# HIPAA Security Risk Analysis — Small Practice

> From $3.5K · Compliance & GRC · https://cisomarketplace.services/services/hipaa-security-risk-analysis-small-practice

The Security Rule requires every covered entity and business associate to perform a security risk analysis. This engagement delivers exactly that for small and mid-sized practices: an asset and ePHI inventory, threat and vulnerability analysis, risk ratings, and a remediation plan you can show OCR, a payer or a cyber insurer. It is the entry point below the full HIPAA/HITECH Compliance Assessment.

## In scope

- ePHI asset and data-flow inventory
- Administrative, physical and technical safeguard review
- Threat, vulnerability and risk rating per asset
- Remediation plan with owners and dates
- Policy and BAA gap check

## Deliverables

- HIPAA security risk analysis report
- Risk register
- Remediation plan
- Attestation summary for insurers and partners

## Tiers

### Essential Practice SRA: $3.5K

Single-location practice with up to 25 staff: ePHI inventory, safeguard review, risk register and remediation plan.

Limits: employees 25, locations 1

Excludes:
- Technical vulnerability scanning
- Policy authoring
- More than one location

### Advanced Practice SRA: $6.5K

Up to 100 staff AND up to 3 locations (exceeding either moves to the next tier): adds policy gap review, BAA review and a staff training session.

Limits: employees 100, locations 3

Excludes:
- Technical vulnerability scanning
- EHR vendor review

### Enterprise Practice SRA: $12.5K

Multi-location groups and business associates up to 500 staff and 10 locations: adds a technical vulnerability scan, EHR and vendor review and a 90-day remediation check. Larger organizations need the HIPAA/HITECH Compliance Assessment.

Limits: employees 500, locations 10

Excludes:
- Organizations above 500 staff — use the HIPAA/HITECH Compliance Assessment
- Penetration testing

## Terms

Starting price shown is the lowest published tier. A written proposal fixes scope, tier and price before anything is signed. Timeline is set in the SOW.

Scope this engagement: https://cisomarketplace.services/scope?service=hipaa-security-risk-analysis-small-practice
