HIPAA compliance that holds up to an auditor, an insurer, an investigation, your board, and due diligence.
Fixed-fee Security Rule assessments for solo and small practices, clinics, and business associates. You get a rated risk register, a prioritised roadmap, and a plain-language summary you can hand to an auditor, an insurer, or your board.
Frameworks we work in
- HIPAA Security Rule
- NIST CSF 2.0
- CIS Controls v8
- SEC / FINRA
- CMMC readiness
Security Risk Analysis
Sample register extract
- HighMFA not enforced on EHR accounts§ 164.312(d)
- HighTwo vendors operating without a current BAA§ 164.308(b)(1)
- MedBackup restores never tested§ 164.308(a)(7)
- LowWorkstation lock timeout exceeds policy§ 164.312(a)(2)(iii)
Illustrative extract. Every finding in your register is rated, cited, and mapped to a remediation owner.
Built Around HIPAA. Fluent in the Rest.
Healthcare is where we go deepest — it is the practice we built the firm around. When a client answers to a different regulator, the same method applies and we say plainly how far we take it.
How to read this
Every consultancy claims every framework. The bar beside each one is how far we actually take it — five means we own the outcome, two means we get you to someone who does.
- End to end
- Analysis through audit file
- Advisory
- We build it, counsel files it
- Readiness
- Prep for a certified assessor
Shared method
- NIST CSF 2.0Govern → Recover
- CIS Controls v8Prioritised safeguards
- NIST SP 800-61Incident handling
The controls overlap heavily, which is why a second framework costs far less than the first.
The annual Security Risk Analysis required at 45 CFR § 164.308(a)(1)(ii)(A), plus the safeguards, documentation, and evidence that make it defensible.
- Annual Security Risk Analysis & rated risk register
- Administrative, physical & technical safeguards
- BAA review and vendor due diligence
- Breach response, tabletops & audit evidence
Where we stopEnd to end. We run the analysis, scope the remediation, and hand you the audit file.
Scoping conversations are free, and we will tell you when something is outside what we should take on.
This Isn't Best Practice. It's the Law.
A Security Risk Analysis is the required starting point for protecting ePHI, documenting reasonable safeguards, and knowing what to fix next.
Required by HIPAA
45 CFR § 164.308(a)(1)(ii)(A) requires covered entities to conduct an accurate, thorough security risk analysis for ePHI — regardless of practice size.
Often Found After Incidents
OCR investigations are commonly triggered by a breach or complaint. A missing or outdated risk analysis is often what turns the incident into a longer corrective-action problem.
The Standard Is Rising
HHS has proposed Security Rule updates that would make written risk analysis expectations more specific. The rule is not final yet, but current documentation puts practices ahead of the curve.
Start with the annual assessment
The goal is not fear — it is a defensible risk register, a plain-language summary, and a prioritized roadmap before an incident, insurer request, or regulatory question creates pressure.
Do You Know Where Your ePHI Lives?
You cannot protect data you have not located, and an auditor will ask. This is the map we build in week one — every system that creates, receives, maintains, or transmits patient data, and the safeguard each one owes.
ePHI
Protected
Select a system to see what we typically find there, how heavily it weighs in a risk analysis, and which other systems it exchanges patient data with.
Select any system to see the finding, its risk weighting, and what it exchanges data with. Get this map built for your practice →
Healthcare Is Under Pressure. Evidence Is What Protects You.
Practices are judged on whether they can prove risk analysis, safeguards, training, and response readiness — before an incident turns into a reportable event.
of healthcare organizations experienced at least one cyberattack in the previous 12 months
Ponemon 2025
average healthcare data breach cost — the highest of any industry
IBM 2025
of healthcare breaches involved compromised or stolen credentials, phishing, or cloud misconfiguration
Verizon DBIR 2025
of SMBs have no formal incident response plan in place
TotalAssure 2025
of SMB data breaches involve ransomware vs. 39% for enterprises
Verizon DBIR 2025
is too long to discover missing HIPAA evidence when an auditor, insurer, or incident already needs it
SaberGuard Readiness
Healthcare Compliance First, Security Built Around ePHI
Risk analysis and audit evidence are the front door. Everything else here exists because a finding pointed at it — safeguards get implemented on the systems the assessment actually flagged.
HIPAA Security Risk Assessment
Annual SRA support for covered entities and business associates: ePHI workflows, threats, vulnerabilities, likelihood, impact, and prioritized remediation evidence.
Audit Readiness & Evidence
Prepare documentation that administrators can defend: policies, procedures, risk register, remediation plan, vendor artifacts, and executive-ready status reporting.
Security Rule Safeguards
Administrative, physical, and technical safeguard reviews mapped to practical controls for clinics, specialty practices, and healthcare operators.
Incident Response for ePHI
Breach triage, containment planning, tabletop exercises, notification decision support, and post-incident hardening for patient-data events.
Secure Healthcare Email
Phishing defense, BEC reduction, spoofing protection, account takeover monitoring, and encrypted delivery for regulated patient communications.
Identity & Access Reviews
MFA, role-based access, risky sign-in review, credential exposure monitoring, and workforce access processes for systems touching ePHI.
Endpoint & EHR Workflow Protection
Endpoint detection, device hardening, patch visibility, and practical security controls around workstations used for EHR and patient operations.
M365, SaaS & Cloud Hardening
Tenant configuration, file-sharing controls, backup readiness, SaaS permissions, and cloud data exposure reduction for healthcare teams.
Clinic Network Segmentation
Firewall, Wi-Fi, VPN, DNS filtering, and segmentation guidance to separate clinical systems, guest access, and administrative operations.
HIPAA Security Awareness
Workforce-ready training, phishing simulations, and administrator reporting focused on patient privacy, social engineering, and credential theft.
AI Governance for Patient Data
Approved-tool policies, prompt/data handling guidance, agent guardrails, and shadow AI controls so staff do not leak PHI into unsafe systems.
Multi-Framework Compliance
One control set, mapped across the regulators you answer to — SEC Regulation S-P, FINRA, and CMMC / NIST SP 800-171 readiness alongside your HIPAA program.
The Order of Defense℠
Nine steps, mapped to the NIST CSF 2.0 functions. Controls applied out of order waste money — you cannot monitor for compromise on systems you have not inventoried.
Map ePHI
Inventory systems, data flows, vendors.
IdentifyVerify Access
MFA, roles, joiner/mover/leaver.
IdentifyProtect Patients
Reduce phishing, malware, BEC.
ProtectPatch & Update
Fix vulnerabilities quickly.
ProtectHarden Safeguards
Secure endpoints, SaaS, networks.
ProtectMonitor ePHI Risk
Detect suspicious access fast.
DetectContain & Document
Triage, preserve evidence, notify.
RespondRecover Data
Restore from clean backups.
RecoverProve Readiness
Policies, reports, remediation proof.
GovernThe SaberGuard Show
Threat breakdowns, compliance deep dives, and practical security advice for small businesses. On YouTube, Apple Podcasts, and Spotify.
Start Your Risk Analysis
No sales pitch — a direct conversation about your risk posture, your evidence, and what an assessment would actually cover for a practice your size.