Keep the doors open and the grant secure
You are running an electronic health record, a dental system, a pharmacy program and a sliding fee scale on a budget built for patient care, and the site visit is coming.
A federally qualified health center carries the compliance load of a hospital on the budget of a small business. The Health Resources and Services Administration expects program requirements met. The Health Insurance Portability and Accountability Act (HIPAA) applies in full. Uniform Data System reporting has to be accurate. Add the 340B drug pricing program, payer audits, and a state Medicaid agency, and the reviews arrive from several directions at once — at an organization where the technology function is often one or two people who also fix printers.
The consequence is not abstract. Grant funding, program standing, and the ability to keep serving a patient population that has nowhere else nearby to go.
IT21 works the technology and control side of that load. The security risk analysis that HIPAA requires and that every investigation asks for first. Access built for a workforce that is genuinely shared — providers who work two days a week, residents who rotate through, students, contracted behavioral health staff — where the usual approach of a permanent role per person does not fit. Vendor and business associate oversight. Downtime procedures, because a clinic day does not stop when the record system does.
What you get:
- A HIPAA security risk analysis current enough to hand to a reviewer without preamble
- Documentation aligned to what an operational site visit asks about on the technology and privacy side
- Data quality work upstream of Uniform Data System reporting, so the numbers are defensible at the source
- Access controls that hold across a shared workforce: part-time providers, residents, students, contracted staff
- Continuity planning for a clinic day when the record system is unavailable
Uniform Data System reporting deserves its own mention. Most centers treat data quality as a reporting problem, addressed each winter by cleaning what the system produces. It is a workflow problem. If a field is captured inconsistently at registration in March, no amount of care in January fixes it honestly.
Assess is the risk analysis and a review of your documentation against what a reviewer will ask for. Transform is remediation sized for a health center budget — the phrase “we recommend a dedicated security team” has never once been useful advice to an FQHC. Optimize is the annual rhythm: refresh the analysis, recertify access, update after each system change.
One credential is worth naming plainly here because reviewers and boards ask. Our principal has held the Certified Information Systems Auditor designation since 1997, and spent years in the Information Risk Management practice at KPMG and as a partner in a CPA firm, on the side of the table that tests evidence rather than prepares it. Health center work has been a significant part of that career.
Data quality is a workflow problem, not a reporting problem.
[PROOF: FQHC or community health center engagement — region, size, scope, result — supply]
If the site visit is on the calendar, or the last risk analysis predates your current record system, the IT Risk & Readiness Assessment is the place to start. It is measured against a recognized technology-governance framework, and it is scoped to be manageable for a health center.
- Assess
- Transform
- Optimize
Oscar Chacon, CISA
Certified Information Systems Auditor since 1997
Not sure where you stand? Start with the assessment.
Request the AssessmentWhere to go next
FQHC HIPAA & site-visit readiness — a brief
HIPAA security risk analysis, operational site-visit readiness, UDS data quality, and access control for a shared health-center workforce.
Get the PDF — enter your email
HubSpot form — assessment-request — not configured
Set portalId and forms.assessment-request in src/lib/hubspot.ts.
Start with the IT Risk & Readiness Assessment
A defined engagement, measured against a recognized control framework, that shows you which controls exist, which are documented but not operating, and which are absent — before you commit a budget.

