top of page
Original size.jpg

Security Risk Assessment

The formal risk analysis HIPAA requires, and what your insurer, OCR, MIPS, and lenders all ask for by name.

Anchor 1

THE MOMENT THIS IS FOR

Your insurer wants a current risk analysis. OCR asks for one first after any breach or complaint. Your MIPS attestation is only true if one actually exists. A lender or a buyer's due diligence team expects to find it. A Security Risk Assessment is the formal, documented analysis HIPAA requires, done properly, so you have a real answer instead of a guess when someone asks.

THIS IS FOR YOU IF:

✔ You need a formal Security Risk Assessment completed.
✔ You need clarity on what matters most and what to fix first.
✔ You want documentation you can use for audits, insurance, or MIPS.

INCLUDES:

✔ Patient information inventory and data flow mapping: how data is created, used, stored, and shared.
✔ A full Security Risk Assessment across administrative, physical, and technical safeguards.
✔ A Privacy Rule workflow review: minimum necessary, disclosures, patient rights, and release of information basics.
✔ A Breach Notification readiness review: incident workflow, decision steps, timelines, and documentation.
✔ A prioritized risk register with owners, plus a 30/60/90-day roadmap.
✔ A debrief meeting with leadership or your practice manager.

WHAT YOUR PRACTICE GAINS:

✔ A completed, defensible Security Risk Assessment.
✔ A clear, documented view of your HIPAA risks and compliance gaps.
✔ A prioritized plan your team can act on without guesswork.

$5000 - Fixed Price, Fixed Scope.  Expedited delivery available for an insurance, OCR, or closing deadline.

WHY US:

Twenty years at Boeing, Microsoft, and Costco taught us which questions on your application actually matter, what real security controls look like, and where HIPAA overlaps with what your insurer is asking. You get findings you can act on, not just a checklist.

FREQUENTLY ASKED QUESTIONS

What is a HIPAA Security Risk Assessment?
 

A Security Risk Assessment is the formal, documented analysis of risks to patient information that the HIPAA Security Rule requires of every practice and Business Associate. It's also often the document OCR requests first in an investigation, what MIPS attestations reference, and what cyber insurance underwriters use to judge whether a practice's safeguards are reasonable.

 

Is a Security Risk Assessment legally required?
 

Yes. The HIPAA Security Rule requires every covered entity and Business Associate to conduct a risk analysis, and it must be updated whenever systems, vendors, or operations change. A risk analysis that's several years old, or that was never truly completed, doesn't satisfy the requirement.

 

How much does a Security Risk Assessment cost?
 

Sorticulture Systems charges a flat $5,000 for a complete Security Risk Assessment, including the risk register, a 30/60/90-day mitigation plan, and a leadership debrief. Expedited delivery is available for practices facing an insurance, OCR, or closing deadline.

 

How is a Security Risk Assessment different from a HIPAA Gap Assessment?
 

A Gap Assessment is a quick checklist review of what's in place and what's missing. A Security Risk Assessment is the full, formal analysis HIPAA actually requires, covering administrative, physical, and technical safeguards, with documented findings an insurer, auditor, or regulator will accept.

 

Do Business Associates need a Security Risk Assessment too?
 

Yes. Any business that creates, receives, maintains, or transmits patient data on behalf of a healthcare client has the same risk analysis obligation as the practice itself, and increasingly the same expectations from cyber insurers and enterprise customers doing vendor security reviews.

MOST COMMON NEXT STEP

Most assessments turn up work worth building into a full program. That's HIPAA Essentials, and if you've just completed this assessment, the Essentials Completion path is $5,000 instead of $10,000.

 

About HIPAA Essentials

bottom of page