For practices of 1–20 providers · One flat fee, billed annually
Everything your practice is required to do this year — done for you, for $995
Four separate legal requirements, four separate things to forget. We run all of them on one annual schedule and hand you the documents an auditor, an insurer, or a breach investigator will ask for.
The review call is free and takes 15 minutes. We tell you which of the four you’re already covered on — including the ones you don’t need us for.
It’s the first thing asked for
After any breach, OCR opens by asking for your risk assessment and your training records. “We meant to” is the expensive answer.
The clock resets every year
These aren’t one-time projects. A 2019 risk assessment and last year’s training roster do not satisfy this year’s obligation.
Your insurer is checking too
Cyber-liability renewals now ask whether you have assessed risk, trained staff, and tested backups. Wrong answers raise premiums or void coverage.
What the $995 covers
Four requirements, one engagement
HIPAA Security Risk Assessment
45 CFR §164.308(a)(1)(ii)(A)
A guided review and technical scan, an attestation-ready written report with every finding rated, and your three highest-risk findings fixed by our engineers. The same assessment we sell on its own for $495.
HIPAA & OSHA staff training
§164.308(a)(5) · OSHA 1910.1030
Security awareness and privacy training for every member of your workforce, plus OSHA bloodborne pathogens and hazard communication. Self-paced, tracked, and delivered with the completion certificates an auditor asks for.
Business Associate Agreement audit
45 CFR §164.308(b)(1)
We inventory every vendor that touches your patient data — EHR, billing, fax, backup, IT, shredding — and tell you which BAAs are missing, expired, or unsigned. Most practices are surprised by this one.
Backup & disaster recovery plan
45 CFR §164.308(a)(7)
HIPAA requires a documented data backup plan, disaster recovery plan, and emergency-mode operation plan. We write all three against how your practice actually runs, then test your restore once to prove it works.
$1,845 of work, bundled at $995
Bought separately, these four run about $1,845. Run together they share one kickoff call, one questionnaire, and one review — which is why we can price the package where we do.
How the year runs
One kickoff, then we carry the calendar
Free review call
Fifteen minutes. We map what you already have and what's missing, and tell you honestly if you don't need all four.
Kickoff + scan
A 30-minute guided call, then the technical assessment and the vendor/BAA inventory run with your permission.
Documents delivered
Risk assessment, BAA findings, and your written backup, disaster recovery, and emergency-mode plans — inside five business days.
Training + reminders
Staff training goes out with tracked completions, and we bring the whole package back around before it expires next year.
See the quality first
Read a real deliverable before you spend anything
We publish a complete sample risk assessment for a fictional pediatric practice — the same structure and level of detail your practice receives. It is the biggest document in the package, so it is the fairest way to judge the rest of it.
- Delivered by the healthcare IT team behind 2,000+ organizations
- Every finding mapped to the rule it satisfies, by citation
- Attestation-ready for MIPS/Promoting Interoperability records
- Works alongside your current IT provider — no switching required
- Full $995 credited to your first invoice if you join our managed services within 90 days
Questions practices ask
Straight answers
Is all of this actually required, or is it best practice?
All four are requirements, not suggestions. The security risk assessment, workforce security training, business associate agreements, and the backup/disaster-recovery plans are each named in the HIPAA Security Rule, and OSHA separately requires bloodborne pathogens and hazard communication training for practices with employees. What varies is how often — most carry an annual or 'periodic' cadence, which is why we run the package yearly.
What happens if we've never done any of this?
That is the normal starting point, and it is not a problem. The first year establishes the documents you don't have: a dated risk assessment, training records for each employee, a BAA inventory, and written backup and contingency plans. From there, each annual cycle is an update rather than a rebuild.
How much of our time does it take?
About two hours from a decision-maker across the year — a 30-minute kickoff call, a short guided questionnaire, and a 30-minute review call when the report is delivered. Staff training is self-paced and runs about 45 minutes per person.
We already have an IT company. Does this conflict?
No, and an independent assessment is exactly what an auditor prefers to see. Many clients keep their existing IT provider and simply hand them the prioritized fix list. Nothing in the package requires you to switch anything.
Do you handle the remediation too?
The three highest-risk findings from the assessment are remediated as part of the package. Everything else arrives as a prioritized 30/60/90-day roadmap with effort estimates, which you can give to any provider — including us. If you do move your managed IT to Practice All within 90 days, the full $995 is credited to your first invoice.
What does it cost after the first year?
The same flat $995, billed annually, for as long as you keep it. The work is genuinely lighter in later years, but the requirement recurs every year, which is the point of putting it on a schedule instead of scrambling after a breach or an audit letter.
Get the whole list off your desk
Start with the free 15-minute review. We’ll tell you where your practice actually stands — and which pieces you don’t need to buy.
