Skip to main content
Flagship program

A year-round security program for healthcare

HIPAA expects ongoing risk management. We run the program calendar with you: assessment, policies, training, exercises, vendor reviews, and reporting.

What it is

Security as a program, not a project

Most practices buy a risk assessment, file the PDF, and forget it. We keep the work alive all year with a fixed calendar, a named advisor, and board-ready reporting.

A fixed calendar

Every quarter has a deliverable and a deadline. Risk assessment, policy refresh, tabletop exercise, and board reporting happen on schedule, not when someone remembers.

A named advisor

You get one person who knows your environment. Questions between milestones, payer questionnaires, and ad-hoc requests are part of the engagement.

Evidence that holds up

Risk analysis, risk management plan, policies, training records, and vendor reviews are organized so a regulator, payer, or insurer request takes hours, not weeks.

Board-ready reporting

Twice a year you receive a two-page summary: what changed, what is still open, and what it costs to close. No jargon, no panic.

Why teams start now

The triggers we see most often

Insurance renewal

Cyber insurance carriers now ask for real evidence: risk assessment, policies, training, incident response. We build that evidence before renewal season.

OCR letter

An OCR inquiry or breach notification deadline exposes every gap at once. The annual program means the documentation is already current and the response is calm.

Board or payer pressure

Owners, boards, and payers want proof that security is managed, not hoped for. We give you a program and metrics they can read.

Breach scare or near miss

A phishing test, ransomware headline, or vendor incident makes it clear that once-a-year compliance is not enough. We turn the reaction into a plan.

Pricing

Fixed fee, no surprises

The annual program is our flagship engagement. Pricing is simple and built around two clear steps.

Step 1
Risk assessment
$12,000
Flat fee for a single site. Not a separate product. It is Quarter 1 of the annual program and the foundation everything else is built on.
Step 2
Annual program
$24,000/yr
Billed annually up front. Light continuity, not a fractional CISO retainer.
What the $24,000 includes
  • 1 annual reassessment, the Security Rule risk assessment as Quarter 1
  • 4 quarterly check-ins
  • Light async questions, capped at 4 hours per quarter
  • Quarterly deliverables and board-ready reporting

Anything beyond that scope moves to the fractional CISO retainer at $4,000 to $12,000 per month, or to a fixed-fee add-on. The 4 hour quarterly cap is a hard cap, so nobody is guessing what is included.

Additional sites, remote workforces, and complex environments are priced on the scoping call.

From assessment to program

Start with the assessment, stay for the year

The $12,000 assessment is not a separate product. It is Quarter 1 of the annual program and the foundation everything else is built on.

1. We map your real risk

The assessment finds breach risk, compliance gaps, privacy requirements, and the dollarized cost of inaction. That becomes the work plan.

2. We drive the urgent agreed gaps to closed

Before Quarter 2 begins, the top findings become an owned work plan. We work it with your IT team or MSP and verify the evidence as items land. They keep running the technology. We own the program, the priorities, and the verification.

3. The calendar keeps you ahead

Quarterly deliverables keep evidence current, so insurance renewals, OCR letters, and payer questionnaires stop feeling like emergencies.

The calendar

What a year looks like

Every quarter has a deliverable and a date. Nothing waits until the week before a renewal.

Quarter 1

Annual HIPAA Security Rule risk assessment, findings report, and a remediation plan ranked by risk and effort.

Quarter 2

Policy and procedure refresh, workforce security training, and evidence collection you can hand to an auditor or payer.

Quarter 3

Incident response and business continuity tabletop, vendor and business associate review, and access recertification.

Quarter 4

Remediation verification, security metrics, and a board-ready summary of posture and next year's plan.

What is included

The parts that matter

Documentation that holds up

Risk analysis, risk management plan, policies, training records, and evidence organized so a payer or regulator request takes hours instead of weeks.

A named person to call

Questions between milestones are part of the program. When a client sends a security questionnaire, forward it to us.

Reporting leadership can read

Two pages your owners or board actually understand: what changed, what is still open, what it costs to close.

Continuous, not once a year

The Security Rule expects ongoing risk management. The calendar keeps that true without adding a full-time hire.

4 deliverables
One per quarter, scheduled up front
1 to 2 weeks for a typical single-site, remote engagement
Risk assessment turnaround
2 pages
Board summary, twice a year
FAQ

Annual program questions

See whether the annual program fits

A 30-minute scoping call covers your setup, your deadlines, and what a fixed-fee engagement would look like.

Book a scoping call