Solo Practitioner
1–3 staff, one location
$2,500–$3,500
fixed fee · scoped on the consult
- Signed HIPAA Security Rule risk analysis report
- Findings with citation, severity, and the evidence that produced each
- Prioritized remediation roadmap
Reviewed and signed by SaberGuard's compliance team. Every finding traced to evidence. Kept current by Ward Agent. Built for small medical, dental, and behavioral health practices in Massachusetts.
A risk analysis is required by 45 CFR 164.308(a)(1)(ii)(A). This isn't best practice. It's the law.
Security Risk Analysis
Finding 07 of 23 · Example Family Dental (sample)
You cannot protect data you have not located, and an auditor will ask. This is the map we build first: every system that touches patient data and the safeguard each one owes.
ePHI
Protected
Select a system to see what we typically find there, how heavily it weighs in a risk analysis, and which other systems it exchanges patient data with.
Select any system to see the finding, its risk weighting, and what it exchanges data with. Get this map built for your practice →
Four steps and one person. You never install anything or log into a portal.
Your administrator · 15 minutes
Read-only access to your Microsoft 365 or Google Workspace settings, plus a short attestation for what software can't see.
Ward Agent · automated
Ward Agent checks what it collected against hand-written rules. A rule, not an AI, decides whether a control is met.
Jonathan DeLeon, CISM®
Jonathan reads every finding, rejects what doesn't hold up, and signs the report. His name is on it.
Remediation · monitoring
Findings become a prioritized plan. If you want, collection keeps running and drift becomes a finding, not a surprise.
Ward reads your security settings on a schedule, checks them against the Security Rule, and every finding points at the configuration that produced it and when it was observed.
Reads
Never reads
Illustrative sample. You receive the signed report; there is no client login.
Risk analysis is the front door. Everything else exists because a finding pointed at it.
Also managed, when a finding points at it
Full catalogMassachusetts has its own law
National compliance tools skip it. Ours is included with every risk analysis.
Two tiers by practice size. Remediation quoted per project. Advisory by the hour.
1–3 staff, one location
$2,500–$3,500
fixed fee · scoped on the consult
4–15 staff
$4,500–$6,500
fixed fee · scoped on the consult
From $800per system
Quoted per project after the risk analysis, when we know what needs fixing.
$150per hour
Billed hourly. No retainer required.
SaberGuard assesses and advises. It does not warrant or certify compliance, and nobody honest will promise you an audit outcome. What you get is a defensible analysis, a plan, and a person who answers the phone.
Full pricingThreat breakdowns, compliance deep dives, and practical security advice for small practices and small businesses.
Listen here or on your platform
The in-page player is provided by Apple and loads only with your permission for embedded media.
A thirty-minute scoping call. You leave with a fixed fee and a start date.
SaberGuard assesses and advises; it does not warrant compliance.