not sure where your practice stands? Contact our office for a free HIPAA Risk Review.

Quick answer: HIPAA has been federal law since 1996, yet small and midsize providers still get tripped up by it, and the reason is rarely carelessness. Most owners and office managers never received formal HIPAA training; they inherited assumptions from a prior job, a vendor’s marketing page, or a...

Did you know that if your school district bills Medicaid electronically for a student's counseling or therapy services, ...
08/05/2026

Did you know that if your school district bills Medicaid electronically for a student's counseling or therapy services, that can technically make the district subject to HIPAA — the same federal law that governs hospitals and doctors' offices?

Here's the good news: in most cases, the actual student records are still protected under FERPA (the student privacy law schools already follow), not HIPAA's privacy rules. But districts still need the right paperwork and safeguards in place for the billing side of things.

More schools are billing Medicaid for mental health and behavioral health services every year, so this is worth understanding if your district is one of them.

We've worked with several large public school systems on this exact issue, and we wrote up a plain-language breakdown of what applies, what doesn't, and what to check first.

Want help figuring out where your district stands? We offer a free HIPAA Risk Review, and for districts who want to go a step further on the student-privacy side, a FERPA assessment — not something the regulations require, but a service our school clients have found genuinely useful for staying on track.

Check out our website to book a free HIPAA Risk Review.

Schools Are Billing Medicaid for Behavioral Health Services — Does That Make Your District a HIPAA Covered Entity?

🚨 HIPAA Update: The federal government just delayed the HIPAA Security Rule changes to 2027 — but don't let that fool yo...
07/27/2026

🚨 HIPAA Update: The federal government just delayed the HIPAA Security Rule changes to 2027 — but don't let that fool you into thinking you have nothing to do.

The CURRENT HIPAA Security Rule is still fully in effect. That means the same rules, the same audits, and the same penalties still apply today. The only thing that got pushed back is a set of NEW proposed requirements (like mandatory encryption and multi-factor authentication) that haven't been finalized yet.

In other words: this is extra time to get prepared, not a free pass.

We put together a quick, plain-English breakdown of what's actually changing (and what isn't) so you know exactly where you stand 👇

Not sure if your organization has any gaps? We're offering a FREE HIPAA Risk Review to help you find out. The link to book is in the article.

Quick answer: HHS has pushed its target for finalizing the HIPAA Security Rule update from May 2026 to July 2027. But the delay only applies to the proposed new requirements— the current HIPAA Security Rule is still full...

Has your HIPAA compliance program gone on vacation for the summer? Bad threat actors are at it on 24/7 basis and do not ...
07/08/2026

Has your HIPAA compliance program gone on vacation for the summer? Bad threat actors are at it on 24/7 basis and do not take time off. Read our latest blog article on what your organization should be doing right now.

Summer is here — and while your staff rotates through PTO, cyber criminals are not. Ransomware gangs, phishing campaigns, and hacking groups operate 365 days a year, and the data confirms they are not taking July off. If...

Compliance pundits have provided many opinions regarding when and if the proposed modifications to the HIPAA Security Ru...
06/22/2026

Compliance pundits have provided many opinions regarding when and if the proposed modifications to the HIPAA Security Rule will be announced by HHS. Read our latest blog post to see what organizations need to know right now.

Is the New HIPAA Security Rule Final Yet? What Covered Entities Need to Know Right Now

Non-Emergency Medical Transportation (NEMT) providers are a growing business in the healthcare sector. When is a NEMT or...
06/17/2026

Non-Emergency Medical Transportation (NEMT) providers are a growing business in the healthcare sector. When is a NEMT organization considered a HIPAA Business Associate? Read our latest blog article to for key takeaways to make this determination.

Non-Emergency Medical Transportation (NEMT) providers serve a critical role in helping patients access healthcare services. However, one of the most common compliance questions in the industry is straightforward: When is...

06/02/2026

Think HIPAA compliance is static? Think again! In our rapidly evolving digital landscape, compliance strategies need to be dynamic and forward-thinking. Colington Consulting is leading the charge with tailored solutions designed for today's challenges.

We focus on mitigating risks and preparing organizations for the future through robust risk management plans and comprehensive training. Don't let compliance become a burden.

Keep it seamless, efficient, and integrated with Colington Consulting, so you can confidently navigate the digital world. Let's turn regulations into opportunities for growth and security.

Would you organization like a complementary 30-minute HIPAA Risk Review? Schedule now:

[email protected]/?ismsaljsauthenabled" rel="ugc" target="_blank">https://outlook.office.com/book/[email protected]/?ismsaljsauthenabled

At the recent HIPAA Summit, a number of sessions addressed the use of AI platforms in the GRC space.  Do AI platforms wo...
05/05/2026

At the recent HIPAA Summit, a number of sessions addressed the use of AI platforms in the GRC space. Do AI platforms work well when it comes to HIPAA compliance as compared to experienced HIPAA consultants? See what we think in our latest blog article.

Why a Full‑Service HIPAA Consultant Is Better Than an AI Compliance Platform

A few sessions at last week's HIPAA Summit covered Business Associates and the use of Business Associate Agreements (BAA...
04/14/2026

A few sessions at last week's HIPAA Summit covered Business Associates and the use of Business Associate Agreements (BAA). For those who did not attend, our latest blog post provides a quick summary of the required content of BAA. The post also looks at OCR enforcement and lessons learned.

If your organization is unclear on when a BAA must be executed or the required content, please book a free initial consultation with our company. You can find the link to book on our website home page.

Business Associate Agreements Under HIPAA: Regulatory Necessity and OCR Enforcement Lessons

Address

Fairfax County, VA
22009

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 9am - 5pm
Friday 9am - 5pm

Telephone

+18447407100

Alerts

Be the first to know and let us send you an email when Colington Consulting posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Share