A new director inherited the systems. Nobody had written down how they worked.
A Montana nonprofit's new director inherited unclear technology and policies. Our audit found the HIPAA and privacy gaps, then we rebuilt policy and trained staff.

A Montana nonprofit that handles sensitive client information, led by a new executive director who inherited an unclear mix of technology, policies, and procedures.
Nonprofit
Technology Audit, HIPAA Gap Assessment, Policy Development, Staff Training
A Montana nonprofit brought on a new executive director, who quickly found that the organization's technology, policies, and procedures were a confusing mix. The organization handles sensitive client information, and for a nonprofit, protecting that information is a large part of keeping the community's trust.
Leadership wanted a clear picture of where they stood: what technology staff actually used, how work got done, and where they fell short on HIPAA and data privacy. Then they wanted a plan to fix it.
Before
The Challenge
Without a clear view of their technology and processes, the organization was running inefficiently and carrying risk it couldn't measure. Gaps in data privacy and HIPAA compliance could mean legal exposure, financial penalties, and damage to the organization's reputation in the community.
The new leadership team set four goals: document and streamline the technology and processes staff relied on, meet HIPAA and data privacy requirements to protect client and organizational information, get more out of the tools they already had for current and new staff, and put real safeguards around sensitive data.
Getting there required a full audit of technology, policies, and procedures; expert guidance on HIPAA and privacy gaps; policies written for how this organization actually works; and training so every staff member understood and followed them.
After
The Results
Technology and processes are now documented and clear, and the executive director can focus on the organization's strategic work instead of IT concerns.
Staff have a clear understanding of the organization's HIPAA and data privacy policies, which strengthens how client information is protected day to day.
The updated procedures and training have improved daily operations and made the team more productive.
The nonprofit now has a framework for maintaining compliance and protecting sensitive information as it grows.
The Solution
We started with a detailed technology audit covering the organization's systems, processes, and workflows. Rather than working only from documentation, we met directly with each business unit to understand how they worked and where they struggled. The audit focused on finding the areas that fell short of HIPAA and data privacy best practices.
Based on those findings, we wrote customized policies and procedures for data security and day-to-day operations. We then worked closely with leadership to fit them into the organization's existing technology, keeping disruption to daily work to a minimum.
Once the new procedures were in place, we trained all staff so everyone understood them and could follow them with confidence, with a focus on HIPAA compliance and protecting sensitive information. We stayed on afterward to resolve issues and make sure everything worked as intended.
The new director inherited a confusing mix of technology, policies, and procedures, with sensitive client data in the middle of it.
Something here raise a question about your own setup?
Thirty minutes, no slide deck. If you're in decent shape we'll tell you that.
Schedule a call