The deal is stuck behind a security review, and the questionnaire assumes a compliance function you don't have yet.
The questionnaire runs forty questions deep and presumes a risk analysis, a register, a training log and a BAA posture. The artifact set that clears it should be built once, well enough that the next buyer's review does not start over.
Three engagements, in the order they usually happen.
Security Risk Assessment
The risk analysis 45 CFR 164.308(a)(1)(ii)(A) requires, with your AI surface in scope as standard. Produces the risk register, the risk management plan and the attestation-ready summary letter that a buyer's security team is actually asking for. What it covers.
AI Vendor Analysis
When it is one vendor holding the deal rather than your whole posture: their public claims checked against their own legal language and against HIPAA, returned as a verdict and a remediation list. The AI governance page.
Fractional Compliance Officer
For when the answer to "who owns compliance" cannot keep being "the CTO." The function, owned, for under a third of a hire. The comparison, worked.
I built the compliance function at companies like yours.
Inside regulated technology companies I built programs rather than maintaining them: HITRUST certifications, SOC 1 and SOC 2 audits, CMS authorization, and hundreds of BAA negotiations against 45 CFR 164.504(e)(2). I have been the person answering the questionnaire, which is why the deliverables are shaped to be handed straight to the person asking.
I also wrote the software. Rote Compliance is a separate business, and if you would rather run the analysis yourself the compliance skills behind it are open source and free to run.
Questions healthtech teams actually ask.
Almost always a current security risk analysis under 45 CFR 164.308(a)(1)(ii)(A), plus the artifacts that hang off it: a risk register, a risk management plan, and BAA language that survives review. That is the Security Risk Assessment: starting at $3,500. The summary letter is written to be handed to a buyer's security team.
It changes what is in scope, not what the assessment is. OCR expects the risk analysis to cover the AI tools in use, vendor AI access, and the shadow AI nobody put on a list. If the AI surface is the whole reason for the review, the AI Vendor Analysis is the narrower, faster engagement.
No. It is the cheapest possible first move, because it tells you what you are actually facing before you spend on a hire or a platform. Where it usually leads is the Program tier of the retainer at $2,500/mo, which is the compliance function without the headcount.
Often, eventually, and driven by your buyers rather than by regulation. I have carried organizations through both. The risk analysis is upstream of either: the evidence it produces is reused by both, which is why doing it first is cheaper than doing it after a framework audit tells you to.
Rote Compliance is the platform I built, and it is a separate business at rotecompliance.com. If you want to run the analysis yourself, the open-source compliance skills are free to read and run against your own documents. The platform itself is the instrument behind my delivery rather than a product sold here. What you buy on this site is me doing it.
Bring me the questionnaire.
Thirty minutes. Send the questions your buyer sent you and I'll tell you which of them you can answer today, which need the assessment, and how long the whole thing takes.