Assessments

Independent HIPAA Risk Assessment

An independent, documented risk assessment covering every system that creates, receives, maintains, or transmits ePHI.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

An independent, documented risk assessment covering every system that creates, receives, maintains, or transmits ePHI.

Why an independent assessment

Self-attestation stopped working the moment your customers started sending vendor questionnaires. An independent hipaa risk assessment gives you a dated, third-party document that answers procurement, satisfies cyber-insurance underwriting, and shows an investigator you took §164.308(a)(8) seriously.

Scope

  • Every system, application, and third party in the ePHI path
  • All relevant implementation specifications, marked required or addressable
  • Technical validation against live configuration where access permits
  • Interviews with the people who actually operate the controls

Deliverable

Risk Assessment Report + risk register, containing:

  • Executive summary with an overall posture rating
  • Finding-by-finding detail: observation, rule citation, risk rating, recommendation
  • Prioritised remediation plan with effort estimates
  • Evidence appendix listing what was reviewed and when
  • A shareable customer-facing summary

Timeline and price

Duration2–3 weeks
Starting price$5,500
Re-assessmentIncluded within 90 days
FormatsPDF, DOCX, and loaded into your workspace

What happens after you fill the form

  1. You get the deliverable immediately. No “a rep will contact you to unlock your download.”
  2. We read your answers before we call. The scoping call starts with what you told us, not a discovery script.
  3. You get a fixed-scope, fixed-price proposal in 2 business days — or a straight “you don’t need us yet,” which we say more often than you’d expect.

On the word “certified.” There is no government HIPAA certification. Any vendor selling you a “HIPAA Certificate” is selling a PDF they printed themselves. What regulators, customers, and insurers actually accept is a documented risk analysis, implemented safeguards, and evidence that both are maintained. That is what SuperHIPAA produces.

Questions

Is this an official HIPAA certification?

No. HHS does not certify anyone and no vendor can. This is an independent third-party assessment — the artefact enterprise customers, insurers, and investors actually ask for.

Can we share the report with customers?

Yes. Every report ships in two versions: a full internal report with findings detail, and a shareable summary safe to send to a prospect or partner.

What if the findings are bad?

Then you know, twelve months before OCR does. Every finding comes with a remediation step, an effort estimate, and an owner suggestion.

Do you re-assess after we fix things?

Yes — a remediation validation pass is included within 90 days at no extra cost.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo