Features

Everything your HIPAA program needs, in plain English.

From a two-minute setup to an auditor-ready record, ComplianceAX guides a small practice through every part of HIPAA compliance.

The guided assessment

HIPAA as a conversation, not a spreadsheet.

  • One plain Yes, No or Not applicable question at a time, covering every applicable HIPAA Security, Privacy and Breach Notification requirement.
  • Covers administrative, physical, technical, privacy, breach and vendor safeguards.
  • Physical safeguards are answered for each location, so a second office is never overlooked.
  • Every question explains why it matters and cites the HIPAA rule it comes from (45 CFR).
  • A progress bar shows each section and how much is left.

Set up in about two minutes

Eight quick facts tailor the assessment to your practice.

  • Practice type, locations, headcount, EHR, where records live, email system, your Privacy and Security Officials, and your IT provider.
  • Questions that can't apply to you are set aside, with the reason recorded.

A head start from your documents

Upload the policies you already have.

  • Private AI reads them and suggests answers, but only with an exact quote that has been checked against your document.
  • If there is no supporting sentence, there is no suggestion.
  • You accept or reject each suggestion one at a time. Nothing counts until you do.

Help on every question

An assistant on every assessment screen.

  • Explains the question in plain English and what counts as proof.
  • Shows what your own documents say, with numbered sources.
  • Never answers for you, never declares you compliant and never gives legal advice.

Score, plan and tasks

Know where you stand and what to do next.

  • A score calculated by fixed rules, never by AI.
  • Every No becomes a gap with next steps, and gaps become a remediation plan ordered by severity.
  • My Work lists only your own tasks. Hand any question to a colleague who knows the answer.

Employees, policies and training

Keep the people side of the program current.

  • An employee list with each person's open tasks.
  • Versioned policies with electronic attestation and sign-off.
  • Training records for every member of your workforce.

Vendors and BAAs

Know who handles your patient data.

  • Track every vendor and whether a business associate agreement is in place.
  • Upload the agreement and AI pulls out its dates and terms, quoting the agreement for every field.

Incidents and breach response

A calm, guided process when something goes wrong.

  • A case file for each incident, with the 60-day breach notification clock in view.
  • A four-factor risk assessment workflow.
  • Whether an incident is a breach is always decided by a person.

Evidence and the auditor packet

Proof lives with the answer it supports.

  • Attach files and quotes to any answer.
  • Export the whole record as of any date: every answer, document, task and decision, ready for an auditor or insurer.

Security built in

Built for data you can't afford to lose.

Every organization's records are kept separate, every sign-in is protected and every action is logged.

Read about private AI and security

Separate by design

Database row-level security keeps each organization's records isolated from every other.

Strong sign-in

Passwordless email sign-in, required two-step verification for owners, admins and officers, and a 15-minute idle timeout.

A tamper-evident record

An append-only, hash-chained audit log of who did what, and when.

See ComplianceAX with your own practice in mind.

Request a 30-minute demo with Southeastern Technical. We'll walk through the assessment, the document head start and what a complete program record looks like.