About Hipsana
For clinicians who run their own practice.
Hipsana is built for a specific person: the dentist who owns a small practice and knows HIPAA is serious, but doesn’t have time to read hundreds of pages of federal regulations to find out where they stand.
Who we serve
Solo practitioners and practice owners with one to ten staff. People who run the whole practice themselves and know HIPAA carries real personal risk, with no in-house compliance help and no time to build it.
How we work
It starts with the Scorecard: ten yes/no questions about how your practice handles patient data, scored against the HIPAA Security Rule. You get a number out of 100, based on your answers, and a written review of the gaps they point to.
The review starts with the actual regulation, not a vendor’s marketing page. We look at what the Security Rule requires and where practices often fall short, then at what a fix actually involves, because HIPAA problems often come down to how a tool is configured, not the tool itself.
If you want help closing those gaps, we may introduce you to a compliance specialist who does that work, if there’s a fit. The Scorecard and the review are free.
The standard behind Hipsana
Hipsana is built to a single standard. Every regulatory claim traces to a primary source: the HIPAA Security Rule itself, the enforcement record the HHS Office for Civil Rights publishes, and NIST’s security guidance. Where a figure comes from breach data or industry research, we name the source. Anything we cannot verify against a regulator, we label rather than guess. The discipline is the point. It lets a practice owner see exactly where they stand and confirm every word of it independently. The full policy is on the editorial standards page.
Hipsana is built for a single audience: solo and small practices that carry a hospital’s HIPAA obligations without a hospital’s compliance department. The work is narrow on purpose, turning a sprawling federal rulebook into the handful of things that actually put a practice at risk.
About the author
Hipsana is written by its founder, Dolev Arama. He built the Scorecard and writes the reviews behind it. He is not an attorney, and Hipsana is a publisher and referral service, not a law firm or a healthcare provider. And he won’t pretend to be a compliance authority. What he brings instead is one rule he doesn’t break: every regulatory claim is traced to the regulator that made it (HHS, OCR, or NIST). Where a figure comes from breach data or industry research, the source is named, and anything he can’t verify gets labeled, not guessed. That’s the point. You never have to take his word for any of it: the sources are named, and you can open every one yourself.
What we are not
We are not attorneys, compliance officers, or healthcare professionals. The Scorecard and the written review are informational: a starting point for understanding your risk, not legal or compliance advice, and not a substitute for a professional engagement when your situation calls for one.
We also don’t handle patient data. The Scorecard asks how your practice operates, never about individual patients, and we never collect protected health information. For questions specific to your practice, consult someone licensed to answer them.
How we make money
When the Scorecard surfaces gaps you want help with, we may connect you to a compliance specialist who handles that work, if a referral makes sense. If we make that introduction, their firm may pay us a referral fee. It never costs you anything, and it never changes what your review says.
Contact
Questions, corrections, or feedback: email hello@hipsana.com. We read every message and reply to most within two business days.
See where your practice stands. Ten questions, about three minutes.