HIPAA Security Rule risk assessment, $12,000 flat
Quarter 1 of the Annual Security Program. One fixed fee buys a clear report across four dimensions, not just a checklist.
Where are the likely breach points? We map the people, systems, and vendors that could expose patient data.
Where do you stand against the HIPAA Security Rule? We identify gaps that regulators and payers ask about first.
What do your notices, consents, and workflows actually promise? We check where privacy obligations and practice reality diverge.
What does inaction cost? We estimate the financial impact so you can prioritize spending on what matters most. Planning estimates for prioritization, not an actuarial appraisal or coverage advice.
What it costs
Priced up front. No free assessments, no unpaid gap lists, no surprise hourly invoices.
Four ways we look at your environment
We examine your risk the way an outsider would: as a patient, a regulator, an attacker, and a peer. Each lens points to a different set of concrete findings.
Patient view
We look at your practice the way a patient would if they requested their records or filed a complaint. Common findings include missing access logs, unclear record-release workflows, and front-desk staff who are unsure how to verify identity. These are the gaps that turn a routine request into a privacy incident.
Regulator view
We review your documentation the way OCR or a state attorney general would during an inquiry. That means checking for an outdated risk analysis, missing required policies, and business associate agreements that do not match your actual vendor list. These are the documentation gaps OCR and state AGs commonly request early in an inquiry.
Attacker view
We trace the paths a low-skill attacker would actually use: stolen credentials, exposed remote access, and untracked devices. Typical findings include weak multi-factor authentication coverage, unmonitored vendor accounts, and old administrator passwords shared among staff. These are the controls that stop opportunistic breaches.
Peer view
We compare your controls against organizations of similar size and specialty, not against a theoretical ideal. We often find incident response plans that are shorter than peers expect, backup testing that lags the usual cadence, and training that does not cover phishing. These are the gaps that show up in payer questionnaires.
How the two weeks run
- 1
Kickoff
A short call to confirm scope, name the people we need for interviews, and set the delivery date.
- 2
Review and interviews
We examine administrative, physical, and technical safeguards, review documentation, and talk to the people who actually run the systems.
- 3
Report and readout
You get the written risk analysis, a ranked remediation plan, and a live walkthrough with your leadership team.
What you receive
- Written risk analysis mapped to the HIPAA Security Rule
- Findings ranked by likelihood, impact, and effort to fix
- Remediation plan with owners and suggested timing
- Executive summary written for non-technical readers
- Evidence index you can reuse for payer and client requests
Risk assessment questions
Start with the assessment, stay for the year
The $12,000 assessment is not a separate product. It is Quarter 1 of our Annual Security Program and the foundation everything else is built on.
- What we map: Breach risk, compliance posture, privacy requirements, and the dollarized cost of inaction. That becomes the work plan.
- How gaps close: Before Quarter 2 begins, we drive the urgent agreed gaps to closed: an owned work plan, worked with your IT team or MSP, with evidence verified as items land. Your IT team or MSP keeps running the technology. We own the program, the priorities, and the evidence verification.
- The year: The program continues on a fixed calendar at $24,000 per year prepaid, so next year starts ahead instead of behind.
Scope your assessment
A 30-minute scoping call covers your setup, your deadlines, and what a fixed-fee engagement would look like.