Verity MedSpa Compliance

The HIPAA program

Find the gaps. Fix them. Keep them fixed.

Most practices that handle patient information can say they are HIPAA compliant. Far fewer can hand someone the written program that proves it. Three steps, in order, priced to the size and complexity of the practice.

Step1

HIPAA Gap Analysis

We review what a practice handling protected health information is expected to have in writing — against the Security, Privacy and Breach Notification Rules, and the Massachusetts written information security program rules where they apply — and report what is missing, partial or out of date, ranked by priority and costed to fix.

  • A scored workbook: every requirement, its evidence, and its gap
  • A written report with findings ranked P1 to P3
  • A documentation inventory — what exists, what is a draft, what is absent
  • A readout with the owner, and a costed scope for Step 2

Timeline 2–4 weeksYour team 4–6 hours Fee $2,950 – $9,000 Fee fixed, quoted after the scoping call

A gap analysis is not a risk analysis.

We say this before anyone asks. A gap analysis measures you against the rule's requirements; it does not assess every risk to the confidentiality, integrity and availability of electronic patient information, and it is not a substitute for the risk analysis the Security Rule requires. That risk analysis is part of Step 2, and we will not let you believe otherwise.

OCR Cybersecurity Newsletter, April 2018 · verified 10 Sep 2026

Step2

Remediation & Implementation

The missing documents, drafted for your practice — not a template pack emailed as a zip file. We write them, you adopt them, and we keep the evidence that you did.

  • Policy and procedure set fitted to your service lines
  • Security risk analysis under the Security Rule
  • Vendor and business associate register, with the agreements executed
  • Incident response plan and breach decision tree
  • Workforce training with competency records
  • Written information security program (Massachusetts, and other states as needed)

Components are scoped from the gap analysis, so you buy what you are actually missing. We write the technical specification; your IT provider implements it and we hold them to it.

Timeline 6–12 weeks, in waves Typical package $12,000 – $23,000 Fee by component, quoted at the readout

Step3

The vCISO & vCPO Program

A compliance program that is not maintained is a folder of documents with last year's date on it. On a monthly retainer you get a named virtual Chief Information Security Officer and Chief Privacy Officer of record — the roles a practice this size cannot hire and increasingly cannot do without.

  • A calendar of recurring obligations, run for you
  • Monthly working session and an action register
  • Access reviews, vendor reviews, training cycles
  • Someone to call when something happens, before it becomes a notification decision
  • Regulatory change alerts for your states, with what they mean for you
  • Annual refresh and mock inspection

Term 12 months, monthly From $750 / month Fee monthly, by practice size

The gap analysis fee is credited in full against a twelve-month program signed within sixty days of your report. Groups of three or more locations are usually better served by a single all-in retainer than by three separate steps — we will say so if that is you.

What sets the price

Two single-site practices are not the same engagement, so they are not the same fee. On the scoping call we score nine things and the tier follows from the score, in front of you.

What we scoreWhy it moves the fee
Locations and statesEach site is its own walkthrough; each state adds its own security-program rules.
Workforce sizeTraining, access reviews and sanctions scale with headcount.
Systems holding patient informationEvery system is a vendor agreement, an access review and a backup question.
Service linesWeight management, hormone therapy and photography-heavy work carry more records and more consent.
Insurance billingBilling changes what the rules expect of you and how much of it applies.
IT environmentA managed Microsoft tenant is a different review from a mix of personal devices.
Ownership structureAn owner-operated practice decides faster than an investor-backed group.
Current documentationIf you already have some of it, you pay less. That is the whole point of measuring first.
A live eventA complaint, an incident, a carrier questionnaire or a sale under way changes the sequence.

We publish what sets the price rather than a price list, because the honest number depends on the answers above. You get a fixed fee in writing after a 30-minute call — not a range that moves later.

Thirty minutes, and you will know your number.

Bring your locations, your service lines, and whatever documentation you think you have. We will tell you which step you need and what it costs.