ESN

HIPAA

What does a HIPAA security risk assessment include?

A HIPAA Security Risk Assessment evaluates your organization against the HIPAA Security Rule and the NIST Cybersecurity Framework, and delivers a written report with prioritized findings, remediation guidance, and the documentation required for audit and insurance purposes. Mine is fixed scope and fixed price at $6,500, delivered in 10 business days.

$6,500 fixed
Delivered in 10 business days HIPAA Security Risk Assessment →

What actually gets reviewed

Administrative, physical, and technical safeguards, all three.

The assessment covers the three safeguard categories the HIPAA Security Rule requires: administrative (policies, training, access management), physical (facility and device security), and technical (encryption, access controls, audit logging). The output isn't a checklist score, it's a written report with findings ranked by actual risk, specific remediation guidance for each one, and the documentation you need to hand to an auditor or a cyber insurance carrier.

This is built by someone who ran HIPAA programs inside behavioral health and community health organizations, not a generic compliance checklist vendor. The findings reflect what actually gets asked in an audit and what actually gets exploited in an incident, not just what a template says to check.

Questions

Frequently asked questions

What does a HIPAA security risk assessment include?

An assessment against the HIPAA Security Rule and NIST Cybersecurity Framework, covering administrative, physical, and technical safeguards, delivered as a written report with prioritized findings, remediation guidance, and audit/insurance documentation.

How much does a HIPAA risk assessment cost?

$6,500 fixed, delivered in 10 business days.

Get started

Talk it through.

Tell me what's going on and I'll send back a written scope before anything is committed.

Start a conversation → See HIPAA Security Risk Assessment →