Skip to content
CISO Marketplace Services

HIPAA/HITECH Compliance Assessment

Comprehensive evaluation of your organization's compliance with HIPAA and HITECH regulations, focusing on the protection of electronic protected health information (ePHI). Our assessment examines technical, administrative, and physical safeguards, providing a detailed gap analysis and remediation plan to achieve and maintain compliance while reducing the risk of breaches and penalties.

In scope

  • HIPAA Security Rule assessment
  • HIPAA Privacy Rule evaluation
  • Breach notification process review
  • Business associate management assessment
  • Technical safeguards evaluation
  • Administrative safeguards review
  • Physical safeguards assessment
  • ePHI data flow analysis
  • Access control implementation review
  • Audit logging and monitoring evaluation
  • Risk analysis methodology assessment
  • Incident response capability review
  • HITECH compliance review
  • Patient data handling assessment

You receive

  • HIPAA/HITECH compliance report
  • Gap analysis and findings
  • Technical safeguards enhancement plan
  • Administrative controls framework
  • Physical security recommendations
  • ePHI protection strategy
  • Business associate agreement review
  • Risk assessment methodology improvements
  • Breach response procedure updates
  • Compliance documentation recommendations
  • Remediation roadmap and timeline

Tiers

Choose the depth.

Essential HIPAA/HITECH Assessment

$36K

HIPAA / HITECH gap assessment for up to 100 employees, 1 site and up to 10 business associates: Security Rule, Privacy Rule and breach notification review, ePHI data flow analysis, safeguards evaluation by interview and document review. Report and roadmap.

employees
100
Sites
1
vendors
10
  • Security Rule, Privacy Rule and breach notification review
  • Administrative, physical and technical safeguards evaluation
  • ePHI data flow analysis
  • Business associate agreement review for up to 10 BAs
  • Compliance report, gap analysis and remediation roadmap
  • — Technical configuration review of access control and logging
  • — Policy and documentation writing
  • — Training
  • — Implementation support
Scope Essential HIPAA/HITECH Assessment

Comprehensive HIPAA Compliance Program

$65K

For up to 500 employees, up to 5 sites and up to 30 business associates. Adds configuration-level review of access control, audit logging and monitoring, an administrative controls framework, updated breach response procedures and compliance documentation.

employees
500
Sites
5
vendors
30
  • Everything in the Essential assessment
  • Configuration review of access control, audit logging and monitoring
  • Technical safeguards enhancement plan
  • Administrative controls framework
  • Breach response procedures updated
  • Compliance documentation written
  • — Workforce training delivery
  • — Hands-on implementation support
  • — Governance framework
  • — Penetration testing
Scope Comprehensive HIPAA Compliance Program

Enterprise Healthcare Compliance Framework

$110K

Advanced compliance program for complex healthcare environments with custom implementation support, training, and governance framework

employees
2500
Sites
15
vendors
75
sessions
4
  • — Ongoing program management (see Healthcare Compliance Program)
  • — Penetration testing or vulnerability scanning
  • — Legal representation in OCR matters
Scope Enterprise Healthcare Compliance Framework

Members: engagement coupons from the CISO Marketplace coupon book apply to services. There is no blanket discount.

What's inside this engagement

Phase by phase.

How a readiness & governance assessment engagement runs, what happens in each phase and what you see. Exact scope, tier and timeline are fixed in your proposal and SOW.

  1. 01Scoping & framework selection

    The standard or regulation, the systems and the business units in scope are fixed.

    You see · Your audit or regulatory driver.

  2. 02Evidence collection & interviews

    Policies, configurations and records reviewed; control owners interviewed.

    You see · Documents and time with control owners.

  3. 03Gap analysis

    Each requirement mapped to current state: met, partial or missing, with the evidence behind it.

    You see · A clear gap register.

  4. 04Roadmap & evidence plan

    Prioritized remediation with owners, and the evidence an auditor will ask for.

    You see · A plan you can execute or hand to us.

Commercials

From first call to final report.

  1. 01

    Scoping call

    A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.

  2. 02

    Proposal & rules of engagement

    A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.

  3. 03

    Sign, then start

    MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.

  4. 04

    Execution

    Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.

  5. 05

    Report & debrief

    An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.

  6. 06

    Retest

    Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.

Timelines are set per engagement in the SOW.

Related

Research

Latest from the blog

All posts on cisomarketplace.com →
Talk to an advisor
Advisor