HIPAA Security Rule risk analysis

Document the risks to ePHI and the work required to reduce them.

A full cybersecurity assessment with the HIPAA Security Rule mapped into the evidence, findings, and remediation plan. Built for medical groups, dental groups, DSOs, and behavioral health organizations.

Book a 30-minute scope call

No patient records are needed for standard assessment activities.

Abstract grid of connected cybersecurity controls aligned into a unified compliance framework
  • 2–4 weeksTypical delivery window
  • All ePHISystems, locations, and vendors in scope
  • Evidence mappedConclusions tied to what was reviewed
  • Written planOwners, priorities, and next actions

Three letters can arrive any week.

01

OCR asks for it first

OCR’s Risk Analysis Initiative penalizes organizations for missing preparation, not for breach size. Small practices are on the list below. Nobody on it thought they’d be.

02

MIPS and insurers ask too

Eligible clinicians attest to the Security Risk Analysis measure, while insurers commonly ask for the date and scope of the latest analysis. The same evidence can support both processes, but each has its own requirements.

03

Old ones can hurt

An outdated analysis describing systems you no longer use proves you knew the requirement and let it lapse. Current beats perfect.

Best fit: healthcare providers, dental groups, behavioral health organizations, and business associates that need a current, organization-wide analysis of risks to ePHI.

Not the right fit: organizations seeking a private HIPAA certification, legal advice, MIPS attestation completion, or an assessment limited to one device while other ePHI systems remain out of scope.

What you get.

Included

  • Everything in the master assessment: scans, interviews, evidence, risk register
  • HIPAA Security Rule review, safeguard by safeguard
  • Evidence trail for every conclusion
  • MIPS Security Risk Analysis documentation support
  • Cyber-insurance application support
  • Executive report + 30/60/90 remediation roadmap
  • Scope, milestones, and delivery dates documented before kickoff

Example report structure

HW / HIPAA ANALYSISSafeguards and evidence
HighAccess to systems containing ePHIOwner set
MedVendor and BAA evidenceDue date
PlanContingency-plan validationTracked

Illustrative structure only. Your report is based on the systems, workflows, locations, vendors, and evidence in scope.

Discuss your HIPAA scope

How pricing works

Priced by scope. Fixed in writing.

There’s no rate card, because no two practices are the same size. Your quote is built from four things, then fixed in writing at the free 30-minute briefing, before any work starts.

Headcount

More staff means more interviews, more accounts with PHI access, and more evidence to review.

Locations

Each site adds physical safeguards review, network segments, and scheduling around clinic hours.

Systems

Your EHR, imaging and practice-management systems, and every vendor touching PHI add surface area to map and verify.

Modules

The HIPAA Security Rule module is standard here. Penetration testing or IR planning extend the scope if you want them.

Your proposal documents the work, locations, deliverables, assumptions, timing, and fees before kickoff. Any change to that scope requires written approval.

Separately scoped when needed

Penetration testing, remediation labor, onsite travel, new software, legal advice, and third-party certification or audit fees are not included unless they appear in your written proposal.

Three steps. Minimal disruption.

01

Private risk briefing (30 min, free)

We learn how your practice runs and give you an honest read, even if the honest read is “you’re in decent shape.” Then your exact scope and fixed price go in writing.

02

The assessment (2–4 weeks)

Scan-first: we map the network and check for exposures, then verify with your staff around patient hours. Your team’s total time: a few hours, without closing a single clinic day.

03

Report, roadmap & follow-through

A leadership walkthrough in plain English, a sequenced plan your IT or MSP can execute, and an evidence file built around the requirements HHS tells regulated entities to document.

What the official guidance actually requires.

HHS describes risk analysis as foundational and ongoing. It must cover all ePHI, document threats and vulnerabilities, assess likelihood and impact, and feed a risk-management process. No single assessment method guarantees compliance.

Sources last reviewed August 27, 2026. This page is general information, not legal advice.

Healthcare leaders describe practical, usable work.

Heartland Dental
Some of the recommendations were simple, but they needed ownership. Their follow-up helped us assign that ownership and keep the remediation work from disappearing behind the next project.
Robert J.Senior Vice President, Chief Digital Officer
American Addiction Centers
We needed a security assessment that understood behavioral-health data and clinical operations. The advisors kept the conversation grounded and focused us on the risks that mattered most.
Sumit S.Chief Information Officer

Questions we hear about this service.

Book your HIPAA scope call.

Thirty minutes with an advisor.

We’ll cover your locations, EHR and supporting systems, current deadline, and the evidence already available. You’ll leave knowing the likely scope, timing, and next step.

Prefer phone or email?

(754) 216-9664 info@hardenwell.com

Do not include PHI or sensitive records in booking notes. See our Privacy Policy.

Book a call