
What are Common HIPAA Security Violations?
Most HIPAA problems do not come from a single dramatic breach. They come from small
Not sure where to start? Schedule a consultation
Not sure where to start? Schedule a consultation
Not sure where to start? Schedule a consultation
AI is only as secure as the data and permissions behind it.
Our AI data readiness and security governance service reviews where your company data lives, who already has access to it, and whether sensitive information is protected. We then correct the permissions and security issues before AI makes that information easier to find.
This is the access and classification work, not the business case. If you are still deciding whether AI is worth it and where to point it, start with our AI Readiness Assessment & Strategy engagement.
AI assistants like Microsoft 365 Copilot work inside the permissions your users already have. They do not create new access. They remove the effort that used to keep badly permissioned files buried.
Finding a misfiled payroll spreadsheet used to require guessing the right site, then the right library, then the right file name. Now a plain English question can return it in one pass.
The gaps that surface are usually years old:
None of this is an AI problem. It is a permissions problem that AI makes visible.
IBM’s breach research is blunt about where AI incidents actually originate. Organizations breached through an AI tool overwhelmingly lacked adequate access controls, and most had no policy governing AI use at all. The current figures are on the cost of getting AI adoption wrong.
The breach rarely starts with the AI model. It starts with weak access controls and unclassified data. The governance side is covered in our AI governance program, and the wider access layer in our AI infrastructure consulting work.
We look at four things, in this order.
SharePoint, OneDrive, Teams, Exchange, on-premises file servers, and the line-of-business applications your team uses every day. Most organizations have more locations than their documentation shows.
A full permissions audit across your tenant:
We identify where PHI, CUI, financial records, HR files, client data, and contracts are stored, then check whether classification, labeling, and encryption are actually applied to them.
Your acceptable use policy for AI, your approved tool list, your review and approval process, your audit logging, and whether anyone owns the ongoing work.
You receive a written report with findings ranked by risk, a remediation plan, and a clear answer on whether your environment is safe to turn AI on.
We start with a conversation about which AI tools you are using or about to deploy, which contracts and regulations apply to you, and which sites and systems those tools will be allowed to reach. This determines the depth of the review.
We run the technical assessment across your Microsoft 365 tenant and connected systems. This is where the permissions audit, data location mapping, and sensitive data discovery happen.
Typical timing: one to three weeks, depending on tenant size and the number of systems in scope.
You get a report written for decision-makers, not just administrators. Every finding is ranked by risk and effort, so you know what has to be fixed before rollout and what can be handled over the following quarter.
We do the correction work:
Typical timing: scoped separately, based on what the review finds.
Permissions drift. New sites get created, projects end, people change roles.
We put an AI governance framework in place, document your policies, train your staff, and run recurring access reviews so the environment stays in the condition we left it. Those reviews run on a schedule under managed AI services.
Typical timing: quarterly or semiannual access reviews, depending on how fast your environment changes.
Healthcare providers and practices. PHI in SharePoint and Teams needs classification and access limits before any AI tool indexes it. See our HIPAA security compliance support.
Defense contractors and manufacturers. Commercial Microsoft 365 tenants are not authorized for CUI, and public AI tools are not appropriate for export-controlled information. The FY2026 NDAA directs the Department of Defense to build an AI security framework into DFARS and CMMC, as C3PAO assessors have noted, so this is moving from best practice to requirement. Businesses near Fort Leavenworth and across the defense supply chain should scope this now.
Accounting and financial services firms. Client financial records, tax documents, and engagement files carry confidentiality obligations that do not pause for an AI rollout. Common across Leawood and Overland Park professional offices.
Public sector and government-adjacent organizations. Records retention, open records exposure, and audit requirements all apply to AI prompts and outputs. Relevant for agencies and insurers in Topeka.
Law firms and professional services. Privileged material and client matter separation depend entirely on permissions being correct.
AI data readiness is not a standalone project. It touches most of what we already manage:
If MDL already provides your Kansas City managed IT services, much of the discovery is already done.
AI data readiness means your company data is organized, classified, and permissioned correctly before AI tools can access it. It covers knowing where sensitive information lives, confirming who has access, and applying protection so AI does not surface something to the wrong person.
Copilot only accesses what the individual user already has permission to open. The risk is that most employees can access far more than anyone realizes, and Copilot makes that content easy to find in seconds.
The fastest indicator is whether you can answer who has access to your most sensitive folders right now, and whether those folders are labeled. If either requires guessing or a manual check, a permissions audit is the right starting point.
This service is the execution work: the permissions audit, the labeling, the correction, and the recurring access reviews. The AI readiness assessment & strategy engagement is the decision work, covering the business case, the use cases, and the roadmap. If you already know you are deploying AI and just need the environment safe, this is the right page.
The review itself typically runs one to three weeks. Remediation is scoped separately once we know what the review found. Ongoing access reviews then run on a recurring schedule, usually quarterly or semiannually.
Only with a clear policy, an approved tool list, and technical controls that prevent sensitive data from being pasted into unapproved tools. Without those, you have shadow AI, which IBM’s 2026 breach report ties to 43% of breached organizations.
Yes. Commercial Microsoft 365 tenants are not authorized for CUI, so contractors handling controlled information typically need a properly configured GCC High environment with documented controls. The AI tool also has to appear in your System Security Plan.
Yes, when the vendor is covered by a Business Associate Agreement and the environment is configured with proper access controls, labeling, and audit logging. Compliance depends on how the tool is set up and governed rather than on the product itself.
Pricing depends on your user count, the number of systems in scope, and your compliance obligations. MDL builds a custom proposal after an initial scoping conversation so you know exactly what is included.
No. Findings are prioritized by risk, and many organizations start with a limited pilot group while higher-risk items are corrected. The goal is a safe starting point, not perfection on day one.
Before AI can safely use your company data, you need to know who already has access to it. That answer is worth having before the rollout, not after.
MDL Technology serves businesses throughout Kansas and Missouri, including Kansas City, Overland Park, Lee’s Summit, Lenexa, Olathe, and North Kansas City. View our full service area.
Talk to MDL Technology today and get a clear, prioritized plan for AI data readiness and security governance built around how your business actually runs.

Most HIPAA problems do not come from a single dramatic breach. They come from small
Every organization that handles patient data is expected to protect it, and the rules for

Most email attacks succeed because a business chooses protection that does not match its actual