Managed security and compliance for regulated small businesses — Kansas City metro and nationally · (913) 601-8810
Frequently Asked Questions

Questions about BoTech and compliance.

If your question is not here, call (913) 601-8810 or email Info@botechsecuritysolutions.com.

All BoTech bundles are priced at a flat monthly rate with no setup fees, no per-seat charges, and no surprise invoices. The rate listed in your service agreement is the rate on your invoice every month. Shield starts at $1,200/month, Comply at $1,100/month, and Fortress at $2,200/month. Final pricing depends on your organization's size, number of endpoints, and the compliance framework selected.
Shield covers managed security only — 24/7 monitoring, EDR, patch management, email security, and P1 incident response. Comply covers a full HIPAA or SOC 2 compliance program — risk assessment, all policies, BAA register, training, and monthly evidence tracking. Fortress combines both under one agreement at $2,200/month, which is less than the two bundles purchased separately. Most organizations with both security and compliance needs choose Fortress.
If you are a healthcare provider, health plan, or a business associate that transmits or stores electronic protected health information, HIPAA applies to you — no minimum threshold. If your enterprise clients, insurance carriers, or government contracts require evidence of security controls, SOC 2 is the framework they are requesting. Some organizations — particularly healthcare technology companies — need both. BoTech can help you determine which applies to your organization.
BoTech's standard timeline is 90 to 120 days from contract execution to audit-ready status. The four phases are: Assess (Days 1–14), Build (Days 15–30), Activate (Days 31–90), and Audit-Ready (Days 90–120). This timeline assumes client completion of information requests within 5 business days. Delays in client response extend the timeline proportionally.
Any person or organization that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is a business associate. This includes IT providers, managed security providers, EHR vendors, billing companies, cloud storage services, email providers, scheduling tools, and any other technology that touches patient data. Each one requires a signed Business Associate Agreement before you share ePHI access. BoTech builds and maintains your BAA register as part of the Comply and Fortress bundles.
P1 incidents are critical security events — ransomware, active breach, system-wide outage, or confirmed unauthorized access to ePHI. BoTech guarantees a one-hour response from a qualified responder for P1 incidents, 24/7. This commitment is included in writing in your service agreement — not as a goal, but as a contractual obligation. P2 (high) incidents receive a four-hour response. P3 (standard) incidents receive a one business day response.
No prior compliance work is required. The Assess phase at the beginning of every engagement starts from wherever your organization actually is — whether you have no documentation at all or a prior compliance program that needs updating. The gap analysis generates the specific list of what needs to be built, which becomes the work plan for the Build phase.
HIPAA implementation specifications are designated as either Required or Addressable. Required specifications must be implemented — no alternative. Addressable specifications must be implemented if they are reasonable and appropriate for your organization; if you decide not to implement one, you must document why and implement an equivalent alternative. 'Addressable' does not mean optional — an undocumented decision not to implement an addressable specification is treated by OCR as willful neglect.
BoTech Security Solutions is headquartered in Lee's Summit, Missouri — in the Kansas City metro. We serve healthcare practices, law firms, and financial services organizations throughout the Kansas City metro area, including Overland Park, Olathe, Lenexa, Shawnee, Independence, Blue Springs, Belton, Raytown, Liberty, and Leawood. BoTech delivers all services remotely, so every client receives the same responsiveness regardless of their specific location in the metro.
SOC 2 Type I is a point-in-time attestation — a CPA firm confirms your controls are designed correctly as of a specific date. Type II confirms your controls operated effectively over an observation period of at least six months. Enterprise clients, insurance carriers, and government contractors typically require Type II — not Type I. The observation period cannot be shortened, which makes starting early critical. BoTech configures evidence collection from day one so there are no gaps during the observation period.
BoTech's incident response plan activates immediately. For P1 events, a qualified responder is engaged within one hour. The response includes containment, investigation, and documentation. For HIPAA-covered organizations, BoTech works with you to conduct the four-factor breach assessment required under 45 CFR 164.402, determines notification obligations, and prepares the documentation required for any HHS or patient notification. Every incident is logged and documented regardless of whether it rises to a reportable breach.

Still have questions?

Contact BoTech directly. Response within one business day.

Or call (913) 601-8810