Expert services

HIPAA Risk Analysis

The §164.308(a)(1)(ii)(A) risk analysis, done properly: asset-based, threat-paired, scored, and defensible.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

The §164.308(a)(1)(ii)(A) risk analysis, done properly: asset-based, threat-paired, scored, and defensible.

Who this is for

Organisations that already know roughly where they stand and need the work done — not another vendor explaining what HIPAA is. Covered entities and business associates both, from 10-person health tech startups to multi-site provider groups.

How the engagement runs

  • Full ePHI asset and data-flow inventory
  • Threat and vulnerability identification per asset
  • Likelihood and impact scoring with a documented methodology
  • Current control effectiveness evaluation
  • Risk register build and treatment decisions with your leadership

What you get

  • Risk Analysis Report with methodology appendix
  • Populated risk register (loaded into the platform, not just a spreadsheet)
  • Risk treatment plan with accepted-risk rationales
  • Board-ready risk summary

Timeline and price

Typical duration3–4 weeks
Starting price$6,500
Delivered byNamed healthcare compliance lead, not a rotating bench
Deliverable formatPDF + DOCX + loaded into your SuperHIPAA workspace

Scope drivers that move the price: number of legal entities, number of clinical or production systems in scope, whether ePHI crosses a cloud boundary, and how much prior documentation exists.

Why teams pick us over a generalist consultancy

A generalist gives you a report. We give you a report and the system that keeps it true twelve months later. The deliverable is not a PDF you file — it is a populated risk register, a live evidence library, and a workforce that has acknowledged the current version of every policy.

What happens after you fill the form

  1. You get the deliverable immediately. No “a rep will contact you to unlock your download.”
  2. We read your answers before we call. The scoping call starts with what you told us, not a discovery script.
  3. You get a fixed-scope, fixed-price proposal in 2 business days — or a straight “you don’t need us yet,” which we say more often than you’d expect.

On the word “certified.” There is no government HIPAA certification. Any vendor selling you a “HIPAA Certificate” is selling a PDF they printed themselves. What regulators, customers, and insurers actually accept is a documented risk analysis, implemented safeguards, and evidence that both are maintained. That is what SuperHIPAA produces.

Questions

How is this priced?

Fixed scope, fixed fee, starting at $6,500. We publish the starting number because vendors who hide it are usually charging based on how desperate you sound.

How long does it take?

3–4 weeks for a typical engagement. Multi-entity or multi-cloud environments take longer and we say so in the proposal, not after you sign.

Do we have to buy the platform too?

No. Services stand alone. Most clients bundle because the deliverables land directly in the platform and stay maintainable, but it is not a condition.

Will this make us HIPAA certified?

No such thing exists. This produces the risk analysis, documented safeguards, and evidence that regulators and enterprise customers actually accept.

Is a risk analysis actually required by law?

Yes. 45 CFR §164.308(a)(1)(ii)(A) requires an accurate and thorough assessment of risks to ePHI, and a missing or inadequate risk analysis is one of the findings OCR cites most often in enforcement actions.

What methodology do you use?

A NIST-aligned approach: map where ePHI lives, enumerate threats and vulnerabilities per asset, rate likelihood and impact, and document a treatment decision with an owner for every risk. The methodology is stated in the report so a reviewer can follow the reasoning.

Does this include penetration testing or vulnerability scanning?

No — a risk analysis is not a pen test, and vendors who conflate the two are selling you the wrong thing. If technical testing is warranted we say so, and existing scanner or pen-test results feed in as inputs.

How often do we need to redo it?

Update it at least annually and after any significant change — new system, new vendor, incident, or acquisition. Because the output lands as a living register, updates are incremental rather than a full rebuild.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo