The HIPAA program
Find the gaps. Fix them. Keep them fixed.
Most practices that handle patient information can say they are HIPAA compliant. Far fewer can hand someone the written program that proves it. Three steps, in order, priced to the size and complexity of the practice.
Step1
HIPAA Gap Analysis
We review what a practice handling protected health information is expected to have in writing — against the Security, Privacy and Breach Notification Rules, and the Massachusetts written information security program rules where they apply — and report what is missing, partial or out of date, ranked by priority and costed to fix.
- A scored workbook: every requirement, its evidence, and its gap
- A written report with findings ranked P1 to P3
- A documentation inventory — what exists, what is a draft, what is absent
- A readout with the owner, and a costed scope for Step 2
A gap analysis is not a risk analysis.
We say this before anyone asks. A gap analysis measures you against the rule's requirements; it does not assess every risk to the confidentiality, integrity and availability of electronic patient information, and it is not a substitute for the risk analysis the Security Rule requires. That risk analysis is part of Step 2, and we will not let you believe otherwise.
OCR Cybersecurity Newsletter, April 2018 · verified 10 Sep 2026Step2
Remediation & Implementation
The missing documents, drafted for your practice — not a template pack emailed as a zip file. We write them, you adopt them, and we keep the evidence that you did.
- Policy and procedure set fitted to your service lines
- Security risk analysis under the Security Rule
- Vendor and business associate register, with the agreements executed
- Incident response plan and breach decision tree
- Workforce training with competency records
- Written information security program (Massachusetts, and other states as needed)
Components are scoped from the gap analysis, so you buy what you are actually missing. We write the technical specification; your IT provider implements it and we hold them to it.
Step3
The vCISO & vCPO Program
A compliance program that is not maintained is a folder of documents with last year's date on it. On a monthly retainer you get a named virtual Chief Information Security Officer and Chief Privacy Officer of record — the roles a practice this size cannot hire and increasingly cannot do without.
- A calendar of recurring obligations, run for you
- Monthly working session and an action register
- Access reviews, vendor reviews, training cycles
- Someone to call when something happens, before it becomes a notification decision
- Regulatory change alerts for your states, with what they mean for you
- Annual refresh and mock inspection
The gap analysis fee is credited in full against a twelve-month program signed within sixty days of your report. Groups of three or more locations are usually better served by a single all-in retainer than by three separate steps — we will say so if that is you.
What sets the price
Two single-site practices are not the same engagement, so they are not the same fee. On the scoping call we score nine things and the tier follows from the score, in front of you.
| What we score | Why it moves the fee |
|---|---|
| Locations and states | Each site is its own walkthrough; each state adds its own security-program rules. |
| Workforce size | Training, access reviews and sanctions scale with headcount. |
| Systems holding patient information | Every system is a vendor agreement, an access review and a backup question. |
| Service lines | Weight management, hormone therapy and photography-heavy work carry more records and more consent. |
| Insurance billing | Billing changes what the rules expect of you and how much of it applies. |
| IT environment | A managed Microsoft tenant is a different review from a mix of personal devices. |
| Ownership structure | An owner-operated practice decides faster than an investor-backed group. |
| Current documentation | If you already have some of it, you pay less. That is the whole point of measuring first. |
| A live event | A complaint, an incident, a carrier questionnaire or a sale under way changes the sequence. |
We publish what sets the price rather than a price list, because the honest number depends on the answers above. You get a fixed fee in writing after a 30-minute call — not a range that moves later.
Thirty minutes, and you will know your number.
Bring your locations, your service lines, and whatever documentation you think you have. We will tell you which step you need and what it costs.