THE MOMENT THIS IS FOR
You know you have to do HIPAA, but you're not sure what's actually in place and what's missing. Maybe you inherited documentation nobody's opened in years, or you're starting from scratch. Before spending real money on a full build-out, it helps to know exactly where you stand.
THIS IS FOR YOU IF:
✔ You want to understand the basics of what HIPAA actually requires.
✔ You're not sure where to start and want a clearer picture of where things stand.
✔ You want to confirm which key HIPAA elements are already in place, and which ones may be missing.
INCLUDES:
✔ One 60-minute working session on how patient information actually moves through your practice, day to day.
✔ A review of key HIPAA elements:
✔ A written summary of what's in place and what may be missing, in priority order.
WHAT YOUR PRACTICE GAINS:
✔ A clear picture of where things stand today.
✔ A practical starting point that reduces confusion.
✔ An honest snapshot of what's present and what needs attention.
$995 - Credits toward the Security Risk Assessment if you book within 60 days.
WHY US:
Twenty years at Boeing, Microsoft, and Costco taught us which questions on your application actually matter, what real security controls look like, and where HIPAA overlaps with what your insurer is asking. You get findings you can act on, not just a checklist.
FREQUENTLY ASKED QUESTIONS
Is a HIPAA Gap Assessment the same as a compliance assessment?
No, and this distinction matters. A Gap Assessment gives you a clear picture of what's in place and what's missing, in one focused session. It doesn't satisfy HIPAA's legal requirement for a formal Security Risk Assessment, and it isn't what your cyber insurer, MIPS, or an auditor will accept as proof of compliance. If the Gap Assessment shows real gaps, the Security Risk Assessment is the next step, and your $995 counts toward it.
What's the difference between a HIPAA Gap Assessment and a Security Risk Assessment?
A HIPAA Gap Assessment is a starting point; a Security Risk Assessment is the formal, documented analysis HIPAA actually requires, and it's what insurers, OCR, and MIPS ask for by name. A Gap Assessment is a structured checklist review of where a practice stands today. Many practices use the Gap Assessment to find out how much work the Security Risk Assessment needs to cover.
How do I know if I need a Gap Assessment or a Security Risk Assessment?
If you're not sure what you have, or whether your HIPAA basics are in place, start with the Gap Assessment. If you already know you need a formal, documented risk analysis, for an insurer, a lender, MIPS, or after an incident, go straight to the Security Risk Assessment instead.
Will a HIPAA Gap Assessment satisfy my MIPS attestation or insurance application?
No. Both a MIPS attestation and a cyber insurance application require a formal Security Risk Assessment, not a gap assessment. If a Gap Assessment turns up a missing or outdated risk analysis, that becomes the next step.
How long does a HIPAA Gap Assessment take?
About a week from the working session to the written summary.
MOST COMMON NEXT STEP
Most assessments turn up at least one real gap that needs the formal treatment. That's the Security Risk Assessment, and your $995 counts toward it if you book within 60 days of completing the Gap Assessment.
About the Security Risk Assessment
