HIPAA Consulting
ALCON DTS helps covered entities run identity, devices, email, and backups so the HIPAA program has an environment it can defend — not a binder next to an open tenant.

Who this is for
Clinics, practices, and other covered entities or business associates in Austin and Central Texas that already have (or must have) a HIPAA program and need the Microsoft 365 tenant and devices to match it.
You keep the legal obligation for the program. ALCON DTS brings the operator work — Entra identity, managed endpoints, mailbox controls, backups, and written procedures that match how the practice actually runs — so the environment and the paperwork are telling the same story.
If you need the broader compliance map (HIPAA beside Texas SB 2610 and related programs), start with Regulatory Compliance. If you need the day-to-day clinical IT bench, see Healthcare IT.
What we support
ALCON DTS supports the pieces below so your HIPAA program sits on a tenant and device set you can actually operate — not a binder that never touches Entra.
Business Associate Agreements
Where ALCON DTS services are in scope, we execute a BAA and keep ePHI in approved systems. Scope is written clearly so everyone knows which services sit under the agreement.
Identity and access in Entra
Who can sign in, who can change privileged settings, and how Conditional Access applies to staff who touch ePHI. Access rules live in the tenant — not only in a policy document.
Managed endpoints and encryption
Windows, macOS, and mobile devices that handle ePHI stay on agreed updates, protection, and encryption. A lost or unmanaged device is an exposure we close with clear ownership.
Mailbox controls and forwarding
Inbound filtering, mailbox permissions, and forwarding stay current on Microsoft 365. Quiet forwarding and weak mailbox hygiene are where ePHI still walks out of the practice.
Backups and restore discipline
You know what is backed up, who can restore, and what “back to work” looks like when something fails — with ePHI restored only into approved systems.
Written procedures that match the live tenant
Expectations are documented enough to run: what is in scope, who approves changes, and how the system list and BAAs stay current. The procedures describe the tenant you operate today.
What’s included
HIPAA Consulting from ALCON DTS is the program work beside Healthcare IT: assessment, training, written procedures, and a place to keep the evidence.
Risk assessment
ALCON DTS performs the security risk analysis the practice needs to keep current: where ePHI lives, which threats matter, and a work plan. You spend a short working session on the environment; ALCON DTS drafts the assessment, recommendations, and the snapshot leadership can use.
Workforce training
New-hire and annual HIPAA security training with completion records. Reminders so training does not lapse. This is workforce documentation the practice can show — not a one-time slide deck.
Policies and procedures
ALCON DTS writes policies and procedures that cover HIPAA Security and Omnibus expectations and match the tenant the practice actually runs. Staff can find them. They stay aligned with Entra, devices, and mail instead of sitting in a binder that contradicts the live system.
Compliance workspace
A workspace for BAAs, incident notes, disaster plans, contracts, and the audit evidence file. It supports the program. It does not make the covered entity HIPAA certified.
How the work runs
HIPAA Consulting is the written program and the evidence file. Healthcare IT is the day-to-day bench for the clinic. Secure IT is the tighter identity, email, endpoint, and logging layer when those belong on the same relationship.
ALCON DTS starts with where ePHI lives — which systems, mailboxes, and devices — then closes the gaps so the program and the Microsoft 365 tenant tell the same story.
When the better fit is Healthcare IT, Secure IT, or a co-managed split with your internal team, we say so and send you there.
What a typical engagement covers
A typical engagement maps ePHI, tightens identity and devices around it, updates procedures so they match the live tenant, and leaves the practice with a work plan it can run. Scope is written before work starts.
Ready for a HIPAA review?
A HIPAA review with ALCON DTS is a short working session on the environment you already run. You leave knowing where ePHI lives, what the tenant already supports, and whether Healthcare IT, Secure IT, or a written consulting scope is the next step.
Related work
Healthcare IT · Regulatory Compliance · Secure IT · Cybersecurity · Managed IT Services · Acceptable AI Use

