HIPAA Consulting
ALCON DTS helps covered entities run identity, devices, email, and backups so the HIPAA program has an environment it can defend — not a binder next to an open tenant.

For covered entities that need the tenant to match the HIPAA program
Clinics, practices, and other covered entities or business associates in Austin and Central Texas that already have (or must have) a HIPAA program and need the Microsoft 365 tenant and devices to match it.
You keep the legal obligation for the program. We bring the operator work — Entra identity, managed endpoints, mailbox controls, backups, and written procedures that match how the practice actually runs — so the environment and the paperwork are telling the same story.
If you need the broader compliance map (HIPAA beside Texas SB 2610 and related programs), start with Regulatory Compliance. If you need the day-to-day clinical IT bench, see Healthcare IT.
What ALCON DTS supports
We support the pieces that make a HIPAA program operable on the tenant and devices you already run — not a binder that never touches Entra. You keep the legal obligation for the program. We bring the operator work so the environment and the paperwork tell the same story.
Where our services are in scope, we execute a Business Associate Agreement and keep ePHI in approved systems. Identity and access live in Entra: who can sign in, who can change privileged settings, and how Conditional Access applies to staff who touch ePHI.
Managed devices that handle ePHI stay on agreed updates, protection, and encryption. Mailbox permissions, forwarding, and inbound filtering stay current on Microsoft 365. You know what is backed up, who can restore, and what “back to work” looks like — with ePHI restored only into approved systems.
Written procedures describe the tenant you operate today. A review maps where ePHI lives and whether Healthcare IT, Secure IT, or a written consulting scope is the next step.
Business Associate Agreements
Where ALCON DTS services are in scope, we execute a BAA and keep ePHI in approved systems. Scope is written clearly so everyone knows which services sit under the agreement.
Identity and access in Entra
Who can sign in, who can change privileged settings, and how Conditional Access applies to staff who touch ePHI. Access rules live in the tenant — not only in a policy document.
Managed endpoints and encryption
Windows, macOS, and mobile devices that handle ePHI stay on agreed updates, protection, and encryption. A lost or unmanaged device is an exposure we close with clear ownership.
Mailbox controls and forwarding
Inbound filtering, mailbox permissions, and forwarding stay current on Microsoft 365. Quiet forwarding and weak mailbox hygiene are where ePHI still walks out of the practice.
Backups and restore discipline
You know what is backed up, who can restore, and what “back to work” looks like when something fails — with ePHI restored only into approved systems.
Written procedures that match the live tenant
Expectations are documented enough to run: what is in scope, who approves changes, and how the system list and BAAs stay current. The procedures describe the tenant you operate today.
What the work includes
HIPAA Consulting from ALCON DTS is the program work beside Healthcare IT: assessment, training, written procedures, and a place to keep the evidence.
Risk assessment
We perform the security risk analysis the practice needs to keep current: where ePHI lives, which threats matter, and a work plan. You spend a short working session on the environment; We draft the assessment, recommendations, and the snapshot leadership can use.
Workforce training
New-hire and annual HIPAA security training with completion records. Reminders so training does not lapse. This is workforce documentation the practice can show — not a one-time slide deck.
Policies and procedures
We write policies and procedures that cover HIPAA Security and Omnibus expectations and match the tenant the practice actually runs. Staff can find them. They stay aligned with Entra, devices, and mail instead of sitting in a binder that contradicts the live system.
Compliance workspace
A workspace for BAAs, incident notes, disaster plans, contracts, and the audit evidence file. It supports the program. It does not make the covered entity HIPAA certified.
How the work runs
HIPAA Consulting is the written program and the evidence file. Healthcare IT is the day-to-day bench for the clinic. Secure IT is the tighter identity, email, endpoint, and logging layer when those belong on the same relationship.
We start with where ePHI lives — which systems, mailboxes, and devices — then closes the gaps so the program and the Microsoft 365 tenant tell the same story.
When Healthcare IT, Secure IT, or a co-managed split with your internal team is the better fit, we recommend that band.
What a typical engagement covers
A typical engagement maps ePHI, tightens identity and devices around it, updates procedures so they match the live tenant, and leaves the practice with a work plan it can run. Scope is written in the review so both sides know what is in.
Start with a review
A HIPAA review with ALCON DTS is a short working session on the environment you already run. You leave knowing where ePHI lives, what the tenant already supports, and whether Healthcare IT, Secure IT, or a written consulting scope is the next step.
Related work
Healthcare IT · Regulatory Compliance · Secure IT · Cybersecurity · Managed IT Services · Acceptable AI Use

