Four triggers, one underlying job.

The renewal
A payer, a health system partner or a cyber insurer asks for the risk analysis, and the most recent one is older than anyone wants to say out loud.
The attestation
MIPS Promoting Interoperability comes due and the attestation requires two statements you cannot currently make honestly.
The incident
Something happened, a lost laptop, a misdirected fax, a phishing click, and the incident response plan turns out to be a paragraph in a policy nobody has opened.
The letter
OCR sends a data request. Its Risk Analysis Initiative exists because the risk analysis is the most frequently cited deficiency in investigations.

All four are the same job surfacing in different clothes. Keeping a program current is continuous work, and it only ever gets an hour when something forces it. The assessment tells you where you actually stand. The retainer is what gives that work a standing owner instead of an emergency.

Find out, then fix it and keep it fixed.

starting at $3,500

Security Risk Assessment

The analysis 45 CFR 164.308(a)(1)(ii)(A) requires, conducted on site, because 45 CFR 164.310 is about your building, and the workstation facing the waiting room does not appear on any intake form. Risk register, 30/60/90 risk management plan, attestation-ready summary letter. Full scope.

from $2,500/mo

Fractional Compliance Officer

A compliance officer at your size runs $95K–$130K once benefits and recruiting are counted. This is under a third of that, with a name on your org chart. Half your assessment fee credits to your first month on retainer. The tiers.

Nonprofit and public single-site organizations: the Small-Organization SRA is starting at $1,750. Behavioral health and SUD programs also carry 42 CFR Part 2. See Part 2 alignment. Several state provisions outrank the federal floor. See state law above HIPAA.

Questions provider organizations actually ask.

Our risk analysis is three years old. How bad is that?

Bad in the specific way OCR looks for. The analysis has to be reviewed as your environment changes, and MIPS requires one unique to each performance period. A three-year-old analysis that predates your current EHR, your telehealth stack and every AI tool in the building is not an analysis of your environment. The refresh is the starting at $3,500 assessment.

Who actually owns compliance here? Right now it is our practice manager.

That is the most common answer, and it is a sound one: at your size compliance is not a full-time role, and a practice manager who knows the building is a better custodian than an outsider who does not. What the arrangement cannot do is keep the program current between audits, because that is continuous work competing with a full job. The Program retainer at $2,500/mo is that function owned by someone whose whole job it is.

We report MIPS. What exactly are we attesting to?

Two statements, both in the Promoting Interoperability category: that a security risk analysis was conducted or reviewed during the calendar year (45 CFR 164.308(a)(1)(ii)(A)), and that risk management activities implemented security measures to address what it found (45 CFR 164.308(a)(1)(ii)(B)). Miss either and the whole category scores zero, which puts the 75-point threshold and up to a 9% adjustment on 2028 Medicare payments in play. Groups of 15 or fewer clinicians are reweighted out in 2026, but the Security Rule obligation applies regardless.

Our BAA stack grew without anyone managing it.

Normal, and it is in scope. BAAs get reviewed against 45 CFR 164.504(e)(2) during the assessment, and remediation language comes with the findings. Keeping the stack current afterward is a retainer function, not a one-time one.

We are a nonprofit / public entity. Is there a lower price?

Yes. Single-site organizations that are nonprofit or public, under roughly $2M revenue, or 15 or fewer staff qualify for the Small-Organization SRA at starting at $1,750. If real complexity surfaces, the engagement routes to the full assessment with that fee credited.

Multiple facilities under one program: how does that price?

Per site. The first site carries the program-level work, so additional sites are cheaper than the first. We scope it on the call rather than guessing here.

Thirty minutes, and you'll know where you stand.

Tell me what triggered this: the renewal, the attestation, the incident, the letter. I'll tell you which engagement fits and what it costs. If the honest answer is that you don't need me yet, you'll get that instead.