Dear Colleague,
If you have landed on this page, there is a good chance you are weighing whether to hand an outside firm something uncomfortable: an honest look at how your organization protects patient information. I have been on the other side of that decision, and I know it is not a small one.
This firm exists because of a question I could not answer for three straight years.
Before EHR Resources, I worked under a State of Nebraska contract helping clinics, medical practices, and hospitals move from paper charts to electronic health records under the federal Meaningful Use incentive program. I worked alongside frontline clinicians, providers, and technical staff, and our teams were assigned more than 1,400 healthcare practices. That work is where this firm got its name.
One of the Meaningful Use measures required covered entities to conduct a HIPAA Security Risk Analysis. Our contract covered migration and attestation, not security assessments, so the same question came back from practice after practice: who actually does the risk analysis? Very few of them had anywhere good to send it. Around the same period I was selected to serve on a national working group of technical professionals drawn from 36 states, convened under the Department of Health and Human Services during Secretary Kathleen Sebelius's tenure, to help develop guidance for covered entities conducting their own internal security risk analyses.
Between the two, providers began calling me directly. They knew I understood the Privacy and Security Rules and had the technical depth behind it. In 2011 I started EHR Resources so I could answer that question properly, independently, and for anyone who asked.
A risk analysis is not a document you buy. It is a decision-making process you go through, and the document is simply the record of it.
The work has not changed much in character since. Conduct the analysis. Write policies and procedures that fit the organization rather than a template. Build a risk management plan someone can actually follow. Identify where compliance is genuinely exposed. Organizations in Nebraska, Kansas, Iowa, Colorado, Texas, California, and elsewhere have brought us in to do exactly that.
My background is not primarily in compliance. It is in technology. Across more than thirty years I have run IT operations in healthcare, insurance, and government, including roles as Director of Information Technology and interim CIO, with the focus always on data security, privacy, and protection. That matters more than it might sound. When I look at your environment, I am not reading a regulation and hunting for the paragraph that matches. I am looking at how your systems are actually configured, where the data actually moves, and who can actually reach it. Then I map that back to the Security Rule.
My first responsibility to a client is to tell the truth about what I find, including when the answer is inconvenient or when it is not what someone hoped to hear. A risk analysis that only produces good news is not doing its job. Neither is one so alarming that nobody can act on it. The value sits in between: a clear, prioritized, plainly written account of what is exposed, how much it matters, and what a reasonable next step looks like given your budget and your staffing.
I also want to be direct about what this work is not. No consultant can make an organization "HIPAA compliant," and anyone who tells you otherwise is selling something. Compliance is a posture you maintain, not a certificate you hang. What I can do is give you a defensible, well-documented analysis, a remediation plan you can actually execute, and evidence that your organization took its obligations seriously. If OCR, a payer, or a business partner ever asks how you arrived at your decisions, you will have an answer.
One more thing, and it is the part I care most about. When you engage this firm, you get me. Not a sales representative who hands you to an associate after the contract is signed. I do the interviews, I do the analysis, I write the report, and I am the one who picks up the phone six months later when a question comes up. That is a deliberate constraint on how fast this business grows, and I consider it worth every bit of the tradeoff.
The measure I pay attention to is not how many organizations we have worked with. It is how many keep asking us back. A good share of our engagements are with clients who return year after year, and that continuity is the part of this business I am proudest of.
If your last risk analysis was a template with your name typed into it, or if it has been a few years and the environment has changed underneath you, I would welcome a conversation. There is no charge for it, and no obligation on the other side.
Thank you for your time, and for the work you do.
Thomas J. Johnson
Thomas J. Johnson, CPHIT, CPEHR, ITPM
Founder, President, and Principal Consultant
EHR Resources, LLC · Veteran-Owned Small Business