The challenge behind the engagement.
This service is for a covered entity or business associate that needs the risk analysis and documented safeguards the HIPAA Security Rule requires, which regulators look for first. We inventory every system that creates, receives, maintains, or transmits electronic health information: clinical records, billing, cloud file shares, email, backups, and connected medical devices, then map how it moves. We perform a formal risk analysis for each group of assets: the threats to it, the safeguards already in place, and the likelihood and impact if they fail. We assess your administrative, physical, and technical safeguards and note where each one stands. You receive the written risk analysis, a risk management plan, and the policy set. The proposed 2025 update remains only proposed; we prepare you for the rule in force today.
Compliance officers and IT leads at clinics, hospitals, health plans, and the software and billing companies that serve them as business associates, often after a customer BAA review, an OCR letter, or a ransomware incident put the risk analysis question on the table.
What we do.
What you can use.
Inventory ePHI and map where it moves
We confirm covered entity or business associate status, collect your business associate agreements, and build the asset inventory and data-flow map with your IT lead: the clinical record system and its interfaces, billing and clearinghouse connections, email and file-sharing services, backups, medical devices, and remote access. Any prior risk analyses and regulator correspondence are read first.
Analyze risk per asset group, then assess safeguards
For each asset group we document the threats, the safeguards already in place, and the likelihood and impact if they fail, then record a risk level the way federal guidance expects. We walk every administrative, physical, and technical safeguard the rule names and note whether each is fully implemented or handled with a documented, equivalent measure.
Deliver the binder OCR would ask for
You receive the written risk analysis, a risk management plan with owners and dates, a gap matrix by safeguard, policies with six-year retention, and a breach response procedure with the four-factor assessment and the 60-day notice clock. Everything is organized the way an OCR data request is, so it can be produced without a scramble.
Who it’s for.
When you need it.
- Healthcare covered entities such as clinics, hospitals, and health plans handling ePHI
- Business associates like billing, software, and clearinghouse vendors bound by a BAA
- Compliance officers who have never completed an enterprise-wide risk analysis
- Practices trusting an EHR vendor's HIPAA claims instead of their own analysis
- An OCR letter, complaint, or Risk Analysis Initiative inquiry has arrived
- A ransomware incident exposed gaps in safeguards and documentation
- A customer BAA review demands proof of a current risk analysis
- You are adopting a new EHR, telehealth platform, or connected medical device
What the scope can include.
- 01
ePHI asset inventory and data-flow map covering clinical records, billing, cloud file shares, email, backups, medical devices, and remote access
- 02
Enterprise-wide risk analysis documented per asset group, following federal risk analysis guidance
- 03
Gap assessment of every administrative, physical, and technical safeguard the Security Rule requires
- 04
Review of addressable safeguards for documented rationale and equivalent measures where full implementation is not used
- 05
Contingency plan, sanction policy, training records, and breach notification procedure checked against the rule
- 06
Optional technical validation of clinical-system access roles, encryption at rest and in transit, MFA coverage, and audit logging
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.
Practice of 1–10 providers or a small business associate, one location
About 30–60 hoursSeveral clinics or 50–250 staff, an electronic health record system plus several cloud apps and vendors
About 60–120 hoursHospital or multi-site health system with many systems and vendors
About 120–240 hours- Number of locations and whether on-site walkthroughs are needed
- Number of systems that store or touch patient information
- Number of vendors and business associate agreements
- Existing policies and prior risk analyses to build on
3–6 weeks for small practices; 2–3 months for multi-site organizations
HIPAA has no certification audit; annual risk analysis updates typically cost 40–60% of the initial assessment.
Get a fixed quote for your scopeRanges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Written risk analysis and risk register that an OCR investigator can follow from asset to risk level
- Risk management plan tying every risk to a treatment decision, owner, date, and evidence
- Gap matrix by safeguard, plus the policy set that closes it
- ePHI data-flow map, business associate inventory, and breach notification checklist in an OCR-style evidence binder
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
Is the 2025 proposed Security Rule update in effect yet?
No. The proposed rule was published in January 2025 and the comment period has closed. As of September 2026 it remains a proposal, and the current Security Rule applies, so we prepare you for the rule in force. That said, the proposals, which include a technology asset inventory and network map refreshed every twelve months, MFA and encryption with limited exceptions, regular penetration testing and vulnerability scanning, and fast restoration procedures, are a sensible roadmap, and we flag where you already meet them.
Is the free HHS risk-analysis tool enough for our risk analysis?
For a small practice it is a reasonable starting point. Regulators, however, expect an accurate and thorough analysis of every system that touches electronic health information, and recent enforcement settlements each cited a missing or incomplete enterprise-wide risk analysis. A questionnaire cannot inventory your clinical-system interfaces or medical devices for you. We build the asset-based analysis, and if you already have output from that tool we use it as one input rather than the deliverable.
- 2017 Trust Services Criteria (With Revised Points of Focus – 2022) | Resources | AICPA & CIMA
- The Security Rule | HHS.gov
- Guidance on Risk Analysis | HHS.gov
- NIST SP 800-66 Rev. 2: Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide
- PCI Data Security Standard (PCI DSS)
- New Information Supplement: PCI DSS Scoping and Segmentation Guidance for Modern Network Architectures
- ISO/IEC 27001:2022 - Information security management systems
