> HIPAA Compliance // Optometry, exclusively

HIPAA Compliance for Optometry Practices

Audit-ready evidence, built and maintained for independent optometry — so when someone asks for proof, you hand them the binder.

Scroll — Gizmo will draw the rest
> 01 // The gap

A hospital's standard. Without the compliance department.

Your practice is held to the same HIPAA standard as a hospital. The hospital has a compliance department. You have a practice to run.

That gap is where independent optometry gets hurt — not because owners don't care, but because the rules assume documentation is someone's full-time job, and in a five-person practice that job belongs to nobody. We close that gap: compliance evidence built and maintained for you — dated, signed, and organized the way an auditor's data request is written.

> 02 // Sound familiar?

Does any of this sound like your practice?

One login for the whole exam lane

The tech starts the workup, the doctor finishes, a scribe documents — all under one account. The audit log works perfectly and proves nothing.

The imaging box on an old OS

The OCT or fundus camera runs an operating system years past end of support, stores patient images locally, and sits on the same network as everything else.

The BAA nobody has tracked

Billing service, shredding company, cloud backup, email host. Some have signed agreements, some don't, and nobody knows which ones have expired.

The backup nobody has tested

Backups run every night. Nobody has ever restored one to confirm it works. A backup you've never restored is a hope, not a safeguard.

None of this makes you careless. It makes you a normal independent practice — which is exactly who gets caught flat-footed when a letter arrives.

> 03 // What we hand you

The product is simple to describe: the binder.

A current, written risk analysis covering your whole environment. A remediation record with dates. Training records with names and acknowledgments. A maintained register of business associate agreements. Tested backups, with the restore test documented. An incident log that shows you evaluate events instead of ignoring them.

Every document dated, attributable to a real person, and retrievable in hours — not reconstructed from a former manager's email archive after the deadline letter arrives. Investigations are decided on documents that already existed. That is what we build, and what we keep current as your practice changes.

> 04 // Plain answers

What HIPAA actually requires.

Do we really need a risk assessment?

Yes — a written, current risk analysis is the single most-requested document in an investigation, and no EHR vendor can carry it for you. Read more →

What actually happens in an audit?

Usually an investigation, not an audit — a written data request with a short deadline, judged on documents you were supposed to already have. Read more →

Our EHR is compliant — aren't we covered?

HIPAA-capable, yes; your compliance, no. Most of what an investigator asks for lives outside the EHR entirely. Read more →

How long do we keep records?

Six years for HIPAA documentation — and evidence you can't produce on demand is functionally the same as no evidence. Read more →

What does a violation actually cost?

The fine is rarely the biggest number — forensics, counsel, notification, and cancelled clinic days usually cost more. Read more →

Want the full picture?

Plain-English answers to the questions practice owners actually search for. Browse all articles →

Sentry™ · Limited Beta

Your access log says "FrontDesk." An auditor wants a name.

Every exam lane runs on one shared Windows account — so the access log can't tell anyone who actually opened a chart. Sentry gives each staff member a badge and a PIN, and turns every sign-in into tamper-evident evidence: an append-only record, sealed with a timestamp and kept six years.

Compliance software can record that MFA is switched on. Only the people running your network can prove which named person was at lane 3 at 2:47pm — and that the record hasn't been touched since.

> Where do you stand?

Find out — in about three minutes.

Twelve plain questions, an honest grade, and a clear list of your gaps. No jargon, no sales pitch, and no patient information — just your answers and an email address.

Or book a call940-799-2457 · Optometry, exclusively · Founded by the inventor behind patented work in distributed personal data security · Trusted by independent optometry practices nationwide