Accepting new clients for 2026–2027

HIPAA compliance that holds up to an auditor, an insurer, an investigation, your board, and due diligence.

Fixed-fee Security Rule assessments for solo and small practices, clinics, and business associates. You get a rated risk register, a prioritised roadmap, and a plain-language summary you can hand to an auditor, an insurer, or your board.

Frameworks we work in

  • HIPAA Security Rule
  • NIST CSF 2.0
  • CIS Controls v8
  • SEC / FINRA
  • CMMC readiness

Security Risk Analysis

Sample register extract

Week 3
Findings by severity23 total
6 High9 Med8 Low
  • HighMFA not enforced on EHR accounts§ 164.312(d)
  • HighTwo vendors operating without a current BAA§ 164.308(b)(1)
  • MedBackup restores never tested§ 164.308(a)(7)
  • LowWorkstation lock timeout exceeds policy§ 164.312(a)(2)(iii)

Illustrative extract. Every finding in your register is rated, cited, and mapped to a remediation owner.


// frameworks.supported()

Built Around HIPAA. Fluent in the Rest.

Healthcare is where we go deepest — it is the practice we built the firm around. When a client answers to a different regulator, the same method applies and we say plainly how far we take it.

How to read this

Every consultancy claims every framework. The bar beside each one is how far we actually take it — five means we own the outcome, two means we get you to someone who does.

End to end
Analysis through audit file
Advisory
We build it, counsel files it
Readiness
Prep for a certified assessor

Shared method

  • NIST CSF 2.0Govern → Recover
  • CIS Controls v8Prioritised safeguards
  • NIST SP 800-61Incident handling

The controls overlap heavily, which is why a second framework costs far less than the first.

The annual Security Risk Analysis required at 45 CFR § 164.308(a)(1)(ii)(A), plus the safeguards, documentation, and evidence that make it defensible.

  • Annual Security Risk Analysis & rated risk register
  • Administrative, physical & technical safeguards
  • BAA review and vendor due diligence
  • Breach response, tabletops & audit evidence

Where we stopEnd to end. We run the analysis, scope the remediation, and hand you the audit file.

Not sure which applies to you? Ask on a scoping call

Scoping conversations are free, and we will tell you when something is outside what we should take on.


// why.not.optional()

This Isn't Best Practice. It's the Law.

A Security Risk Analysis is the required starting point for protecting ePHI, documenting reasonable safeguards, and knowing what to fix next.

Required by HIPAA

45 CFR § 164.308(a)(1)(ii)(A) requires covered entities to conduct an accurate, thorough security risk analysis for ePHI — regardless of practice size.

Often Found After Incidents

OCR investigations are commonly triggered by a breach or complaint. A missing or outdated risk analysis is often what turns the incident into a longer corrective-action problem.

The Standard Is Rising

HHS has proposed Security Rule updates that would make written risk analysis expectations more specific. The rule is not final yet, but current documentation puts practices ahead of the curve.

Start with the annual assessment

The goal is not fear — it is a defensible risk register, a plain-language summary, and a prioritized roadmap before an incident, insurer request, or regulatory question creates pressure.

Start Your Risk Analysis
// ephi.locate()

Do You Know Where Your ePHI Lives?

You cannot protect data you have not located, and an auditor will ask. This is the map we build in week one — every system that creates, receives, maintains, or transmits patient data, and the safeguard each one owes.

ePHI

Protected

Select a system to see what we typically find there, how heavily it weighs in a risk analysis, and which other systems it exchanges patient data with.

Select any system to see the finding, its risk weighting, and what it exchanges data with. Get this map built for your practice →


// threat_landscape

Healthcare Is Under Pressure. Evidence Is What Protects You.

Practices are judged on whether they can prove risk analysis, safeguards, training, and response readiness — before an incident turns into a reportable event.

0%

of healthcare organizations experienced at least one cyberattack in the previous 12 months

Ponemon 2025

$0M

average healthcare data breach cost — the highest of any industry

IBM 2025

0%

of healthcare breaches involved compromised or stolen credentials, phishing, or cloud misconfiguration

Verizon DBIR 2025

0%

of SMBs have no formal incident response plan in place

TotalAssure 2025

0%

of SMB data breaches involve ransomware vs. 39% for enterprises

Verizon DBIR 2025

0d

is too long to discover missing HIPAA evidence when an auditor, insurer, or incident already needs it

SaberGuard Readiness


// services.list()

Healthcare Compliance First, Security Built Around ePHI

Risk analysis and audit evidence are the front door. Everything else here exists because a finding pointed at it — safeguards get implemented on the systems the assessment actually flagged.

HIPAA Security Risk Assessment

Annual SRA support for covered entities and business associates: ePHI workflows, threats, vulnerabilities, likelihood, impact, and prioritized remediation evidence.

HIPAA SRAePHI

Audit Readiness & Evidence

Prepare documentation that administrators can defend: policies, procedures, risk register, remediation plan, vendor artifacts, and executive-ready status reporting.

Audit PrepEvidence

Security Rule Safeguards

Administrative, physical, and technical safeguard reviews mapped to practical controls for clinics, specialty practices, and healthcare operators.

SafeguardsControls

Incident Response for ePHI

Breach triage, containment planning, tabletop exercises, notification decision support, and post-incident hardening for patient-data events.

IR PlanBreach Triage

Secure Healthcare Email

Phishing defense, BEC reduction, spoofing protection, account takeover monitoring, and encrypted delivery for regulated patient communications.

EmailEncryption

Identity & Access Reviews

MFA, role-based access, risky sign-in review, credential exposure monitoring, and workforce access processes for systems touching ePHI.

MFAAccess

Endpoint & EHR Workflow Protection

Endpoint detection, device hardening, patch visibility, and practical security controls around workstations used for EHR and patient operations.

EDREndpoints

M365, SaaS & Cloud Hardening

Tenant configuration, file-sharing controls, backup readiness, SaaS permissions, and cloud data exposure reduction for healthcare teams.

M365SaaS

Clinic Network Segmentation

Firewall, Wi-Fi, VPN, DNS filtering, and segmentation guidance to separate clinical systems, guest access, and administrative operations.

NetworkVPN

HIPAA Security Awareness

Workforce-ready training, phishing simulations, and administrator reporting focused on patient privacy, social engineering, and credential theft.

TrainingPhishing Sim

AI Governance for Patient Data

Approved-tool policies, prompt/data handling guidance, agent guardrails, and shadow AI controls so staff do not leak PHI into unsafe systems.

AI PolicyPHI

Multi-Framework Compliance

One control set, mapped across the regulators you answer to — SEC Regulation S-P, FINRA, and CMMC / NIST SP 800-171 readiness alongside your HIPAA program.

SECCMMCNIST
// framework.execute()

The Order of Defense

Nine steps, mapped to the NIST CSF 2.0 functions. Controls applied out of order waste money — you cannot monitor for compromise on systems you have not inventoried.

Identify
Protect
Detect
Respond
Recover
Govern
1.

Map ePHI

Inventory systems, data flows, vendors.

Identify
2.

Verify Access

MFA, roles, joiner/mover/leaver.

Identify
3.

Protect Patients

Reduce phishing, malware, BEC.

Protect
4.

Patch & Update

Fix vulnerabilities quickly.

Protect
5.

Harden Safeguards

Secure endpoints, SaaS, networks.

Protect
6.

Monitor ePHI Risk

Detect suspicious access fast.

Detect
7.

Contain & Document

Triage, preserve evidence, notify.

Respond
8.

Recover Data

Restore from clean backups.

Recover
9.

Prove Readiness

Policies, reports, remediation proof.

Govern

// show.listen()

The SaberGuard Show

Threat breakdowns, compliance deep dives, and practical security advice for small businesses. On YouTube, Apple Podcasts, and Spotify.

// contact.init()

Start Your Risk Analysis

No sales pitch — a direct conversation about your risk posture, your evidence, and what an assessment would actually cover for a practice your size.

11 Apex Dr, Suite 300A #256, Marlborough, MA 01752info@saberguard.tech