Apgar and Associates, LLC | Privacy, Security, Risk Management logo
Select Partner

Apgar and Associates, LLC | Privacy, Security, Risk Management

Healthcare privacy, security, and compliance consulting specialists

Portland, Oregon, United States
1-10 employees
Verified
3 Certs

About Apgar and Associates, LLC | Privacy, Security, Risk Management

Apgar & Associates, LLC is a Portland, Oregon-based consulting firm specializing in healthcare privacy, security, and regulatory compliance. Led by President & CEO Chris Apgar, who serves on the Health Sector Coordinating Council's Joint Cybersecurity Working Group on behalf of AHIMA, the firm works with hospitals, health systems, digital health vendors, and business associates navigating HIPAA, HITECH, and other healthcare compliance requirements.

The firm provides security risk analysis, compliance program development, policies and procedures documentation, security incident response planning, and certification readiness services for HITRUST, SOC 2, and ISO 27001. As a designated HITRUST Readiness Licensee since October 2022, Apgar & Associates offers structured preparation for organizations pursuing formal certifications. Their approach emphasizes comprehensive security risk assessments, evidence collection frameworks, and actionable remediation strategies.

The firm has responded to OCR investigations, supported breach response efforts, and helped business associates demonstrate compliance to healthcare clients. They maintain an active thought leadership presence addressing topics including network segmentation requirements, cybersecurity performance goals (CPGs), remote work security, and ransomware incident classification.

Best For

Healthcare organizations and business associates needing structured compliance consulting for HIPAA Security Rule requirements, particularly those preparing for HITRUST certification, responding to OCR investigations, or implementing security incident response programs. Well-suited for digital health vendors scaling operations and health systems strengthening existing compliance frameworks.

Key Strengths

  • HITRUST Readiness Licensee designation with structured certification preparation methodology
  • Leadership participation in HSCC Joint Cybersecurity Working Group demonstrates industry engagement and current knowledge
  • Demonstrated OCR investigation response experience with healthcare providers
  • Comprehensive security risk analysis approach aligned with ISO 27001 and HIPAA Security Rule requirements
  • Specific expertise helping business associates demonstrate compliance to healthcare clients
  • Regular thought leadership on evolving topics like NPRM changes and CPG implementation

Why Choose Apgar and Associates, LLC | Privacy, Security, Risk Management

Choose Apgar & Associates when you need methodical, compliance-focused consulting from practitioners with direct healthcare industry involvement. Their HITRUST Readiness Licensee status and HSCC participation suggest current knowledge of evolving healthcare security standards and regulatory expectations.

Expect a structured approach to security risk analysis, evidence-based gap remediation, and documentation development that supports both day-to-day compliance operations and formal certification pursuits. Their experience with OCR investigations indicates familiarity with regulatory scrutiny scenarios.

Healthcare Focus

Apgar & Associates focuses exclusively on healthcare sector privacy and security compliance. Their expertise centers on HIPAA Security and Privacy Rules, OCR enforcement patterns, and healthcare-specific certification frameworks including HITRUST. The firm addresses healthcare business associate compliance requirements, PHI breach response protocols, and telehealth security considerations. Their leadership's AHIMA representation and HSCC participation demonstrates sustained commitment to healthcare industry standards evolution and cybersecurity coordination specific to the healthcare and public health sector.

Ideal Client Profile

Mid-sized healthcare providers, health systems, and business associates with 50-500 employees seeking to strengthen existing compliance programs or prepare for formal certifications. Digital health companies scaling operations who need to demonstrate security maturity to healthcare clients. Organizations facing OCR investigations requiring experienced compliance response support.

Specializations

HIPAA compliance consulting HITRUST certification readiness SOC 2 preparation ISO 27001 readiness Security risk analysis Security incident response Healthcare privacy programs

Client Types

Hospitals Health Systems Digital Health Healthcare Startups

Why Choose Apgar and Associates, LLC | Privacy, Security, Risk Management?

  • 1-10 team members
  • 3 certifications verified
  • Select Partner on Curatrix
  • Verified on Curatrix

Quick Facts

Headquarters
Portland, Oregon, United States
Company Size
1-10 employees

Certifications

hitrust soc 2 iso 27001

Profile last updated: Jan 26, 2026

Suggest a correction

Need help evaluating healthcare partners?

Our team can help you find the right provider for your specific needs.

Get Guidance

Looking for similar providers?

Browse our curated directory of pre-vetted healthcare B2B service providers.