The yearly re-evaluation the Security Rule expects, packaged so you can hand it to a customer, an insurer, or an investigator.
Who this is for
Organisations that already know roughly where they stand and need the work done — not another vendor explaining what HIPAA is. Covered entities and business associates both, from 10-person health tech startups to multi-site provider groups.
How the engagement runs
- Re-run of the risk analysis against changes in the environment
- Control effectiveness re-testing
- Policy currency and acknowledgement review
- BAA and vendor re-verification
- Year-over-year posture comparison
What you get
- Annual Review Report
- Updated risk register and treatment plan
- Refreshed evidence package
- Next-year remediation roadmap
Timeline and price
| Typical duration | 2 weeks |
| Starting price | $4,000 |
| Delivered by | Named healthcare compliance lead, not a rotating bench |
| Deliverable format | PDF + DOCX + loaded into your SuperHIPAA workspace |
Scope drivers that move the price: number of legal entities, number of clinical or production systems in scope, whether ePHI crosses a cloud boundary, and how much prior documentation exists.
Why teams pick us over a generalist consultancy
A generalist gives you a report. We give you a report and the system that keeps it true twelve months later. The deliverable is not a PDF you file — it is a populated risk register, a live evidence library, and a workforce that has acknowledged the current version of every policy.
What happens after you fill the form
- You get the deliverable immediately. No “a rep will contact you to unlock your download.”
- We read your answers before we call. The scoping call starts with what you told us, not a discovery script.
- You get a fixed-scope, fixed-price proposal in 2 business days — or a straight “you don’t need us yet,” which we say more often than you’d expect.
On the word “certified.” There is no government HIPAA certification. Any vendor selling you a “HIPAA Certificate” is selling a PDF they printed themselves. What regulators, customers, and insurers actually accept is a documented risk analysis, implemented safeguards, and evidence that both are maintained. That is what SuperHIPAA produces.