Compliance you can prove, not paperwork you filed once.
Arias InfoSec Consulting helps independent medical and dental practices across North Jersey run a real HIPAA security program — an assessment that holds up, gaps that actually get fixed, and a plan for keeping it that way.
The risk analysis every HIPAA-covered practice is required to complete, in writing, at least once a year — and the document most practices don't actually have.
of OCR financial penalties in a recent year landed on small medical and dental practices — not the hospital systems with compliance departments.
Most practices have a folder, not an assessment.
A HIPAA risk analysis isn't a form your EHR vendor emails you once. It's a documented, practice-specific review of where patient data lives, who can reach it, and what happens if a laptop is stolen or a login gets phished — repeated every year and after anything material changes.
Owners and office managers already wear the compliance-officer hat alongside billing, staffing, and patient care. The assessment gets skipped, or a generic template gets signed without anyone actually walking the practice's systems. That's the gap that shows up when OCR asks for records, or after a breach makes the decision for you.
Three ways to work together
Each stage stands on its own, and each one sets up the next — start with the assessment, fix what it finds, then keep it current.
Security Risk Assessment
A full review of every place patient data lives — EHR, devices, email, backups, vendors — measured against the HIPAA Security Rule's administrative, physical, and technical safeguards. You get a written report with prioritized findings, not a checklist.
Remediation & Policy Package
Every assessment finds gaps. This closes them — written policies and procedures, vendor business associate agreements, access control fixes, and a staff training session your team will actually sit through.
Ongoing Compliance Program
Compliance isn't a once-a-year fire drill. Quarterly check-ins, an annual assessment refresh, policy updates as regulations change, and a direct line when a new hire needs access or a vendor sends a contract to sign.
Built on 10+ years inside the systems this protects.
Arias InfoSec Consulting is run by Jefrey Arias, a CISSP-certified security professional whose background spans healthcare IT access control and HIPAA-regulated environments, industrial and utility network security, and identity and access management administration.
That combination is unusual: most compliance consultants have read the regulation. Fewer have actually configured the access controls, audited the Active Directory environment, and sat inside a healthcare organization's IT team responsible for protecting patient records day to day.
Services are available in English and Spanish — a real advantage for the many independently owned practices across North Jersey serving Spanish-speaking patients and staffed by Spanish-speaking teams.
Essex, Hudson, Bergen, Passaic, Union, and Morris counties — on-site or remote.
- CertificationCISSP (ISC2)
- CertificationCompTIA Security+, ISC2 CC
- Healthcare ITHIPAA access control & EHR security, medical center IT
- Industrial / OT securityUtility-sector network security experience
- Identity & accessActive Directory & IAM administration
- LanguagesEnglish & Spanish
Start with a conversation, not a contract.
Tell us about your practice and where compliance stands today. We'll follow up to schedule a short call — no obligation, no pressure.