Accepting new practices for 2026–2027

A HIPAA risk analysis you can defend., an auditor accepts., your insurer trusts., that stays current. and reviewed by a human.

Reviewed and signed by SaberGuard's compliance team. Every finding traced to evidence. Kept current by Ward Agent. Built for small medical, dental, and behavioral health practices in Massachusetts.

A risk analysis is required by 45 CFR 164.308(a)(1)(ii)(A). This isn't best practice. It's the law.

Security Risk Analysis

Finding 07 of 23 · Example Family Dental (sample)

High

Multi-factor authentication is not enforced for 3 of 11 accounts with mailbox access

45 CFR 164.312(d)Person or entity authentication
accounts_with_mailbox
11
mfa_registered
8 of 11
conditional_access
policy disabled
observed
2026-09-28 06:10 UTC
source
Entra ID · read-only
sha256 3f9a…c21eReviewed and signed · Jonathan DeLeon, CISM®

What the assessment maps

Do You Know Where Your ePHI Lives?

You cannot protect data you have not located, and an auditor will ask. This is the map we build first: every system that touches patient data and the safeguard each one owes.

ePHI

Protected

Select a system to see what we typically find there, how heavily it weighs in a risk analysis, and which other systems it exchanges patient data with.

Select any system to see the finding, its risk weighting, and what it exchanges data with. Get this map built for your practice →


How an engagement runs

From first call to a signed, evidence-backed report

Four steps and one person. You never install anything or log into a portal.

  1. 01

    Collect

    Your administrator · 15 minutes

    Read-only access to your Microsoft 365 or Google Workspace settings, plus a short attestation for what software can't see.

  2. 02

    Evaluate

    Ward Agent · automated

    Ward Agent checks what it collected against hand-written rules. A rule, not an AI, decides whether a control is met.

  3. 03

    Review and sign

    Jonathan DeLeon, CISM®

    Jonathan reads every finding, rejects what doesn't hold up, and signs the report. His name is on it.

  4. 04

    Fix and keep watching

    Remediation · monitoring

    Findings become a prioritized plan. If you want, collection keeps running and drift becomes a finding, not a surprise.


Ward Agent by SaberGuard

The assessment that keeps running

Ward reads your security settings on a schedule, checks them against the Security Rule, and every finding points at the configuration that produced it and when it was observed.

Reads

  • MFA registration state
  • Conditional access and security defaults
  • Admin role assignments
  • Stale and unused accounts

Never reads

  • Email
  • Files
  • Calendars
  • Chat
Ward Agent · evidence pipeline · sample
read-only · 0 errors
SCHEDULECollection runevery 24h · read-onlySNAPSHOTConfigurationsha256 3f9a…c21eRULES ENGINEEvaluating164.312(d)-01 · not an AIFinding draftedExpert reviewReport delivered
›
Collection started · Microsoft 365 tenant · read-only · 06:00 UTC
Controls
44
Evidence items
312
Last run
2h ago
Reviewer
Jonathan DeLeon, CISM®

Illustrative sample. You receive the signed report; there is no client login.


Massachusetts has its own law

201 CMR 17.00 requires a written information security program from anyone holding personal information about a Massachusetts resident, whether or not HIPAA applies.

National compliance tools skip it. Ours is included with every risk analysis.

What it requires

Pricing

Fixed fees, scoped before you commit

Two tiers by practice size. Remediation quoted per project. Advisory by the hour.

Most Popular

Solo Practitioner

1–3 staff, one location

$2,500–$3,500

fixed fee · scoped on the consult

  • Signed HIPAA Security Rule risk analysis report
  • Findings with citation, severity, and the evidence that produced each
  • Prioritized remediation roadmap

Small Group

4–15 staff

$4,500–$6,500

fixed fee · scoped on the consult

  • Signed HIPAA Security Rule risk analysis report
  • Findings with citation, severity, and the evidence that produced each
  • Prioritized remediation roadmap

Remediation & Hardening

From $800per system

Quoted per project after the risk analysis, when we know what needs fixing.

vCISO & Senior Advisory

$150per hour

Billed hourly. No retainer required.

Annual Refresh for existing clients: 40 to 50% of the initial fee. Continuous monitoring is scoped with your assessment.

SaberGuard assesses and advises. It does not warrant or certify compliance, and nobody honest will promise you an audit outcome. What you get is a defensible analysis, a plan, and a person who answers the phone.

Full pricing

The podcast

The SaberGuard Show

Threat breakdowns, compliance deep dives, and practical security advice for small practices and small businesses.

Listen here or on your platform

The in-page player is provided by Apple and loads only with your permission for embedded media.

Find out where your practice stands.

A thirty-minute scoping call. You leave with a fixed fee and a start date.

SaberGuard assesses and advises; it does not warrant compliance.