A compliance program with an owner stays current between the emergencies.
In most practices this size, compliance sits with a practice manager or an IT lead on top of a full job. That is the right call for the constraint: at your size it is not a full-time role, and the person carrying it is usually doing it well. What the arrangement cannot do is stay current continuously, because staying current is its own work and nobody's week has that hour already in it.
Four triggers, one underlying job.
All four are the same job surfacing in different clothes. Keeping a program current is continuous work, and it only ever gets an hour when something forces it. The assessment tells you where you actually stand. The retainer is what gives that work a standing owner instead of an emergency.
Find out, then fix it and keep it fixed.
Security Risk Assessment
The analysis 45 CFR 164.308(a)(1)(ii)(A) requires, conducted on site, because 45 CFR 164.310 is about your building, and the workstation facing the waiting room does not appear on any intake form. Risk register, 30/60/90 risk management plan, attestation-ready summary letter. Full scope.
Fractional Compliance Officer
A compliance officer at your size runs $95K–$130K once benefits and recruiting are counted. This is under a third of that, with a name on your org chart. Half your assessment fee credits to your first month on retainer. The tiers.
Nonprofit and public single-site organizations: the Small-Organization SRA is starting at $1,750. Behavioral health and SUD programs also carry 42 CFR Part 2. See Part 2 alignment. Several state provisions outrank the federal floor. See state law above HIPAA.
Questions provider organizations actually ask.
Bad in the specific way OCR looks for. The analysis has to be reviewed as your environment changes, and MIPS requires one unique to each performance period. A three-year-old analysis that predates your current EHR, your telehealth stack and every AI tool in the building is not an analysis of your environment. The refresh is the starting at $3,500 assessment.
That is the most common answer, and it is a sound one: at your size compliance is not a full-time role, and a practice manager who knows the building is a better custodian than an outsider who does not. What the arrangement cannot do is keep the program current between audits, because that is continuous work competing with a full job. The Program retainer at $2,500/mo is that function owned by someone whose whole job it is.
Two statements, both in the Promoting Interoperability category: that a security risk analysis was conducted or reviewed during the calendar year (45 CFR 164.308(a)(1)(ii)(A)), and that risk management activities implemented security measures to address what it found (45 CFR 164.308(a)(1)(ii)(B)). Miss either and the whole category scores zero, which puts the 75-point threshold and up to a 9% adjustment on 2028 Medicare payments in play. Groups of 15 or fewer clinicians are reweighted out in 2026, but the Security Rule obligation applies regardless.
Normal, and it is in scope. BAAs get reviewed against 45 CFR 164.504(e)(2) during the assessment, and remediation language comes with the findings. Keeping the stack current afterward is a retainer function, not a one-time one.
Yes. Single-site organizations that are nonprofit or public, under roughly $2M revenue, or 15 or fewer staff qualify for the Small-Organization SRA at starting at $1,750. If real complexity surfaces, the engagement routes to the full assessment with that fee credited.
Per site. The first site carries the program-level work, so additional sites are cheaper than the first. We scope it on the call rather than guessing here.
Thirty minutes, and you'll know where you stand.
Tell me what triggered this: the renewal, the attestation, the incident, the letter. I'll tell you which engagement fits and what it costs. If the honest answer is that you don't need me yet, you'll get that instead.