For practices of 1–20 providers · Flat fee, no contract
The HIPAA security risk assessment your practice is required to have — done for you, for $495
A guided review and technical scan of your practice, an attestation-ready written report, and your three highest-risk findings fixed by our engineers. Delivered in five business days.
Prefer to talk first? Book a free 15-minute call. Fully credited toward managed services if you join within 90 days.
It’s the law
The HIPAA Security Rule requires a periodic, documented risk assessment — and it’s the first thing OCR asks for after a breach.
The rules are tightening
Proposed Security Rule updates add mandatory MFA, encryption, and asset inventories. Practices that assess now get ahead of it calmly.
Small practices are the target
Health records are the most valuable data criminals can steal, and small practices are attacked precisely because they assume they’re too small to matter.
What the $495 includes
A complete assessment, not a scan-and-scare PDF
30-minute kickoff call
We walk through your practice: systems, EHR, staff, locations, and vendors. No prep needed — we ask, you answer.
Technical security scan
With your permission, we scan your network and endpoints the way an attacker would look at them: exposed services, unpatched systems, weak access controls, backup posture.
Administrative safeguards review
Access management, workforce training, business associate agreements, and contingency planning — mapped against the HIPAA Security Rule safeguard by safeguard.
Attestation-ready written report
A dated, practice-specific risk assessment you can file for HIPAA compliance and MIPS attestation — with every finding rated by likelihood and impact.
Your top 3 findings, fixed
We don't just hand you homework. The three highest-risk findings are remediated by our engineers as part of the package.
A 30/60/90-day roadmap
A prioritized plan for everything else, with clear effort estimates. Take it to any IT provider — including the one you already have.
How it works
From booking to attestation-ready in five business days
Book online
Pay the flat $495 and pick a kickoff slot. We confirm within one business day.
Kickoff + scan
A 30-minute guided call, then our engineers run the technical assessment with your permission.
Report delivered
Your written, dated risk assessment with every finding rated and a 30/60/90-day fix roadmap.
Top 3 fixed + review call
We remediate your three highest-risk findings and walk the whole report with you in plain English.
See exactly what you get
Read a sample report before you spend a dollar
We publish a full sample assessment for a fictional pediatric practice — the same structure, rating methodology, and level of detail your practice receives. If your current IT provider has never given you a document like this, that’s worth knowing.
- Performed by the healthcare IT team behind 2,000+ organizations
- Mapped to HIPAA Security Rule safeguards, finding by finding
- Accepted for MIPS/Promoting Interoperability attestation records
- Flat fee — no upsell required to get the full report
- $495 credited to your first invoice if you join within 90 days
Questions practices ask
Straight answers
Is a security risk assessment actually required?
Yes. The HIPAA Security Rule (45 CFR §164.308(a)(1)(ii)(A)) requires every covered entity to conduct an accurate and thorough assessment of risks to electronic PHI, and to review it periodically. It is also required to attest for MIPS/Promoting Interoperability. Practices are asked to produce it during audits and after any breach investigation.
What do you need from us?
About 30 minutes of a decision-maker's time for the kickoff call, permission to run a technical scan, and answers to a short guided questionnaire. Most practices spend under two hours total. We do the rest.
Is this remote or on-site?
The assessment is remote-first and works anywhere in the US. For practices in Bergen County and northern New Jersey, we can include an on-site walkthrough at no extra charge.
How long until we get the report?
Your written report and fix list are delivered within five business days of the kickoff call, followed by a 30-minute review call to walk through the findings in plain English.
Is this just a sales pitch for your managed services?
The report is a complete, standalone deliverable — the fix list doubles as a scope of work you can hand to any IT provider. If you do choose Practice All for remediation or managed services within 90 days, the full $495 is credited to your first invoice. No pressure either way.
We already have an IT company. Is this still useful?
Especially then. An independent assessment is exactly what an auditor wants to see, and it's the honest way to verify that what you're paying for is actually in place. Many of our assessment clients keep their existing IT and simply hand them the fix list.
Know where your practice stands by next week
One flat fee. A document your auditor, your insurer, and your own peace of mind will thank you for.
