A year-round security program for healthcare
HIPAA expects ongoing risk management. We run the program calendar with you: assessment, policies, training, exercises, vendor reviews, and reporting.
Security as a program, not a project
Most practices buy a risk assessment, file the PDF, and forget it. We keep the work alive all year with a fixed calendar, a named advisor, and board-ready reporting.
A fixed calendar
Every quarter has a deliverable and a deadline. Risk assessment, policy refresh, tabletop exercise, and board reporting happen on schedule, not when someone remembers.
A named advisor
You get one person who knows your environment. Questions between milestones, payer questionnaires, and ad-hoc requests are part of the engagement.
Evidence that holds up
Risk analysis, risk management plan, policies, training records, and vendor reviews are organized so a regulator, payer, or insurer request takes hours, not weeks.
Board-ready reporting
Twice a year you receive a two-page summary: what changed, what is still open, and what it costs to close. No jargon, no panic.
The triggers we see most often
Insurance renewal
Cyber insurance carriers now ask for real evidence: risk assessment, policies, training, incident response. We build that evidence before renewal season.
OCR letter
An OCR inquiry or breach notification deadline exposes every gap at once. The annual program means the documentation is already current and the response is calm.
Board or payer pressure
Owners, boards, and payers want proof that security is managed, not hoped for. We give you a program and metrics they can read.
Breach scare or near miss
A phishing test, ransomware headline, or vendor incident makes it clear that once-a-year compliance is not enough. We turn the reaction into a plan.
Fixed fee, no surprises
The annual program is our flagship engagement. Pricing is simple and built around two clear steps.
- 1 annual reassessment, the Security Rule risk assessment as Quarter 1
- 4 quarterly check-ins
- Light async questions, capped at 4 hours per quarter
- Quarterly deliverables and board-ready reporting
Anything beyond that scope moves to the fractional CISO retainer at $4,000 to $12,000 per month, or to a fixed-fee add-on. The 4 hour quarterly cap is a hard cap, so nobody is guessing what is included.
Additional sites, remote workforces, and complex environments are priced on the scoping call.
Start with the assessment, stay for the year
The $12,000 assessment is not a separate product. It is Quarter 1 of the annual program and the foundation everything else is built on.
1. We map your real risk
The assessment finds breach risk, compliance gaps, privacy requirements, and the dollarized cost of inaction. That becomes the work plan.
2. We drive the urgent agreed gaps to closed
Before Quarter 2 begins, the top findings become an owned work plan. We work it with your IT team or MSP and verify the evidence as items land. They keep running the technology. We own the program, the priorities, and the verification.
3. The calendar keeps you ahead
Quarterly deliverables keep evidence current, so insurance renewals, OCR letters, and payer questionnaires stop feeling like emergencies.
What a year looks like
Every quarter has a deliverable and a date. Nothing waits until the week before a renewal.
Quarter 1
Annual HIPAA Security Rule risk assessment, findings report, and a remediation plan ranked by risk and effort.
Quarter 2
Policy and procedure refresh, workforce security training, and evidence collection you can hand to an auditor or payer.
Quarter 3
Incident response and business continuity tabletop, vendor and business associate review, and access recertification.
Quarter 4
Remediation verification, security metrics, and a board-ready summary of posture and next year's plan.
The parts that matter
Documentation that holds up
Risk analysis, risk management plan, policies, training records, and evidence organized so a payer or regulator request takes hours instead of weeks.
A named person to call
Questions between milestones are part of the program. When a client sends a security questionnaire, forward it to us.
Reporting leadership can read
Two pages your owners or board actually understand: what changed, what is still open, what it costs to close.
Continuous, not once a year
The Security Rule expects ongoing risk management. The calendar keeps that true without adding a full-time hire.
Annual program questions
See whether the annual program fits
A 30-minute scoping call covers your setup, your deadlines, and what a fixed-fee engagement would look like.