Between 20 and 200 people, no CISO, and a compliance burden written for organisations ten times your size.
What you get
- A Privacy and Security Officer on retainer instead of a hire
- Guided risk analysis your operations lead can run
- Training that fits into an existing onboarding flow
- Published pricing so you can budget without three sales calls
The shared responsibility line
This is where most teams get it wrong. Your provider secures the infrastructure. You secure your configuration, your identities, your data classification, your logging retention, and your workforce. Every enforcement action we have read involved the second half of that sentence, not the first.
How it fits together
| Layer | Who owns it | How SuperHIPAA helps |
|---|---|---|
| Infrastructure | Provider (under BAA) | We verify your BAA is current and covers the services you use |
| Configuration | You | Continuous checks mapped to §164.312 |
| Data classification | You | ePHI inventory and flow mapping |
| Workforce | You | Training, acknowledgement, access reviews |
| Documentation | You | Policies, risk analysis, evidence, all versioned |
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.