A blunt, evidence-based read on where you stand against every required and addressable specification in the Security, Privacy, and Breach Notification Rules.
Who this is for
Organisations that already know roughly where they stand and need the work done — not another vendor explaining what HIPAA is. Covered entities and business associates both, from 10-person health tech startups to multi-site provider groups.
How the engagement runs
- Kickoff and scope confirmation — entities, systems, ePHI flows
- Documentation review of existing policies, BAAs, and prior assessments
- Interviews with IT, clinical, HR, and vendor owners
- Technical validation: encryption, access control, logging, backup, MFA
- Findings workshop and prioritised remediation roadmap
What you get
- Gap Assessment Report with per-specification status
- Prioritised remediation plan with effort and owner
- Executive summary suitable for the board
- Evidence request list for anything we could not verify
Timeline and price
| Typical duration | 2–3 weeks |
| Starting price | $4,500 |
| Delivered by | Named healthcare compliance lead, not a rotating bench |
| Deliverable format | PDF + DOCX + loaded into your SuperHIPAA workspace |
Scope drivers that move the price: number of legal entities, number of clinical or production systems in scope, whether ePHI crosses a cloud boundary, and how much prior documentation exists.
Why teams pick us over a generalist consultancy
A generalist gives you a report. We give you a report and the system that keeps it true twelve months later. The deliverable is not a PDF you file — it is a populated risk register, a live evidence library, and a workforce that has acknowledged the current version of every policy.
What happens after you fill the form
- You get the deliverable immediately. No “a rep will contact you to unlock your download.”
- We read your answers before we call. The scoping call starts with what you told us, not a discovery script.
- You get a fixed-scope, fixed-price proposal in 2 business days — or a straight “you don’t need us yet,” which we say more often than you’d expect.
On the word “certified.” There is no government HIPAA certification. Any vendor selling you a “HIPAA Certificate” is selling a PDF they printed themselves. What regulators, customers, and insurers actually accept is a documented risk analysis, implemented safeguards, and evidence that both are maintained. That is what SuperHIPAA produces.