AI is arriving inside the tools your practice already uses.
Scribes in the EHR. Assistants in the phone system. Staff pasting into chatbots. Each one is a patient-data decision, and most practices have no record of who approved what, or on what basis. Velari's one-week sprint turns that into evidence an owner, MSP, or insurer can actually use.
Payments vendorNew AI answering featureAI terms unclear
Microsoft 365Email & file sharingMFA gap
Former contractorAccess from 2023Offboard
Evidence-backed
Section 04
30 / 60 / 90 roadmap
owner · MSP · vendor
30NowMFA everywhere; kill stale access
60NextBAA cleanup; AI attestation signed
90ThenDowntime tabletop; logging review
Owner-ready
Sample deliverables — click to flip through the packet
Why this exists
Nobody bought an AI strategy. It shipped anyway.
AI isn't arriving at small practices as a big procurement decision. It arrives as a button that appeared overnight, and every button is a patient-data decision someone should be able to explain later.
Inside the EHR
Ambient scribes and note assistants are being bundled straight into the EHRs small practices already run. Turning one on takes a click; the vendor's retention and training terms take longer to read.
Who approved it, and what did they check?
Inside your vendors
Phone systems, patient messaging, payments, and scheduling platforms are shipping AI answering and drafting features as routine product updates, often on by default and rarely re-vetted by anyone.
Does the BAA you signed cover the feature they added?
In the browser
Staff under time pressure paste referral letters, visit notes, and billing questions into free chatbots because it helps. Without written rules, every paste is an unrecorded disclosure decision.
What are staff allowed to paste, and where is that written?
The sprint
One week. Six passes over how patient data actually moves.
Fixed scope, fixed fee, and a hard boundary: no patient charts, no PHI uploads, no software installed. Everything works from how your systems and vendors are set up, not what's inside them.
01
AI tools & features
Every AI touchpoint gets inventoried with its data flow: tools in use, features being pitched by your vendors, and the ones staff quietly tried.
You keep: AI inventory & risk cards02
Patient data outside the EHR
Email, web forms, billing exports, shared drives, texting, phones, and backups, all mapped so exposure has an address.
You keep: data-flow map03
Vendors & BAAs
Which vendors touch patient data, what the paperwork actually covers, and what to send each one that falls short.
You keep: vendor gap list04
Access, MFA & logging
Who can reach what, which accounts outlived their purpose, and whether the logs would support an investigation.
You keep: access review notes05
Outside-in exposure
Your domain, email security, and public web surface, checked passively. It's the view an attacker or insurer gets first.
You keep: exposure summary06
Downtime & fallback
A short tabletop: systems go down Tuesday morning. Who does what, who can disable an AI tool, and how does care continue?
You keep: downtime one-pager
What you receive
A packet that answers questions before they're asked.
Every deliverable is written to be handed to someone: your MSP, your insurer, a reviewer, or the next owner. Nothing requires you to log into a platform. It's yours, locally, forever.
Executive summary10-minute owner read
AI tool inventory & risk cardsper tool
Patient-data-flow mapbeyond the EHR
Vendor & BAA evidence reviewgaps named
Staff AI use attestationready to sign
External exposure summarypassive checks
Downtime & fallback one-pagerfirst hours
Evidence binder indexwhat lives where
30/60/90 roadmapowner · MSP · vendor
Owner–MSP handoff sheetdecisions & asks
How the week runs
Concrete from the first call.
Before day 1
15-minute fit check
Practice size, systems, vendors, what prompted the call. If the sprint isn't the right fix, you'll hear it here, free.
Day 1
No-PHI intake
A structured intake with the owner or office manager: system list, vendor list, AI tools in play, and the evidence boundary in writing.
Days 2–3
Mapping and review
Data flows, vendor and BAA evidence, AI features, access and MFA, and passive external checks, documented as they're found.
Day 4
Downtime tabletop
A one-hour scenario with the people who'd actually be in the room. It surfaces the gaps no questionnaire finds.
Day 5
Readout and handoff
A plain-English walkthrough with the owner, the full packet delivered, and the 30/60/90 plan agreed, including what goes to the MSP.
Who this is for
Owner-led practices. One to eight locations. No security hire.
If you have an EHR, an MSP or part-time IT, a stack of vendor logins, and a nagging feeling about AI, then this was built for you.
The EHR started offering an AI scribe and nobody knows who should say yes.
The cyber-insurance questionnaire arrived and the honest answers are guesses.
You're changing MSPs and want an independent picture before the handoff.
A vendor renewal or BAA cleanup is overdue and nobody owns it.
A near miss: a phish that almost worked, or an outage that almost hurt.
The honest part
What Velari is not.
Small practices get sold a lot of fear and a lot of stamps. This is neither.
Not a certification
Nothing here "certifies you HIPAA compliant," because no honest service can. You get evidence and a defensible record, not a sticker.
Not a data grab
No patient charts, no PHI uploads, no installed agents. If someone selling you security wants your patient data first, ask them why.
Not a replacement for your MSP
Your MSP keeps running IT. The sprint hands you both a prioritized, independent list they can execute against.
Not legal advice
Readiness and evidence support, not legal opinions, breach determinations, or penetration testing. Counsel stays counsel.
And if a $2,500 sprint isn't the right fix for your situation, you'll hear that in the first fifteen minutes.
Who you're emailing
Velari is Noah Mills. The work is public.
I'm a St. Louis-based healthcare security practitioner. Before you spend a dollar, you can read the actual tools and methods this sprint is built on. They're published openly, with sanitized examples, so the work makes the case instead of a brochure.
Do you need access to our systems or patient data?
No. The sprint works from structured interviews, your vendor and system list, documentation you already have, and passive external checks. No patient charts, no PHI uploads, no software installed, no credentials handed over.
Is this a HIPAA certification or a formal Security Risk Analysis?
No, and be wary of anyone selling one. There is no such thing as an official "HIPAA certified" stamp. The sprint produces organized evidence and a prioritized plan that make a formal risk analysis, an insurance renewal, or a reviewer conversation dramatically easier.
We already have an MSP. Why would we need this?
Your MSP runs the systems; almost nobody is watching the seams between them: vendor AI features, BAAs, data in web forms and texting, staff chatbot use. The sprint maps those seams and hands your MSP a concrete, prioritized list. MSPs generally like it: it turns vague worry into tickets.
Why a fixed fee?
Because an owner should be able to approve this in one conversation. $2,500, one week, defined deliverables, no meter running. If your situation needs less than a sprint, you'll be told that on the fit check instead of being sold one.
What happens after the sprint?
The packet is yours either way. Most practices run the 30/60/90 plan with their MSP on their own. If you want continuity, there's an ongoing option with quarterly reviews, vendor-change checks, and a standing contact, described on the sprint page. No pressure baked in.
Start here
Start with fifteen minutes.
One call: practice size, systems, vendors, AI tools in play, and whether the sprint is the right next step. If it isn't, you'll leave with a straight answer and a free checklist anyway.