Our Services

We provide tailored expertise to help you build, strengthen, and sustain privacy, security and business continuity compliance programs from risk assessment to safeguard implementation. 

HIPAA Services

Under HIPAA, healthcare organizations (and those vendors that support them) are required to have HIPAA Privacy and Security Officers. Kamili Privacy provides cost-effective solutions to address this critical requirement. By using Kamili Privacy, you would be getting access to one of the most experienced HIPAA expert in the world.

Clients that most commonly use our HIPAA Services include:

  1. Healthcare Facilities: Hospitals, nursing homes, and pharmacies
  2. Outpatient & Support Services: Home health providers, dental offices, independent labs, medical billing, transcription services, and medical transportation
  3. Therapy & Specialized Care: Physical therapy, mental health therapy services, and other health care organizations
  4. Technology Vendors of Healthcare Organizations: Cloud storage providers, tech support organizations, etc.

specific HIPAA Services

HIPAA Security Officer

You would receive the following services under this category:

  • Initial assessment and onboarding support
  • Annual HIPAA Risk Analysis
  • Annual HIPAA Risk Management Process
  • Year-round training & awareness
  • Business Associate Agreement update/template
  • Breach protocol review/development
  • Audit Preparedness
  • Annual HIPAA Security Compliance Report (Technical/Non-Technical Evaluation)

HIPAA Privacy Officer

You would receive the following services under this category:

  • Initial assessment and onboarding support
  • HIPAA Privacy policy/procedures review/development/update
  • HIPAA forms review
  • Year-round training & awareness
  • Breach protocol review/development
  • Business Associate Agreement update/template
  • Audit Preparedness
  • Annual HIPAA Privacy Compliance Report

To purchase any of the above services, to ask any questions or for a free consultation, please send an email to [email protected] or Click This Button Below

Our Pricing: Simple + Predictable

Healthcare organizations can sign up for HIPAA Privacy & Security Officer services for a simple flat fee that is dependent on the size of the organization and number of locations.

Single-Location Healthcare Providers

Flat fee of $18,000 per year

(or $1,800 per month)

Medium-Sized Healthcare Providers

$30,000 – $60,000 per year
(or $3,000 to $6,000 per month)

Large Healthcare Providers

$75,000 – $120,000 per year

(or $7,500 to $12,000 per month)

HIPAA Security Officer Only (for Business Associates)

Flat fee of $36,000 per year
(or $3,600 per month)

HIPAA Privacy Officer services are not offered to business associates.

Consulting Services

Business Continuity Plan

Guided by applicable regulations, industry standards and best practices, our consultants help you build a business continuity plan that is designed to minimize long-term consequences of disruptions while maximizing opportunities for efficiency.

AI Governance Strategy

Our consultants help you create a flexible and adaptable roadmap. Our objectives include developing clear governance models, establishing clear roles and responsibilities, drafting processes for model risk management in line with industry regulations and establishing a trustworthy and compliant AI deployment approach.

Risk Assessment & Gap Analysis

Our consultants conduct thorough assessments of an organization’s current practices. This process is a systematic audit designed to identify vulnerabilities and gaps. Our primary goal is to measure the distance between the organization’s current state and a legally compliant, industry best-practice standard, which is critical for adherence to laws like the Health Information Privacy and Accountability Act (HIPAA), General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA). By pinpointing and prioritizing these risks, we establish a roadmap for remediation.

Policy & Procedure Development

Our consultants are instrumental in helping clients create, update, and implement policies and procedures. Policies are the high-level guiding principles, while procedures are the detailed step-by-step instructions that employees follow to execute the policies. We ensure these documents are not just legally sound but are also practical and aligned with the organization’s operational realities.

Data Mapping & Inventory

A fundamental task for our consultants is assisting organizations in creating detailed maps and inventories of their personal data. This involves documenting what personal data is collected, where it is processed and stored, how it is secured, and to whom it is transferred. This data inventory is the essential foundation for any privacy, security and business continuity program, as organizations cannot protect data, they do not know they have. This map allows for responsible data handling, enabling the business to demonstrate accountability for all data flows.

Training Awareness

Our consultants develop and deliver training programs specifically tailored to different roles within the organization. The purpose of these programs is to educate employees on core data protection principles, such as recognizing and reporting security incidents and understanding their responsibilities under the organization’s privacy policies. By increasing employee awareness, we transform privacy from a niche compliance issue into a shared, operational duty.

Implementation of Safeguards

Our consultants provide expertise in implementing both technical and organizational safeguards. Technical safeguards might include ensuring proper data encryption and deploying Data Loss Prevention (DLP) tools. Organizational safeguards focus on integrating principles like data minimization and establishing effective systems for consent management. We champion the concept of Privacy by Design, ensuring that privacy protections are built into new systems and processes from the outset. We also assist organizations with the implementation of de-identification programs under HIPAA.

Incident Response

In the event of a suspected breach, our consultants assist in managing and investigating privacy breaches and other security incidents. Our role is to provide a structured, compliant approach, which includes coordinating the internal investigation, managing data containment, determining the scope and impact of the breach, and ensuring that any required regulatory and public notifications are executed accurately and within legal timelines This is performed through Rimon Law

Third-Party Risk Management

Our consultants help organizations manage the privacy compliance of business associates and other third parties. This involves creating a robust process for vendor due diligence (vetting a third party’s privacy practices before engagement) and ensuring that all vendor contracts include necessary privacy provisions, such as Standard Contractual Clauses (SCCs) or Data Processing Agreements (DPAs). This protects the organization from liability caused by a vendor’s failure to protect shared data.Negotiating SCCs, DPAs or other contracts is performed through our collaboration with Rimon Law.

Compliance Documentation

Our consultants assist in creating all necessary compliance documentation required to demonstrate accountability to regulators. This includes drafting public-facing documents like privacy notices (informing consumers about data use) and internal documents like Records of Processing Activities (RoPA). This thorough documentation serves as the organization’s proof of compliance.

Ongoing Monitoring

Our consultants establish a continuous feedback loop by providing ongoing auditing and monitoring services. This ensures that the privacy, security and business continuity programs remain both effective and up-to-date with changing regulations. We routinely test the implemented controls and processes to confirm they are functioning as intended, providing an essential layer of assurance and adaptation.

Reporting

Our consultants help organizations report on the status and effectiveness of their privacy, security and business continuity programs to the organization’s management and leadership. These reports provide the executive team with a clear, concise overview of the current risk landscape, key performance indicators (KPIs) of the programs, and any resource needs, enabling informed strategic decision-making.

To purchase any of the above services, to ask any questions or for a free consultation, please send an email to [email protected] or Click This Button Below

Training & Speaking Services

Kamili Privacy offers comprehensive training and speaking engagements designed to enhance understanding and compliance in critical areas of privacy, security, and Artificial intelligence. Our services are tailored to meet the unique needs of your organization.

Keynote Speaking

Engaging keynote presentations on leadership, crisis management, team management, HIPAA, privacy, security and artificial intelligence. Ideal for conferences, corporate events, and industry gatherings.

Pricing: Pricing is $10,000, plus preparation and reasonable travel expenses.

In-Person Training

Customized on-site training sessions covering essential topics.

Pricing: Pricing is $5,000 per day, plus preparation and reasonable travel expenses.

 

 

Custom Online Training

Creation of customized training using client policies, procedures and requirements. Common topics include HIPAA, privacy, security, team management, leadership and resiliency. 

Pricing – charged at an hourly rate.

 

To purchase any of the above services, to ask any questions or for a free consultation, please send an email to [email protected] or Click This Button Below