// pricing.plans()

Fixed Fees, Scoped Before You Commit

Two risk-analysis tiers by practice size, remediation quoted only where a finding points at it, and senior advisory by the hour.

HIPAA Security Rule risk analysis

Most Popular

Solo Practitioner

$2,500–$3,500fixed fee

One clinician, a few staff, one location, and a Microsoft 365 or Google Workspace tenant nobody has looked at since it was set up.

Signed HIPAA Security Rule risk analysis report
Findings with citation, severity, and the evidence that produced each
Prioritized remediation roadmap
Massachusetts written information security program (201 CMR 17.00 WISP)
Scoped read-only collection setup that can keep running
Findings call to walk through results

Scope is fixed on the scoping call and does not change afterward. Annual Refresh: 40–50% of the initial fee for existing clients.

Start Your Risk Analysis

Small Group

$4,500–$6,500fixed fee

Four to fifteen people, shared systems, an EHR, and a growing list of vendors who touch patient data.

Signed HIPAA Security Rule risk analysis report
Findings with citation, severity, and the evidence that produced each
Prioritized remediation roadmap
Massachusetts written information security program (201 CMR 17.00 WISP)
Scoped read-only collection setup that can keep running
Findings call to walk through results

Scope is fixed on the scoping call and does not change afterward. Annual Refresh: 40–50% of the initial fee for existing clients.

Start Your Risk Analysis

After the baseline

Remediation & Hardening

From $800per system

Findings become fixes on NinjaOne, Guardz, and Microsoft 365, done by the same person who signed the report.

Microsoft 365 hardening: MFA, admin roles, sharing, audit logging
Endpoint management and protection on NinjaOne and Guardz
Identity and MFA rollout, email security, backup and recovery
Security awareness training and incident response

Quoted per project after the risk analysis, when we know what needs fixing.

Contact Us

vCISO & Senior Advisory

$150per hour

Senior security judgment when the situation genuinely needs it, without hiring a security department.

Policy questions, vendor reviews, insurer and auditor conversations
Ongoing security governance for the practice
Decisions that need a security professional in the room

Billed hourly. No retainer required.

Contact Us

SaberGuard assesses and advises. It does not warrant or certify compliance, and nobody honest will promise you an audit outcome. What you get is a defensible analysis, a plan, and a person who answers the phone.

Jonathan DeLeon, founder of SaberGuard

“You are not buying a binder. You are buying the ability to answer, on the day someone asks, exactly what you did to protect patient data — and to show your work.”

Jonathan DeLeonFounder & Security Strategist
CISM®CCSP®10+ yrs in the fieldMarlborough, MA

SaberGuard is deliberately small. You work directly with the person doing the assessment — there is no junior analyst running a template and no account manager between you and the findings.

Read the full background