Security and HIPAA compliance support for practices and healthcare vendors.
Your carrier or broker wants a current risk assessment and a clear remediation plan. We deliver both in 1 to 2 weeks for a typical single-site, remote engagement, priced up front.
Learn moreYou need a fast, defensible picture of your Security Rule posture and a path forward. We respond within one business day.
Learn moreOur assessment looks at your risk through four lenses: patient, regulator, attacker, and peer. You get a ranked, dollarized plan instead of a checklist.
- Independent and multi-site medical practices
- Dental, behavioral health, and specialty groups
- Digital health and healthcare SaaS vendors
- Billing companies and other business associates
Four things that make this different
Annual program
Compliance is a calendar, not a project. We build and run the program calendar with you, including the assessment, policy updates, training, and board-ready reporting. Your organization remains accountable for HIPAA compliance.
Flat-fee assessments
A HIPAA Security Rule risk assessment is $12,000 for a single site, delivered in 1 to 2 weeks for a typical single-site, remote engagement. You know the price and the date before we start.
Operator-led, not questionnaire-led
Led security at national healthcare companies, ran HITRUST r2 certifications, and reported to boards. The same standard, sized for your organization.
No shame, no checkbox theater
You will not be lectured. We tell you what is actually risky, what regulators expect, and what can wait until next year.
Start with the assessment, stay for the year
The $12,000 assessment is not a separate product. It is Quarter 1 of our Annual Security Program and the foundation everything else is built on.
- What we map: We map breach risk, compliance posture, privacy requirements, and the dollarized cost of inaction. That becomes the work plan.
- How gaps close: Before Quarter 2 begins, we drive the urgent agreed gaps to closed: an owned work plan, worked with your IT team or MSP, with evidence verified as items land. Your IT team or MSP keeps running the technology. We own the program, the priorities, and the evidence verification.
- The year: The Annual Security Program continues on a fixed calendar at $24,000 per year prepaid, so insurance renewals, OCR requests, and payer questionnaires stop feeling like emergencies.
A checklist assessment checks a box. This one helps you run the practice.
Before: A typical compliance-only assessment
- Security Rule checklist only
- One-time PDF that sits on a shelf
- Findings ranked by checkbox, not by actual risk
- No estimate of what a breach would cost
After: What you get from us
- Breach risk, compliance posture, privacy, and dollar-of-risk together
- $12,000 flat, delivered in 1 to 2 weeks for a typical single-site, remote engagement
- Ranked remediation plan with owners and timing
- Evidence you can reuse for insurance, payers, and regulators
Three steps, no mystery
- 1
Scoping call
Thirty minutes. We cover your sites, systems, vendors, and any deadline pushing this forward. You leave with a scope and a price.
- 2
Assessment and plan
We review controls, interview the people who run them, and deliver a findings report with a prioritized remediation plan in plain English.
- 3
Annual cadence
Policies, training, tabletop exercises, vendor reviews, and reporting run on a schedule so next year starts ahead instead of behind.
Three moments that bring teams to us
Client names and identifying details are withheld. Each statement below is a placeholder example, not a real testimonial.
A multi-site practice gathered current application answers, mapped each answer to supporting evidence, and turned unsupported controls into an owned work plan for its IT partner.
A specialty group assembled a current risk analysis and organized evidence package inside the stated OCR response window, ready for counsel review.
A billing company compared its vendor oversight and training cadence with peers, documented the gaps, and placed the agreed updates on a quarterly program calendar.
You work directly with the person who ran these programs
Tim spent his career as a CISO at national healthcare companies, led HITRUST r2 certification efforts, and presented security posture to boards and audit committees. Every engagement is delivered by him, not handed to a junior analyst with a questionnaire.
Questions we get first
Book a 30-minute scoping call
Bring your renewal date, your questionnaire, or just your questions. We will tell you what the work looks like and what it costs.