Three engagements, in the order they usually happen.

starting at $3,500

Security Risk Assessment

The risk analysis 45 CFR 164.308(a)(1)(ii)(A) requires, with your AI surface in scope as standard. Produces the risk register, the risk management plan and the attestation-ready summary letter that a buyer's security team is actually asking for. What it covers.

starting at $5,000

AI Vendor Analysis

When it is one vendor holding the deal rather than your whole posture: their public claims checked against their own legal language and against HIPAA, returned as a verdict and a remediation list. The AI governance page.

from $2,500/mo

Fractional Compliance Officer

For when the answer to "who owns compliance" cannot keep being "the CTO." The function, owned, for under a third of a hire. The comparison, worked.

I built the compliance function at companies like yours.

Inside regulated technology companies I built programs rather than maintaining them: HITRUST certifications, SOC 1 and SOC 2 audits, CMS authorization, and hundreds of BAA negotiations against 45 CFR 164.504(e)(2). I have been the person answering the questionnaire, which is why the deliverables are shaped to be handed straight to the person asking.

I also wrote the software. Rote Compliance is a separate business, and if you would rather run the analysis yourself the compliance skills behind it are open source and free to run.

Questions healthtech teams actually ask.

A buyer sent us a security questionnaire we cannot answer. What do we actually need?

Almost always a current security risk analysis under 45 CFR 164.308(a)(1)(ii)(A), plus the artifacts that hang off it: a risk register, a risk management plan, and BAA language that survives review. That is the Security Risk Assessment: starting at $3,500. The summary letter is written to be handed to a buyer's security team.

Our AI features touch ePHI. Does that change the assessment?

It changes what is in scope, not what the assessment is. OCR expects the risk analysis to cover the AI tools in use, vendor AI access, and the shadow AI nobody put on a list. If the AI surface is the whole reason for the review, the AI Vendor Analysis is the narrower, faster engagement.

We have no compliance team. Is an assessment premature?

No. It is the cheapest possible first move, because it tells you what you are actually facing before you spend on a hire or a platform. Where it usually leads is the Program tier of the retainer at $2,500/mo, which is the compliance function without the headcount.

Do we need HITRUST or SOC 2 too?

Often, eventually, and driven by your buyers rather than by regulation. I have carried organizations through both. The risk analysis is upstream of either: the evidence it produces is reused by both, which is why doing it first is cheaper than doing it after a framework audit tells you to.

Where does the software fit?

Rote Compliance is the platform I built, and it is a separate business at rotecompliance.com. If you want to run the analysis yourself, the open-source compliance skills are free to read and run against your own documents. The platform itself is the instrument behind my delivery rather than a product sold here. What you buy on this site is me doing it.

Bring me the questionnaire.

Thirty minutes. Send the questions your buyer sent you and I'll tell you which of them you can answer today, which need the assessment, and how long the whole thing takes.