Since 2002

HIPAA Compliance Services Chicago, IL

Illinois covered entities face HIPAA obligations alongside the Illinois Personal Information Protection Act and, for organizations using biometric authentication for EHR access, the Biometric Information Privacy Act (BIPA). Organizations that haven't mapped which systems trigger BIPA alongside their HIPAA program are carrying compliance gaps on both fronts.

500+
Organizations Served
23+
Years in Compliance
3
IL Frameworks to Align

HIPAA Compliance Solutions for Healthcare Practices

HIPAA Compliance Services for Healthcare Providers in Chicago, IL

Chicago healthcare organizations answer to more than OCR. HIPAA sets the federal floor, and Illinois layers on the Personal Information Protection Act (PIPA) and the Biometric Information Privacy Act (BIPA), two state laws that behave very differently. PIPA mostly defers to HIPAA for covered entities, with one added notification step that catches organizations that do not know it exists. BIPA defers to nothing. It reaches workforce biometrics HIPAA never touches, and it carries a private right of action. A compliance program built for HIPAA alone leaves both exposures open.

Stratify IT has been building compliance programs for healthcare organizations and their technology vendors since 2002. For Chicago-area providers, that means mapping HIPAA requirements against Illinois state obligations rather than stopping at the federal floor. If you cannot say with confidence where your posture stands today, start with a structured risk analysis. Contact us to discuss a scoped engagement.

Healthcare Organizations We Work With in the Chicago Area

HIPAA applies across the full spectrum of covered entities and their business associates. The rulebook reads the same for every covered entity. The operating problems do not. We work across the following segments in the Chicago metro area, including the Streeterville hospital district, the Illinois Medical District on the Near West Side, and suburban health systems across Cook, DuPage, and Lake Counties.

Major Health Systems and Hospital Networks

Chicago's health system environment includes large integrated networks with multiple hospital campuses, affiliated physician practices, and shared technology platforms. Each affiliate handling ePHI requires its own documented risk analysis and BAA structure, and shared EHR environments create ePHI access control obligations that must be mapped across the full organizational footprint.

Federally Qualified Health Centers

Chicago's FQHC network serves a large and geographically distributed patient population across underserved neighborhoods. Multiple funding streams, high workforce turnover, and community health worker programs that operate outside traditional clinical settings create specific challenges for consistent HIPAA training documentation and access control management.

Behavioral Health Providers

Psychiatry, psychology, and substance use disorder practices in Illinois answer to three record regimes at once. 42 CFR Part 2 restricts SUD treatment records beyond anything HIPAA requires. The Illinois Mental Health and Developmental Disabilities Confidentiality Act (740 ILCS 110) goes further still for behavioral health records generally, requiring specific written consent for disclosures HIPAA would treat as routine operations. Practices that have not mapped which records fall under which regime are exposed on all three fronts.

Dental Practices and Group Dental Organizations

Dental covered entities handling ePHI through digital imaging systems, patient management platforms, and third-party billing relationships require documented controls and active BAA management. Multi-location dental groups operating shared technology platforms face additional complexity in defining ePHI access controls across sites.

Home Health Agencies

Field staff carry ePHI on phones, tablets, and laptops that spend the workday on home networks and in parked cars. Device encryption, remote wipe capability, and access controls that survive a lost laptop are what separate an incident report from a reportable breach.

Healthcare Technology Vendors

Software developers, billing services, and IT providers that touch ePHI carry direct HIPAA liability as business associates. OCR can reach them without going through their clients. Chicago-area health tech vendors that use biometric identifiers for employee authentication or patient verification must also assess their obligations under BIPA independently of their HIPAA program.

What a HIPAA Compliance Program Requires

The Security Rule sorts safeguards into administrative, physical, and technical categories and, for now, splits implementation specifications into required and addressable. Addressable has never meant optional. Plenty of organizations treat it that way anyway, which is why regulators keep finding the same gaps year after year. Our complete HIPAA compliance guide walks through the full rule in detail.

That flexibility may not survive much longer. OCR published a proposed overhaul of the Security Rule in January 2025 that would retire the addressable category outright and make encryption, multifactor authentication, and annual compliance audits mandatory. As of mid-2026 no final rule has issued and the current Security Rule remains the law in force, but the direction is unambiguous. Chicago organizations building programs today should build toward where the rule is heading rather than to a floor that is about to move.

A defensible program starts with a documented risk analysis under 45 CFR § 164.308(a)(1) and a risk management plan that closes what the analysis finds. Policies have to describe your actual workflows rather than a template's idea of them. Training has to match job functions and leave a record. And the program as a whole needs review on a regular cycle, not a one-time build.

For organizations moving electronic protected health information (ePHI) across multiple systems (EHR platforms, billing vendors, cloud storage, and remote access tools among them) the technical safeguards around access controls, audit logging, and transmission security deserve review against what each system does in practice, and every one of those vendor relationships needs a current BAA.

Risk Analysis

A formal risk analysis under 45 CFR § 164.308(a)(1) establishes where ePHI is stored, transmitted, and processed, and which threats apply at each point. It is the control OCR checks first and the one most often absent from resolution agreements. No defensible HIPAA program exists without it. The distinction between risk analysis vs. risk assessment trips up more organizations than it should.

Policies & Procedures

Written policies covering privacy, security, and breach notification, drafted around how your organization actually operates rather than how a template assumes it does. We draft new documentation, bring stale documents current, and retire what no longer matches practice.

Business Associate Agreements

Every vendor with a path to ePHI needs a current, accurate BAA. We inventory the vendor list, flag missing and outdated agreements, and align each one with what the vendor does with your data in practice.

Technical Safeguards

Access controls, audit logging, encryption at rest and in transit, automatic logoff. We assess your current posture across the EHR and supporting systems and show you exactly where the gaps sit.

Workforce Training

Role-specific, documented, and tied to the work people do. A generic annual video satisfies nobody, least of all an auditor reading your training records.

Incident Response

Breach notification runs on fixed clocks for individuals, HHS, and in some cases the media. We build response plans, run tabletop exercises, and work incidents alongside you when they happen.

Illinois-Specific Compliance Considerations

PIPA treats HIPAA-regulated organizations differently from everyone else, and the difference matters. A covered entity or business associate that complies with HIPAA and HITECH is deemed compliant with PIPA, with one added obligation. Any breach reported to the Secretary of Health and Human Services must also be reported to the Illinois Attorney General within 5 business days of the HHS notification. The general PIPA trigger requiring Attorney General notice at 500 affected Illinois residents applies to ordinary data collectors and expressly does not apply to HIPAA entities meeting the deemed-compliance conditions. In practice the 5-day clock is the step Chicago providers miss, because nothing in the federal framework hints that it exists.

BIPA runs the other direction. It carves out patient information captured in a healthcare setting or handled for treatment, payment, and operations under HIPAA, and it covers nearly everything else. Fingerprint time clocks, biometric EHR log-ons, badge-in systems, and visitor kiosks with face matching all sit inside BIPA even in a fully HIPAA-compliant organization. Compliance requires a written retention and destruction policy, written consent before collection, and defined limits on disclosure. The private right of action is what gives the statute teeth. The 2024 amendment known as SB 2979 softened the damages arithmetic by treating repeated collections from the same person as a single violation, but per-person liability across a whole workforce still adds up quickly.

Where HIPAA, PIPA, and BIPA obligations overlap, we map controls once and reuse the evidence rather than running three parallel programs. Our team works with providers across the Chicago metro area including Streeterville, the Illinois Medical District, Evanston, and the northern and western suburban corridors.

How Stratify IT Approaches HIPAA Engagements

Most engagements open with a HIPAA risk analysis, a systematic review of how ePHI moves through your systems and where the exposure sits. Organizations that have never run a formal analysis, or have not refreshed one in years, tend to learn the most from this step.

The remediation plan comes out of the analysis with priorities attached. Missing BAAs, outdated policies, and training gaps close quickly. Access control restructuring, encryption on legacy systems, and vendor security reviews take planning. We scope the work to your risk profile, not to a product tier.

Gap Assessment First

We inventory current policies, map ePHI data flows, review existing controls, and compare documented practice against observed practice. The distance between the two is where the findings live.

Scaled to Your Organization

A solo practitioner and a multi-location hospital system do not share an audit profile, a budget, or a tolerance for process. We do not hand a twelve-person clinic an enterprise framework it cannot sustain.

Multi-Framework Alignment

For organizations subject to HIPAA alongside Illinois PIPA, BIPA, or SOC 2 obligations, we map controls across frameworks so a single policy or technical safeguard satisfies overlapping requirements, reducing duplicate documentation without creating gaps.

Audit-Ready Documentation

Risk analyses, policies, BAA inventories, and training records built the way auditors read them. When HHS or a client asks for documentation, the answer is a folder, not an emergency sprint.

Healthcare technology vendors supporting Defense health programs sometimes carry CMMC obligations on top of HIPAA. The frameworks overlap enough that coordinated work keeps you from paying twice for the same controls. Explore our CMMC consulting services if that applies to your organization, or our managed IT services in Chicago for ongoing technology support.

Incident Response and Breach Notification

The first 24 to 72 hours after a suspected breach determine most of what follows, and HIPAA's notification clocks for individuals, HHS, and in some cases the media run whether or not you are ready.

For Illinois organizations the state overlay is narrower than most assume. Because of PIPA's deemed-compliance provision, the added state step is the Attorney General notification within 5 business days of the HHS report rather than a second full notification track.

Biometric identifiers are the exception. An incident touching fingerprint or face-scan data, whether from EHR login systems, time-and-attendance clocks, or facility access controls, can trigger BIPA obligations even when it never crosses HIPAA's breach threshold.

OCR has pursued enforcement actions against covered entities in the Midwest for failures in risk analysis, access controls, and breach response. Resolution agreements are public record on the HHS website, and they name the same gaps over and over. Absent risk analyses. Stale policies. Training nobody documented. Organizations with current documentation across all three stand in a materially different position when an investigation opens.

A response plan your team has rehearsed, with contact names and preservation steps written down, removes most of the improvisation from a bad week. We build and test those plans through tabletop exercises and stay engaged when incidents happen. If an investigation or corrective action plan follows, we handle the HHS communications and remediation documentation with you. Our HIPAA compliance services overview covers the full engagement model, and our governance, risk, and compliance services page shows where HIPAA sits in the larger governance picture.

Talk to a HIPAA Compliance Specialist

HIPAA work goes better when it begins with a clear view of systems, ePHI handling, policies, vendors, and prior assessments. Bring us the current state and we will tell you what we would fix first.

HIPAA, BIPA & Illinois Law: Common Questions

The Illinois MHDDCA (740 ILCS 110) imposes stricter consent and disclosure rules for mental-health and developmental-disability records than HIPAA requires. Written consent is generally required to disclose these records, and a subpoena alone is not enough: it must be accompanied by a court order or the recipient's written consent before any provider may release the records. Chicago behavioral-health providers, hospitals with psychiatric units, and their IT vendors should treat mental-health records as a separately governed category with its own access controls and release procedures, not as ordinary PHI.

Yes. Practices and vendors that connect to or partner with large Chicago health systems such as Northwestern Medicine, Rush, or UChicago Medicine are typically required to complete vendor security assessments and meet contractual controls that exceed the HIPAA baseline, including MFA, encryption, endpoint detection and response, and a documented, current risk analysis. These obligations flow down to the IT provider, who must be able to produce supporting evidence on request. The health-system questionnaire, not the HIPAA minimum, is usually the practical standard for keeping these data-sharing and referral relationships.

BIPA requires any organization that collects, stores, or uses biometric identifiers, including fingerprints, retina or iris scans, and facial geometry, from Illinois residents to maintain a written retention and destruction policy, obtain written consent from individuals before collecting biometric data, and prohibit the sale or profit from biometric identifiers. In healthcare settings, BIPA applies to EHR authentication systems using fingerprint login, biometric time-and-attendance systems used by clinical staff, and patient identity verification systems. BIPA violations carry statutory damages of $1,000 per negligent violation and $5,000 per intentional violation, and Illinois courts have permitted class action suits under BIPA. A HIPAA-compliant program does not satisfy BIPA, the two frameworks must be assessed independently.

Illinois PIPA requires notification to affected Illinois residents in the most expedient time possible and without unreasonable delay following a breach of personal information. For breaches affecting more than 500 Illinois residents, notification to the Illinois Attorney General is also required. PIPA defines personal information more broadly than HIPAA's definition of PHI, and a breach that triggers HIPAA notification will typically also trigger PIPA obligations. The two frameworks define the triggering event and required notification content differently, which means organizations should pre-define a combined notification workflow rather than building one during an active incident.

FQHCs in Illinois operate under HRSA's Health Center Program compliance requirements alongside HIPAA, PIPA, and in some cases BIPA. HRSA requires FQHCs to maintain written policies and procedures covering patient rights, confidentiality, and data security, which overlap with but do not fully substitute for HIPAA's required policies. FQHCs that use biometric systems for employee access or patient check-in must assess BIPA applicability independently. Community health worker programs that operate outside the main clinic site create additional complexity around device management, ePHI access controls, and workforce training for staff who are not traditional clinical employees.

A health IT company that develops, hosts, or maintains software that processes ePHI on behalf of a covered entity qualifies as a business associate under HIPAA. This requires a BAA with each covered entity client, implementation of the company's own administrative, physical, and technical safeguards, and a documented risk analysis for the systems and environments that handle ePHI. Subcontractors with access to ePHI, such as cloud infrastructure providers, testing environments, or offshore development teams, must be bound by equivalent obligations through downstream BAAs. Illinois-based health IT companies that use biometric authentication in their products or internal systems must also assess BIPA applicability for Illinois users and employees.

What Our Clients Say About Our IT Services

"Outstanding experience from start to finish. His proactive approach made a huge difference in keeping our operations seamless and efficient."

Sally Porter, Washington Town Center

"They're customer-focused and very responsive. I recommend them very highly."

Karen Rifai, Art Studio Owner

"More than just tech support, they became true partners in our community mission."

Angel Sanchez, Inwood Community Services

"Absolutely no hesitation recommending Stratify."

Julien Frank, Royalty Solutions

"They surpassed our expectations by providing peace of mind, streamlined collaboration, and enhanced data security."

Derek Power, Beacon Interiors

"Their skilled technological expertise allowed for quick project completion."

Chris Ohanian, DesignWorks/Tache Jewelry Group

"With SRS, our systems stayed secure, providing peace of mind."

Shirley Lascano, Chado Ralph Rucci

"We have had no security breaches across our three companies in 20 years of service."

Mark Spier, Royalty Solutions Corp

HIPAA Compliance Services for Chicago Healthcare Organizations

Chicago covered entities and business associates start with a scoped risk analysis. Before any work begins, you'll have a clear picture of your compliance gaps, remediation priorities, and what a full project will cost.

Risk analysis under 45 CFR § 164.308(a)(1) with documented findings
Policies, procedures, and BAA inventory built around your workflows
Illinois PIPA and BIPA alignment alongside your HIPAA compliance program
Incident response planning and OCR audit preparation

Start Your Chicago HIPAA Engagement

The first step is a focused review of your systems, users, compliance obligations, and current support model. That review helps define the work that should be addressed first.

45min
Discovery Session
No
Initial Investment
24hr
Response Guarantee
23+
Years Experience

HIPAA Compliance Services Nationwide

Stratify IT provides HIPAA compliance services for covered entities and business associates across major healthcare markets. Every regional program addresses Privacy Rule, Security Rule, and Breach Notification Rule requirements alongside applicable state privacy law.

Complete HIPAA Pathway

End-to-end compliance from initial Security Risk Analysis through ongoing policy maintenance and OCR audit preparation.

State Law Integration

NY SHIELD Act, Massachusetts data privacy law, BIPA, Texas HB 300, CCPA, and CMIA addressed alongside federal HIPAA requirements.

Covered Entities & Business Associates

Full compliance support for providers, health plans, clearinghouses, and any vendor handling PHI under a BAA.

Find HIPAA compliance services in your region built around your local healthcare market and state regulatory environment.