THE
MINI
RISK TOOL
THIS TOOL IS FOR INFORMATIONAL PURPOSES ONLY.
IN ORDER TO MEET HIPAA COMPLIANCE
REQUIREMENTS, THIS TOOL MUST BE PAIRED WITH
THE RISK ANALYSIS SERVICE FROM PERSON
CENTERED TECH.
Training & Security Compliance
Made Effortless For Your Team
Track Staff Training and Security Tasks in Minutes
Start Free Today
Free, fast, and secure.
CLICK OR TAP to get started in just 2 minutes.
No credit card required
Relied on by 1500+ group practices nationwide
Secure logins for every staff
member. No confusion, no
mix-ups.
Automated reminders sent
for you. Stop chasing staff for
training or security task
completion.
One dashboard shows you
exactly who’s on track —
and who isn’t. Clear, real-time training logs
— always audit-ready
Manage & Meet Your Team's Training
Needs With Ease
Optimize your mental health
practice and cover your HIPAA
needs without sacrif icing client
care
It works for you, because we made it for you,
because we are you.
Get Connected
Schedule a call with our team
CLICK OR TAP to schedule a call
[Link]
info@[Link]
YOUR
SECURITY
CIRCLE
CULTIVATING A WALLED GARDEN
OF TRUST, FUNCTIONALITY, AND
COMPLIANCE
Think of this tool as an initial While this mini risk analysis is
“Needs Assessment & a powerful place to begin, it
Treatment Plan” for your doesn’t fulfill the HIPAA
practice’s security and Security Rule’s requirement
compliance foundation. It for a documented “thorough
helps you map what’s inside and accurate” risk assessment.
your “security circle”—the PCT’s consultant-performed
people, systems, and HIPAA Security Risk Analysis &
information you’re responsible Mitigation Planning service
for protecting—and spot what does, and it results in a
may still be outside it. By customized, prioritized action
walking through five key areas plan. If you're ready for deeper
—your tech stack, team clarity and compliance
training, device safeguards, confidence, our focused two-
risk planning, and policies & hour RAMP session offers a
procedures—you’ll gain clarity manageable, high-impact
on what’s solidly in place and next step.
where meaningful action can
strengthen your foundation.
This mini risk analysis is like a gentle check-in for your practice’s security,
compliance, and functionality—designed to help you identify what will most
meaningfully support, optimize, and fortify your practice.
TECH STACK
The tools and programs you use to run your practice.
Outside
Action Required: If you have any filled circles in this section, you need a
formal Risk Analysis and Risk Mitigation Plan
There are unmet functionality needs in either/both client-serving and
internal operations.
Not all third-party services that handle client info (PHI) are a practice
provided and controlled asset (e.g. personal services).
HIPAA Business Associate Agreements are not executed (or
available) between all third-party service providers that handle PHI
and the practice.
Systems containing or handling PHI are not configured to prevent
information being “leaked” or “forgotten.”
Documentation needs being met are reliant on behavior rather than
automated by systems.
Inside
Action Required: If you have any unfilled circles in this section, you need a
formal Risk Analysis and Risk Mitigation Plan
All functionality needs are effectively met (client-serving & internal
operations)
All third-party services that handle client info (PHI) are a practice
asset
HIPAA Business Associate Agreements are executed between all
third-party service providers that handle PHI and the practice
All the practice’s systems are set up so they don’t “leak” or “forget”
information.
Services help maintain documentation automatically (e.g. HIPAA-
secure email, phone, texting.)
TRAINING
See
Recommended
Staff Trainings
Action Required: If you have any
filled circles in this section, you
Outside need a formal Risk Analysis and
Risk Mitigation Plan
CLICK OR TAP for
recommended trainings
All workforce have not been trained on the practice’s P&Ps.
All workforce do not have a foundational knowledge of HIPAA, state laws, and
ethics standards appropriate and necessary to their role within the practice.
Reminders and trainings to ensure the P&Ps are understood and being
followed by everyone (including the leadership team) are not being made.
All workforce are not trained on the P&Ps at least once a year.
All workforce do not have the training and help they need to make sure they
can properly use the equipment and services within the circle.
All workforce do not have the training they need to maintain the circle and
also do their jobs without interruption.
Inside Action Required: If you have any unfilled circles in this section, you need
a formal Risk Analysis and Risk Mitigation Plan
At onboarding, all workforce receive training on the P&Ps and other
registration processes (e.g. remote workspaces and BYOD.) Training on
HIPAA and other laws, as necessary.
All workforce have a foundational knowledge of HIPAA, state laws, and
ethics standards appropriate and necessary to their role within the
practice
Reminders and trainings are continuously provided as needed to ensure
the P&Ps are understood and being followed by everyone (including the
leadership team.)
All workforce are formally trained on the P&Ps at least once/year.
All workforce have the training and help they need to make sure they can
properly use the equipment and services within the circle
All workforce have the training they need to maintain the circle and also
do their jobs without interruption.
DEVICE Get Your Team’s
Devices Secured
SECURITY CLICK OR TAP to learn
more about device
security support
Outside
Action Required: If you have any filled circles in this section, you need a
formal Risk Analysis and Risk Mitigation Plan
All practice-owned data-handling devices have been
“hardened” with necessary technical measures (e.g. full device
encryption, strong and unique encryption passcodes, anti-
virus/anti-malware, firewalls, etc.,)
All workforce members’ personally-owned devices that ever
touch client info have been “hardened” with necessary
technical measures (e.g. full device encryption, strong and
unique encryption passcodes, anti-virus/anti-malware, firewalls,
etc.,)
All practice-owned and personally-owned devices that touch
PHI qualify for Safe Harbor under HIPAA’s Breach Notification
Rule
Hardening of all practice-owned devices is documented
All workforce have been trained on the behavioral security
measures (e.g. never connecting to WiFi that doesn’t meet
trusted network criteria, etc.,) that must be followed for any
devices that ever touch PHI and agreed to abide by them
All workforce member’s personally-owned devices that touch
PHI have been registered and approved as meeting the BYOD
policy requirements for technical security measures and
accompanying behavioral security measures
When any device that has touched practice PHI is no longer
going to be used for practice work, the device is properly
“retired” (e.g. data scrubbed/wiped, factory reset) and
documented as such
Get Your Team’s
DEVICE Devices Secured
SECURITY CLICK OR TAP to learn
more about device
security support
Action Required: If you have any unfilled circles in this section, you need a
Inside formal Risk Analysis and Risk Mitigation Plan
All functionality needs are effectively met (client-serving & internal
operations)
All third-party services that handle client info (PHI) are a practice
asset
HIPAA Business Associate Agreements are executed between all
third-party service providers that handle PHI and the practice
All the practice’s systems are set up so they don’t “leak” or “forget”
information.
Services help maintain documentation automatically (e.g. HIPAA-
secure email, phone, texting.)
HIPAA-Secure Devices, Made Simple
Vulnerability is for your clients. Not your devices.
Person Centered Tech has device
security support for Group Practice
leaders through Practice Care
Premium.
Register and secure all devices —
practice-owned or staff-owned — with
HIPAA-compliant procedures,
simplified management, and peace of
mind
RISK ANALYSIS &
RISK MITIGATION
PLANNING
Outside
Action Required: If you have any filled circles in this section, you need a
formal Risk Analysis and Risk Mitigation Plan
The practice has not conducted and documented an “accurate and
thorough assessment” of the potential threats and vulnerabilities to
the confidentiality, integrity, and availability of electronic protected
health information the practice creates, receives, maintains or
transmits
Threat likelihood and potential threat realization impact have not been
ranked from highest to lowest
The practice has not assessed and documented the security measures
(technical, administrative, physical) used to safeguard e-PHI, whether
security measures required by the Security Rule are already in place,
and if current security measures are configured and used properly
Risks have not been categorized as “addressable” and “required” for
mitigation
“Reasonable and appropriate” safeguards and security measures that
reduce the likelihood of risk to the confidentiality, availability and
integrity of e-PHI have not been identified
A risk mitigation plan for implementing necessary safeguards and
security measures has not been created, followed, and documented
Risk analysis is not updated on an annual and as-needed basis
Security Risk Analysis – without the stress
Schedule your
A technical and practical qualitative assessment led by Risk
a consultant to ensure compliance with HIPAA Assessment
standards for a thorough risk assessment. Today
Protect your clients. Protect your practice.
CLICK or TAP to book yours
RISK ANALYSIS &
RISK MITIGATION
PLANNING
Inside
Action Required: If you have any unfilled circles in this section, you need a
formal Risk Analysis and Risk Mitigation Plan
The practice has conducted and documented an “accurate and thorough
assessment” of the potential threats and vulnerabilities to the
confidentiality, integrity, and availability of electronic protected health
information the practice creates, receives, maintains or transmits
Threat likelihood and potential threat realization impact have been
ranked from highest to lowest
The practice has assessed and documented the security measures
(technical, administrative, physical) used to safeguard e-PHI, whether
security measures required by the Security Rule are already in place, and
if current security measures are configured and used properly
Risks have been categorized as “addressable” and “required” for
mitigation
“Reasonable and appropriate” safeguards and security measures that
reduce the likelihood of risk to the confidentiality, availability and integrity
of e-PHI have been identified
A risk mitigation plan for implementing necessary safeguards and
security measures has been created, followed, and documented
Risk analysis is updated on an annual and as-needed basis
Risk Analysis DONE in 2 hours.
Action plan
Get a consultant-led security risk analysis and risk included — not
mitigation plan – fast, thorough, and HIPAA-compliant. just an
assessment.
Seriously. Book today.
HIPAA
COMPLIANCE
MANUAL
SECURITY POLICIES & PROCEDURES
Outside
Action Required: If you have any filled circles in this section, you need
security policies and procedures
The practice does not have a comprehensive set of formal, written security
compliance policies and procedures which address each standard of the
HIPAA Security Rule and specify how the practice and its workforce meet
each standard
Administrative safeguard policies and procedures do not address: Security
Management Process, Security Personnel, Information Access
Management, Workforce Training and Management, and Evaluation
standards and requirements.
Physical safeguard policies and procedures do not address: Facility Access
and Control, and Workstation and Device Security standards and
requirements.
Technical safeguard policies and procedures do not address: Access
Control, Audit Controls, Integrity Controls, and Transmission Security
standards and requirements.
Written Security P&Ps have not been implemented and followed in-
practice
Get the Policies and Procedures Get Your HIPAA
Your Practice Needs Manual Started
Today
Everything you need to facilitate a strong
security platform that keeps you and your
clients HIPAA safe.
CLICK OR TAP to learn
more about policies and
Get started prodecures
HIPAA
COMPLIANCE
MANUAL
SECURITY POLICIES & PROCEDURES
Inside
Action Required: If you have any unfilled circles in this section, you need
security policies and procedures
The practice has a comprehensive set of formal, written security
compliance policies and procedures which address each standard of the
HIPAA Security Rule and specify how the practice and its workforce meet
each standard
Administrative safeguard policies and procedures address: Security
Management Process, Security Personnel, Information Access
Management, Workforce Training and Management, and Evaluation
standards and requirements.
Physical safeguard policies and procedures address: Facility Access and
Control, and Workstation and Device Security standards and requirements.
Technical safeguard policies and procedures address: Access Control, Audit
Controls, Integrity Controls, and Transmission Security standards and
requirements.
Security P&Ps have been implemented and are followed in-practice
Simplified, Practice-Ready Policies and Procedures
No generic boilerplate — just policies and procedures built for mental health
practices, ready for implementation and peace of mind.
ad for Risk Analysys with lifetime access and consultant performed
Comprehensive Support for Your Group Practice
Practice Care
What you need, no matter where you are.
Practice Care provides the support your group practice needs for
HIPAA compliance, device and workspace security, and ongoing
optimization — all in one service plan.
Whether you’re just starting compliance, getting your devices secure
after a breach, or maintaining policies and procedures, Practice Care
gives you expert guidance and ongoing support.
Premium Device Security
Premium Practice Optimization
Resources
Get The Support
Premium Workspace Security You’re Looking
For Through
Premium Direct Support and Practice Care
Consultation
CLICK OR TAP to learn
Includes
more about Practice Care
Office Hours!
Get started with Practice Care today
Save additional two months free and get 20% off foundational
trainings with annual subscription
Group Practice
Office Hours
Your Questions, Answered —
Live & On-Demand
Weekly live sessions + recordings
Submit questions anytime
Personalized video clips of your answers
Expert-led sessions with specialists
Weekly live sessions and
recordings
Off ice hours were great. I
was really happy with the Personalized video clips
give and take and the to questions you’ve
individual attention. You asked
will def initely be seeing
Expert-led sessions and
me again there.
guest specialists
Abigail McCarrel LCSW, DCSW
Join Group Practice
Office Hours Today
Includes
CLICK OR TAP to learn more about
Office Hours! Practice Care
Included in Practice Care Premium
Compliance Bundle
Investment
All-in-one compliance support, tailored
for group practices.
Purchase
POLICIES AND PROCEDURES the bundle
HIPAA MANUAL and save
$1200 $100
Codify and operationalize Your HIPAA Security Compliance
Program in your Policies & Procedures.
HIPAA SECURITY RISK ANALYSIS AND
MITIGATION PLANNING
$500
2-hour consultant-led risk analysis, with actionable mitigation
plan. Meets federal HIPAA requirements.
ANNUAL GROUP PRACTICE CARE
PREMIUM
$990/yr
Ongoing tools and resources, device security, workspace
security, and direct support-- all in one plan.
trusted and recommended by:
Let’s Get In Touch
Support For Mental Health, By Mental Health
The team of therapists and tech experts at PCT are all here to
help our colleagues in mental health build practices that
leverage tech to provide safe, effective client care.
Liath Dalton
Director & Senior Consultant
Group Program Manager
[Link]
info@[Link]
CLICK OR TAP to book a call with Liath