A letter arrived from the Office for Civil Rights
It is a deadline, not a verdict. What matters now is producing an organized, documented response on time.
Sound familiar?
- The letter asks for your risk analysis and you are not sure the current one qualifies
- Policies exist somewhere but nobody has updated them in a few years
- Training records are spread across email, a shared drive, and someone's memory
- The response window is measured in weeks and nobody owns it internally
How we help
Read the request with you
We go through each item OCR asked for and map it to what you already have, what needs rebuilding, and what has to be created.
Build the risk analysis
A written Security Rule risk analysis with a ranked remediation plan, the document these requests almost always center on.
Assemble the response package
Policies, training records, and evidence organized in the order the request lists them, with a cover summary your counsel can review.
Turnaround is 1 to 2 weeks for a typical single-site, remote risk analysis at $12,000 flat, with the response package assembled alongside it. If your deadline is tighter, say so on the call.
Start with the assessment. Stay with the annual program.
The $12,000 risk assessment
A complete picture in 1 to 2 weeks for a typical single-site, remote engagement: breach risk, compliance posture, privacy requirements, and the dollarized cost of inaction, with a ranked remediation plan.
The Annual Security Program, $24,000 a year
The assessment findings become a quarterly calendar of policy updates, training, vendor reviews, and board-ready reporting, so you can prepare for next year's deadline before it arrives.
Common questions
The OCR response checklist
The documents most commonly requested and how to organize them. Placeholder download.
Ready to talk?
A 30-minute scoping call covers your setup, your deadlines, and what a fixed-fee engagement would look like.