Expert services

Incident Response Assistance

When something happens, the clock starts. We run the four-factor analysis, the notification decision, and the documentation trail with you.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

When something happens, the clock starts. We run the four-factor analysis, the notification decision, and the documentation trail with you.

Who this is for

Organisations that already know roughly where they stand and need the work done — not another vendor explaining what HIPAA is. Covered entities and business associates both, from 10-person health tech startups to multi-site provider groups.

How the engagement runs

  • Immediate triage and containment guidance
  • Four-factor breach risk assessment under §164.402
  • Notification decision and timeline management
  • Individual, HHS, and media notification drafting where required
  • Post-incident corrective action plan

What you get

  • Documented breach risk assessment
  • Notification letters and HHS submission support
  • Incident timeline and evidence file
  • Corrective action plan

Timeline and price

Typical durationOn call
Starting price$5,000 retainer
Delivered byNamed healthcare compliance lead, not a rotating bench
Deliverable formatPDF + DOCX + loaded into your SuperHIPAA workspace

Scope drivers that move the price: number of legal entities, number of clinical or production systems in scope, whether ePHI crosses a cloud boundary, and how much prior documentation exists.

Why teams pick us over a generalist consultancy

A generalist gives you a report. We give you a report and the system that keeps it true twelve months later. The deliverable is not a PDF you file — it is a populated risk register, a live evidence library, and a workforce that has acknowledged the current version of every policy.

What happens after you fill the form

  1. You get the deliverable immediately. No “a rep will contact you to unlock your download.”
  2. We read your answers before we call. The scoping call starts with what you told us, not a discovery script.
  3. You get a fixed-scope, fixed-price proposal in 2 business days — or a straight “you don’t need us yet,” which we say more often than you’d expect.

On the word “certified.” There is no government HIPAA certification. Any vendor selling you a “HIPAA Certificate” is selling a PDF they printed themselves. What regulators, customers, and insurers actually accept is a documented risk analysis, implemented safeguards, and evidence that both are maintained. That is what SuperHIPAA produces.

Questions

How is this priced?

Fixed scope, fixed fee, starting at $5,000 retainer. We publish the starting number because vendors who hide it are usually charging based on how desperate you sound.

How long does it take?

On call for a typical engagement. Multi-entity or multi-cloud environments take longer and we say so in the proposal, not after you sign.

Do we have to buy the platform too?

No. Services stand alone. Most clients bundle because the deliverables land directly in the platform and stay maintainable, but it is not a condition.

Will this make us HIPAA certified?

No such thing exists. This produces the risk analysis, documented safeguards, and evidence that regulators and enterprise customers actually accept.

What counts as a reportable breach?

An impermissible use or disclosure of unsecured PHI is presumed to be a breach unless a documented four-factor risk assessment shows a low probability the PHI was compromised. We run that assessment with you and write it down, because the documentation is what protects you later.

What are the notification deadlines?

Affected individuals within 60 days of discovery. HHS within 60 days for breaches affecting 500 or more people, or in an annual log for smaller ones, plus media notice for 500+ in a state. The clock starts at discovery, not at confirmation.

Do you work alongside our lawyers and forensics firm?

Yes. Counsel keeps privilege and makes the legal calls, forensics does forensics, and we run the HIPAA regulatory workflow — the risk assessment, the notification content, and the documentation trail.

Can we call you mid-incident without a retainer?

Retainer clients get first response; we take direct engagements when capacity allows. If you are mid-incident, contact us anyway — we will tell you straight away whether we can start immediately.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo