# HIPAA/HITECH Compliance Assessment

> From $36K · Compliance & GRC · https://cisomarketplace.services/services/hipaa-hitech-compliance-assessment

Comprehensive evaluation of your organization's compliance with HIPAA and HITECH regulations, focusing on the protection of electronic protected health information (ePHI). Our assessment examines technical, administrative, and physical safeguards, providing a detailed gap analysis and remediation plan to achieve and maintain compliance while reducing the risk of breaches and penalties.

## In scope

- HIPAA Security Rule assessment
- HIPAA Privacy Rule evaluation
- Breach notification process review
- Business associate management assessment
- Technical safeguards evaluation
- Administrative safeguards review
- Physical safeguards assessment
- ePHI data flow analysis
- Access control implementation review
- Audit logging and monitoring evaluation
- Risk analysis methodology assessment
- Incident response capability review
- HITECH compliance review
- Patient data handling assessment

## Deliverables

- HIPAA/HITECH compliance report
- Gap analysis and findings
- Technical safeguards enhancement plan
- Administrative controls framework
- Physical security recommendations
- ePHI protection strategy
- Business associate agreement review
- Risk assessment methodology improvements
- Breach response procedure updates
- Compliance documentation recommendations
- Remediation roadmap and timeline

## Tiers

### Essential HIPAA/HITECH Assessment: $36K

HIPAA / HITECH gap assessment for up to 100 employees, 1 site and up to 10 business associates: Security Rule, Privacy Rule and breach notification review, ePHI data flow analysis, safeguards evaluation by interview and document review. Report and roadmap.

Limits: employees 100, locations 1, vendors 10

Includes:
- Security Rule, Privacy Rule and breach notification review
- Administrative, physical and technical safeguards evaluation
- ePHI data flow analysis
- Business associate agreement review for up to 10 BAs
- Compliance report, gap analysis and remediation roadmap

Excludes:
- Technical configuration review of access control and logging
- Policy and documentation writing
- Training
- Implementation support

### Comprehensive HIPAA Compliance Program: $65K

For up to 500 employees, up to 5 sites and up to 30 business associates. Adds configuration-level review of access control, audit logging and monitoring, an administrative controls framework, updated breach response procedures and compliance documentation.

Limits: employees 500, locations 5, vendors 30

Includes:
- Everything in the Essential assessment
- Configuration review of access control, audit logging and monitoring
- Technical safeguards enhancement plan
- Administrative controls framework
- Breach response procedures updated
- Compliance documentation written

Excludes:
- Workforce training delivery
- Hands-on implementation support
- Governance framework
- Penetration testing

### Enterprise Healthcare Compliance Framework: $110K

Advanced compliance program for complex healthcare environments with custom implementation support, training, and governance framework

Limits: employees 2500, locations 15, vendors 75, sessions 4

Excludes:
- Ongoing program management (see Healthcare Compliance Program)
- Penetration testing or vulnerability scanning
- Legal representation in OCR matters

## Terms

Starting price shown is the lowest published tier. A written proposal fixes scope, tier and price before anything is signed. Timeline is set in the SOW.

Scope this engagement: https://cisomarketplace.services/scope?service=hipaa-hitech-compliance-assessment
