Media Express prepares Chicago-area healthcare providers, dental practices, therapy clinics, medical device makers, and IT/MSPs serving healthcare for HIPAA compliance. Privacy Rule + Security Rule + BAA framework + patient-facing website compliance. One partner. One contract. One deadline.
HIPAA has two categories of regulated entities. Covered entities are the front-line healthcare organizations. Business associates are everyone else who touches PHI on their behalf. Both categories carry the same penalties for violations.
Rule of thumb: if PHI enters or leaves your systems, in any form, HIPAA applies to you.
HIPAA is enforced through three primary rules. All apply to covered entities. Most apply to business associates. Missing any one exposes you to OCR enforcement.
Defines what counts as PHI, who can access it, when it can be shared, and how patients can request their own records. Requires a written Notice of Privacy Practices (public-facing, on your website) and formal patient-consent procedures.
Applies to electronic PHI. Requires administrative safeguards (policies, training, sanctions), physical safeguards (facility access, workstation security), and technical safeguards (access controls, encryption, audit logs, transmission security).
Requires notification to affected patients within 60 days of a breach affecting 500+ individuals. Immediate notification to HHS. Large breaches also reported to local media. Business associates must notify covered entities without unreasonable delay.
HIPAA fines are tiered based on culpability. Amounts adjust annually for inflation. These are 2024 published tiers per HHS. Multiple violation categories can stack in a single incident.
| Category | Minimum | Maximum | Description |
|---|---|---|---|
| Did Not Know | $137 | $68,928 | Covered entity or BA did not know (and by exercising reasonable diligence would not have known) of the violation. |
| Reasonable Cause | $1,379 | $68,928 | Violation due to reasonable cause and not willful neglect. |
| Willful Neglect (Corrected) | $13,785 | $68,928 | Willful neglect but corrected within 30 days of discovery. |
| Willful Neglect (Not Corrected) | $68,928 | $2,067,813 | Willful neglect not corrected. Ceiling is per violation category per year. |
Criminal penalties for knowing misuse of PHI: up to $250,000 fine and up to 10 years imprisonment.
OCR complaints from patients, employees, and competitors trigger investigations. Most small/mid healthcare businesses that fail an audit didn't think they were "big enough" for OCR to notice.
A structured, phased approach with clear deliverables and fixed pricing. You always know what's next, what it costs, and when it's done.
Take our 15-question quiz. Get an instant PDF report with your HIPAA readiness score, applicable rules, and top-priority gaps. This tells us whether you're a covered entity or business associate and what to focus on first.
Fixed-price engagement. We map your current state against Privacy Rule + Security Rule + Breach Notification requirements. Identify every gap, produce a phased roadmap with timelines and costs. Includes OPSEC website audit to catch PHI-related information leaks.
Notice of Privacy Practices (public + patient-facing). BAA templates for your vendors. Employee HIPAA policies. Security Rule administrative safeguards. Patient portal compliance. Website Privacy Rule alignment. Every artifact an OCR investigator would look for — ready.
Whatever technical gaps exist — encryption at rest and in transit, MFA rollout for anyone touching ePHI, access controls, audit logs, patient data segregation, workstation security, backup testing. We coordinate the work and verify each control is in place.
HIPAA is not one-and-done. Annual risk assessment, ongoing training, updated policies as regulations change, incident response for potential breaches. Managed retainer keeps you compliant year-over-year without rebuilding from scratch.
Small practices can reach HIPAA-ready quickly. Larger practices with more complex data flows need full alignment. Ongoing retainer keeps you compliant as regulations evolve.
Prices depend on practice size, complexity of workflows, and existing security posture. Assessment results give you an accurate quote.
Above are typical Illinois market rates. Media Express pricing is more accessible — we build once and reuse across clients, so you don't pay for someone else's discovery work. Contact us for a personalized quote based on your exact situation.
⚜ Free Consultation →Yes, if your business creates, receives, maintains, or transmits Protected Health Information on behalf of a covered entity. Common examples: IT/MSP firms, billing companies, transcription services, cloud vendors, EHR platforms, shredding services, cybersecurity firms, law firms handling healthcare matters. Business associates sign a BAA and must comply with most of the same Security Rule requirements as covered entities.
Protected Health Information — any individually identifiable health information (names, dates, addresses, SSNs, medical record numbers, biometrics, photos) combined with information about an individual's health, treatment, or payment for care. Electronic PHI (ePHI) is PHI stored or transmitted electronically.
Small clinic with baseline IT: 6-10 weeks for HIPAA-ready posture. Full compliance alignment: 3-6 months. Starting from scratch with no security foundation may take longer.
HIPAA-Ready Website package: $6-15k one-time. Full Alignment: $20-60k phased. Managed retainer: $1.5-6k/mo. See pricing tiers above.
No. Formal HIPAA audits are conducted by OCR (Office for Civil Rights, HHS) or by independent third-party firms during accreditation reviews. Media Express prepares you for those audits — website compliance, documentation, BAA framework, gap remediation — and coordinates with independent audit partners when you need formal review.
Civil penalties from $137 to $2,067,813 per violation category per year (2024 tiers, inflation-adjusted). Criminal penalties include fines up to $250,000 and up to 10 years imprisonment for knowing misuse of PHI for personal gain or malicious harm. Most enforcement actions also carry corrective action plans with multi-year monitoring.
Business Associate Agreement — a contract between a covered entity and any business associate that touches PHI. Yes, you need one with every business associate. Yes, business associates need one with sub-business associates. Media Express provides tested BAA templates that cover your vendors and yourself in the sub-BA position.
HIPAA references several related terms. If you want to go deeper on any of them, our wiki covers each in plain English.
Take the free 15-question Compliance Readiness Assessment. Instant PDF report with your HIPAA status (covered entity vs business associate), readiness score, and top-priority actions. No sales pitch.