Skip to main content
Who we serve
  • Independent and multi-site medical practices
  • Dental, behavioral health, and specialty groups
  • Digital health and healthcare SaaS vendors
  • Billing companies and other business associates
Why teams pick us

Four things that make this different

Annual program

Compliance is a calendar, not a project. We build and run the program calendar with you, including the assessment, policy updates, training, and board-ready reporting. Your organization remains accountable for HIPAA compliance.

Flat-fee assessments

A HIPAA Security Rule risk assessment is $12,000 for a single site, delivered in 1 to 2 weeks for a typical single-site, remote engagement. You know the price and the date before we start.

Operator-led, not questionnaire-led

Led security at national healthcare companies, ran HITRUST r2 certifications, and reported to boards. The same standard, sized for your organization.

No shame, no checkbox theater

You will not be lectured. We tell you what is actually risky, what regulators expect, and what can wait until next year.

After the assessment

Start with the assessment, stay for the year

The $12,000 assessment is not a separate product. It is Quarter 1 of our Annual Security Program and the foundation everything else is built on.

  • What we map: We map breach risk, compliance posture, privacy requirements, and the dollarized cost of inaction. That becomes the work plan.
  • How gaps close: Before Quarter 2 begins, we drive the urgent agreed gaps to closed: an owned work plan, worked with your IT team or MSP, with evidence verified as items land. Your IT team or MSP keeps running the technology. We own the program, the priorities, and the evidence verification.
  • The year: The Annual Security Program continues on a fixed calendar at $24,000 per year prepaid, so insurance renewals, OCR requests, and payer questionnaires stop feeling like emergencies.
Before vs after

A checklist assessment checks a box. This one helps you run the practice.

Before: A typical compliance-only assessment

  • Security Rule checklist only
  • One-time PDF that sits on a shelf
  • Findings ranked by checkbox, not by actual risk
  • No estimate of what a breach would cost

After: What you get from us

  • Breach risk, compliance posture, privacy, and dollar-of-risk together
  • $12,000 flat, delivered in 1 to 2 weeks for a typical single-site, remote engagement
  • Ranked remediation plan with owners and timing
  • Evidence you can reuse for insurance, payers, and regulators
How it works

Three steps, no mystery

  1. 1

    Scoping call

    Thirty minutes. We cover your sites, systems, vendors, and any deadline pushing this forward. You leave with a scope and a price.

  2. 2

    Assessment and plan

    We review controls, interview the people who run them, and deliver a findings report with a prioritized remediation plan in plain English.

  3. 3

    Annual cadence

    Policies, training, tabletop exercises, vendor reviews, and reporting run on a schedule so next year starts ahead instead of behind.

What this looks like in practice

Three moments that bring teams to us

Client names and identifying details are withheld. Each statement below is a placeholder example, not a real testimonial.

Insurance renewal

A multi-site practice gathered current application answers, mapped each answer to supporting evidence, and turned unsupported controls into an owned work plan for its IT partner.

Placeholder example
OCR inquiry

A specialty group assembled a current risk analysis and organized evidence package inside the stated OCR response window, ready for counsel review.

Placeholder example
Peer comparison

A billing company compared its vendor oversight and training cadence with peers, documented the gaps, and placed the agreed updates on a quarterly program calendar.

Placeholder example
Tim Williams
Founder and principal consultant
CISSP · CRISC · CISA
Who you work with

You work directly with the person who ran these programs

Tim spent his career as a CISO at national healthcare companies, led HITRUST r2 certification efforts, and presented security posture to boards and audit committees. Every engagement is delivered by him, not handed to a junior analyst with a questionnaire.

FAQ

Questions we get first

Book a 30-minute scoping call

Bring your renewal date, your questionnaire, or just your questions. We will tell you what the work looks like and what it costs.

Book a scoping call