The full service catalogue, what each one produces, and how to sequence them without paying for overlap.
The catalogue, item by item
The market sells HIPAA help under a dozen names for perhaps six actual services. Knowing what each one produces is the defence against buying the same work twice under different labels.
- Readiness assessment — a lightweight scored review, often free or near-free (ours is genuinely free), that tells you roughly where you stand. Output: a prioritised list of likely gaps. It is a compass, not a survey.
- Gap assessment — a structured comparison of your programme against every applicable specification of the Privacy, Security, and Breach Notification Rules. Output: a findings register with severity and remediation guidance. See our gap assessment.
- Risk analysis — the §164.308(a)(1)(ii)(A) requirement itself: asset-based, threat-paired, scored, documented. Output: the risk register and methodology document OCR asks for first. This is a regulatory artefact, not just advice.
- Implementation / remediation — someone actually closing the findings: writing policies against your real operations, deploying controls, chasing BAAs, standing up training. Output: a running programme.
- Fractional compliance officer — a retainer for ongoing ownership: the recurring calendar, incident triage, customer questionnaire responses. Output: continuity.
- Incident and breach support — the four-factor assessment, notification drafting, OCR correspondence. Buy this alongside counsel, not instead of counsel.
The right sequence
Readiness assessment, then gap assessment, then risk analysis, then implementation, then platform, then annual review. Buying implementation before assessment means remediating things that may not be your top risks.
The sequence is really a rule about information: never pay for work whose scope you have not measured. The readiness assessment is cheap because it only needs your answers; the gap assessment costs more because it verifies them; the risk analysis costs more again because it inventories and scores; and implementation is priced by everything the earlier steps found. Run in order, each step scopes and therefore disciplines the price of the next. Run out of order — most commonly, an implementation retainer sold to a company that has never been assessed — and you are paying delivery rates for discovery work.
Two legitimate reasons to compress the sequence: a live incident, where remediation cannot wait for elegance, and a dated enterprise deal, where you may run the gap assessment and the most obvious fixes in parallel. In both cases compress it knowingly, not because a vendor’s package happened to bundle it that way.
What overlaps
Gap assessment and risk analysis share the asset inventory. Buy them together and the second should cost less. If a vendor charges full price for both, they are billing you twice for one inventory.
The inventory — which systems hold ePHI, where it flows, who accesses it — is the expensive substrate under both deliverables, typically a third or more of the effort. Other overlaps to price-check: policy templates bundled into implementation engagements (the templates are commodity; the adaptation to your operations is the work — our template library gives the commodity part away), and training content sold per-engagement when it should be a subscription. A vendor’s line-item quote tells you quickly whether they think about overlap; a single blended number tells you they would rather you did not.
Fixed fee versus time and materials
Fixed fee for scoped assessments. T&M only for incident response, where scope genuinely cannot be known in advance.
The underlying principle: whoever can better estimate the work should carry the estimation risk. A vendor who has run fifty gap assessments can price yours; if they insist on T&M anyway, they are transferring their uncertainty to your invoice. The converse holds for incidents — nobody knows on day one how deep a compromise goes, and a vendor offering a fixed-fee breach response is either padding heavily or planning to stop when the fee runs out, both bad. For retainers, insist the scope list what is included per month and what triggers overage, in writing, before the first invoice.
What you should own at the end
Working files, not just the PDF. The risk register in a format you can edit. Policies in DOCX. Evidence in a portable export.
This is the clause to negotiate before signing, because afterwards the leverage is gone. Your documentation obligations run six years under §164.316 — far longer than most vendor relationships — and next year’s review starts from this year’s working files. A locked deliverable means paying the same vendor to update their own PDF annually, which is precisely the business model of the firms that resist this clause. Add two related demands: the methodology (so a different assessor can reproduce the work), and a handover session with the people who will maintain the programme internally.
Choosing a provider
The consultant guide covers vetting in depth, but the short version travels well: ask who specifically does the work, what you own at the end, and whether they will validate remediation afterwards. And walk away from anyone selling “HIPAA certification” — HHS operates no such programme, and a vendor whose headline claim is false is not the vendor to build your evidence base.
Reading a services proposal
Most proposals in this market can be evaluated in four checks. Scope: does it name the entities, systems, and rule sections covered, or does it say “HIPAA compliance review” and leave the boundary to goodwill? Vague scope is where both overbilling and under-delivery hide. Deliverables: is each output named with its format — risk register as editable spreadsheet, policies as DOCX, report with findings severity — or is the deliverable “a report”? Method: does the proposal say how the work happens (interviews, evidence sampling, configuration review) so you can distinguish an assessment from a questionnaire mailed to your inbox? And people: are the individuals named, with healthcare backgrounds you can check?
Two clauses worth adding if absent: a remediation validation option priced now (re-testing findings after you fix them, which turns the report into a closed loop), and the working-files ownership term from above. And one clause worth striking: exclusivity or auto-renewing retainers in a first engagement — earn the renewal with the first deliverable.
The pattern across everything on this page is the same: the services market is healthy where scope is measurable and rotten where it is vague. Sequence the work so each purchase is scoped by the last one, own what you paid for, and keep the recurring maintenance in-house or on-platform where it is cheapest. Judgement is worth buying; persistence is worth owning. If you are unsure which service to buy first, the answer is almost always the free one: the readiness assessment scopes everything that follows.
Where SuperHIPAA fits
Everything above is work. The platform does the parts that are mechanical — evidence collection, acknowledgement tracking, register maintenance, renewal reminders — and our team does the parts that need judgement. You keep the parts that need to be yours.
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.