Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
Back to About
Alexander Perrin

The Builder · CEO

Alexander Perrin

Founder · SaaS Product Architect

LinkedIn
An entire industry was charging $2,000 a month for annual assessments and generic templates. The practices were paying for a certificate, not protection.

Alexander Perrin is the founder and Chief Executive Officer of Patient Protect. He assembled the team, designed the product architecture, and built the market positioning that separates Patient Protect from the documentation-first HIPAA compliance category — a decision grounded in the conviction that independent practices deserve real security infrastructure, not paperwork disguised as protection.

Before founding Patient Protect, he spent two decades in enterprise technology, with product and architecture responsibilities across SaaS, platform, and security categories. That background shaped the platform's design language: five connected systems, twenty operational workflows, and a compliance model that operates continuously rather than annually. The company's founding work began in 2015 under a DBA, with Patient Protect LLC formalized in 2018 out of Chicago, Illinois.

He is the primary author of Patient Protect's research program, published through the Secure Care Research Institute. His work includes The Economics of ePHI Exposure (SSRN #5257628) and the State of Compliance quarterly research series. The economics paper models the ten-year financial impact of healthcare data breaches on independent practices — including the finding that a 5,000-record breach at a mid-sized clinic with weak security generates between $4 million and $6 million in long-term impact when regulatory penalties, litigation, insurance changes, patient attrition, remediation, and downstream fraud are modeled together.

He writes and directs the Patient Protect editorial program, contributes to HIPAA Pulse coverage of OCR enforcement and breach economics, and represents the company in commentary on the structural disadvantage independent practices face against the same threat actors that target hospital systems.

Current focus

  • Patient Protect platform strategy and product direction
  • Secure Care Research Institute research program
  • HIPAA Pulse editorial direction and enforcement coverage
  • Vendor-category commentary and comparative HIPAA compliance analysis

Areas of expertise

  • Product strategy and platform architecture for HIPAA compliance software
  • Market positioning and competitive analysis in the HIPAA compliance category
  • HIPAA compliance economics and long-term breach financial modeling
  • Independent-practice operational risk and compliance program design
  • OCR enforcement pattern analysis and regulatory response modeling
  • Business Associate ecosystem strategy and vendor-risk framing
  • Research authorship and publication (Secure Care Research Institute)
  • Editorial direction of HIPAA Pulse and the Patient Protect research program

Credentials & experience

  • 20 Years — Enterprise Technology & SaaS Product Architectureprofessional experience
  • Founder — Patient Protect LLC (work began 2015 as DBA; LLC 2018)professional experience
  • Founder — Secure Care Research Instituteprofessional experience

Authored guides

Published by Alexander Perrin

35 guides on Patient Protect.

Best HIPAA compliance software for direct primary care practices in 2026
Compliance Operations·2026-08-11

Best HIPAA Compliance Software for Direct Primary Care (2026)

Direct primary care has a different HIPAA exposure profile — no third-party payer flow, membership-based patient relationships, longer continuous engagement, and concierge-style communication. The 5 features that distinguish DPC-fit compliance tools.

HIPAA compliance software vs HIPAA compliance platform - definitional and operational difference for independent practices
HIPAA Fundamentals·2026-07-28

HIPAA Software vs HIPAA Platform: What's the Real Difference? (2026)

Compliance software helps you document. A compliance platform enforces. The technical and operational gap between the two is the difference between a binder and a working program — and it determines whether the practice survives an OCR audit.

Best HIPAA compliant telehealth platforms comparison for independent practices in 2026
Compliance Operations·2026-07-21

Best HIPAA-Compliant Telehealth Platforms (2026)

Zoom for Healthcare, Doxy.me, Updox, SimplePractice, Spruce, Healthie — ranked for independent practices on BAA, encryption, EHR integration, and cost. The eight criteria that separate eligible from actually compliant.

Independent healthcare practice compliance work — the quiet failure mode of HIPAA at small practices
Compliance Operations·2026-07-21

The Quiet Failure of HIPAA in Independent Practices

HIPAA was designed for institutions with compliance departments, then applied unchanged to solo dentists and four-person therapy practices. The failure mode this produces is not dramatic — it accumulates quietly, and the industry has been solving the wrong problem.

DOJ 2026 $6.5B healthcare fraud takedown and the 120-day corporate self-disclosure window - what it means for independent practices
Compliance Operations·2026-07-13

The 120-Day Sprint: What DOJ's $6.5B Fraud Sweep Means for Independent Practices

In June 2026 the DOJ charged 455 defendants across a $6.5B healthcare fraud takedown. In March, DOJ published a first-ever department-wide Corporate Enforcement Policy with a 120-day self-disclosure window. Together they change how an independent practice must handle an internal compliance report.

HIPAA risk assessment cost breakdown for independent healthcare practices in 2026
Compliance Operations·2026-06-30

How Much Does a HIPAA Risk Assessment Cost? (2026)

HIPAA risk assessments range from $0 (HHS SRA Tool) to $25,000 (full consultant engagement). The honest breakdown by tier, what you actually get, and how to evaluate quotes.

Patient Protect platform walkthrough showing initial setup, dashboard overview, and first compliance actions
Product & Platform·2026-04-11

Your First Hour on Patient Protect

What happens when you sign up for Patient Protect. A minute-by-minute breakdown showing how architecture, guided setup, and acknowledgments cover ~70% of HIPAA requirements in under 60 minutes.

Warning illustration showing risks of healthcare staff using ChatGPT with unprotected patient data
Security & Threats·2026-03-19

Is ChatGPT HIPAA Compliant? Only With Covered Product + BAA

OpenAI signs BAAs for specific enterprise, healthcare, clinician, and API deployments — not for personal ChatGPT, ChatGPT Health, or ChatGPT Business. What that means for independent practices whose staff are already using it.

Cost analysis showing hidden compliance expenses burdening independent healthcare practices
Security & Threats·2025-11-09

The Hidden Tax on Independent Healthcare

Independent practices face a six-fold surge in cyberattacks and carry enterprise-grade compliance obligations with none of the infrastructure. Here is what that actually costs.

Patient rights framework showing access, amendment, and accounting obligations under HIPAA Privacy Rule
Compliance Operations·2025-09-30

Strengthen Patient Rights (Step 7 of 17)

Step 7: Provide PHI access, honor patient requests, track disclosures, and deliver Notice of Privacy Practices — the Privacy Rule in practice.