OCR asks for it first
OCR’s Risk Analysis Initiative penalizes organizations for missing preparation, not for breach size. Small practices are on the list below. Nobody on it thought they’d be.
HIPAA Security Rule risk analysis
A full cybersecurity assessment with the HIPAA Security Rule mapped into the evidence, findings, and remediation plan. Built for medical groups, dental groups, DSOs, and behavioral health organizations.
No patient records are needed for standard assessment activities.
OCR’s Risk Analysis Initiative penalizes organizations for missing preparation, not for breach size. Small practices are on the list below. Nobody on it thought they’d be.
Eligible clinicians attest to the Security Risk Analysis measure, while insurers commonly ask for the date and scope of the latest analysis. The same evidence can support both processes, but each has its own requirements.
An outdated analysis describing systems you no longer use proves you knew the requirement and let it lapse. Current beats perfect.
Best fit: healthcare providers, dental groups, behavioral health organizations, and business associates that need a current, organization-wide analysis of risks to ePHI.
Not the right fit: organizations seeking a private HIPAA certification, legal advice, MIPS attestation completion, or an assessment limited to one device while other ePHI systems remain out of scope.
Included
Example report structure
Illustrative structure only. Your report is based on the systems, workflows, locations, vendors, and evidence in scope.
Discuss your HIPAA scopeHow pricing works
There’s no rate card, because no two practices are the same size. Your quote is built from four things, then fixed in writing at the free 30-minute briefing, before any work starts.
More staff means more interviews, more accounts with PHI access, and more evidence to review.
Each site adds physical safeguards review, network segments, and scheduling around clinic hours.
Your EHR, imaging and practice-management systems, and every vendor touching PHI add surface area to map and verify.
The HIPAA Security Rule module is standard here. Penetration testing or IR planning extend the scope if you want them.
Your proposal documents the work, locations, deliverables, assumptions, timing, and fees before kickoff. Any change to that scope requires written approval.
Separately scoped when needed
Penetration testing, remediation labor, onsite travel, new software, legal advice, and third-party certification or audit fees are not included unless they appear in your written proposal.
We learn how your practice runs and give you an honest read, even if the honest read is “you’re in decent shape.” Then your exact scope and fixed price go in writing.
Scan-first: we map the network and check for exposures, then verify with your staff around patient hours. Your team’s total time: a few hours, without closing a single clinic day.
A leadership walkthrough in plain English, a sequenced plan your IT or MSP can execute, and an evidence file built around the requirements HHS tells regulated entities to document.
HHS describes risk analysis as foundational and ongoing. It must cover all ePHI, document threats and vulnerabilities, assess likelihood and impact, and feed a risk-management process. No single assessment method guarantees compliance.
Sources last reviewed August 27, 2026. This page is general information, not legal advice.
Some of the recommendations were simple, but they needed ownership. Their follow-up helped us assign that ownership and keep the remediation work from disappearing behind the next project.
We needed a security assessment that understood behavioral-health data and clinical operations. The advisors kept the conversation grounded and focused us on the risks that mattered most.
No. We do not require patient information for standard assessment activities. Clients redact patient identifiers before submitting evidence.
The assessment supports the Security Risk Analysis measure by documenting the analysis and resulting risk-management work. It does not complete every Promoting Interoperability requirement, and your clinician or practice remains responsible for its attestation. Review the current CMS measure specification with your MIPS advisor.
Shared systems are assessed once; locations are sampled on-site. You get one report with per-site findings, which is what a DSO or multi-site group actually needs. The multi-site scope is priced into the fixed quote up front.
No, but move now, and talk to a healthcare attorney first. We work quickly alongside your counsel to build the security documentation that answers the request. What we can’t do is backdate anything. No one honest can.
No. HHS does not endorse or recognize private HIPAA certification as proof of compliance. You receive a documented risk analysis and remediation record; the engagement does not guarantee a regulator’s conclusion.
We’ll cover your locations, EHR and supporting systems, current deadline, and the evidence already available. You’ll leave knowing the likely scope, timing, and next step.
Prefer phone or email?
(754) 216-9664 info@hardenwell.com
Do not include PHI or sensitive records in booking notes. See our Privacy Policy.