The §164.308(a)(1)(ii)(A) risk analysis, done properly: asset-based, threat-paired, scored, and defensible.
Who this is for
Organisations that already know roughly where they stand and need the work done — not another vendor explaining what HIPAA is. Covered entities and business associates both, from 10-person health tech startups to multi-site provider groups.
How the engagement runs
- Full ePHI asset and data-flow inventory
- Threat and vulnerability identification per asset
- Likelihood and impact scoring with a documented methodology
- Current control effectiveness evaluation
- Risk register build and treatment decisions with your leadership
What you get
- Risk Analysis Report with methodology appendix
- Populated risk register (loaded into the platform, not just a spreadsheet)
- Risk treatment plan with accepted-risk rationales
- Board-ready risk summary
Timeline and price
| Typical duration | 3–4 weeks |
| Starting price | $6,500 |
| Delivered by | Named healthcare compliance lead, not a rotating bench |
| Deliverable format | PDF + DOCX + loaded into your SuperHIPAA workspace |
Scope drivers that move the price: number of legal entities, number of clinical or production systems in scope, whether ePHI crosses a cloud boundary, and how much prior documentation exists.
Why teams pick us over a generalist consultancy
A generalist gives you a report. We give you a report and the system that keeps it true twelve months later. The deliverable is not a PDF you file — it is a populated risk register, a live evidence library, and a workforce that has acknowledged the current version of every policy.
What happens after you fill the form
- You get the deliverable immediately. No “a rep will contact you to unlock your download.”
- We read your answers before we call. The scoping call starts with what you told us, not a discovery script.
- You get a fixed-scope, fixed-price proposal in 2 business days — or a straight “you don’t need us yet,” which we say more often than you’d expect.
On the word “certified.” There is no government HIPAA certification. Any vendor selling you a “HIPAA Certificate” is selling a PDF they printed themselves. What regulators, customers, and insurers actually accept is a documented risk analysis, implemented safeguards, and evidence that both are maintained. That is what SuperHIPAA produces.