45 CFR §164.308(a)(1)(ii)(A) · Federal Security Rule

The law already requires your risk analysis. We'll run it for free — and put it to work on your insurance bill.

CompliantSync handles the HIPAA Security Risk Analysis every covered practice and business associate is required to keep on file — then uses that same documentation to shop your cyber insurance for a stronger rate. One relationship, not three vendors.

No obligation · Serving Maryland practices directly, assessments available nationwide
Built on the federal ONC methodology Findings cited to CFR Maryland-based No cost to start
Risk Register — Live Draft
Sample Gap Checklist
All Set
✓
  • Documented risk analysis on file
  • Multi-factor authentication enabled
  • Device & data encryption confirmed
  • Business Associate Agreements on file
  • Staff training logged
Undocumented practices typically see
higher cyber premiums or declined coverage
↓ stronger rate class
$145 – $2,190,294
Per-violation civil penalty range under OCR's current fine schedule (effective Jan 2026) — enforced whether or not a breach ever occurs.
Required, not optional
Every covered entity and business associate must conduct and document a periodic risk analysis under the Security Rule.
Underwriting question #1
Most cyber insurers now ask directly whether a HIPAA risk analysis exists before they'll quote a policy.
The Regulatory Foundation

This isn't a "best practice" pitch. It's a citation.

Every finding in our assessment is mapped back to the actual federal rule that requires it — not a vague recommendation you can safely ignore.

45 CFR §164.308(a)(1)(ii)(A)

HIPAA Security Rule

The implementation specification requiring an accurate, periodic assessment of risks to electronic protected health information. This is the provision OCR checks first after any complaint or breach investigation.

HITECH Act (2009)

Enforcement teeth

Introduced the tiered civil penalty structure and extended direct liability to business associates — billing companies, IT vendors, and EHR hosts included.

HIPAA Omnibus Rule (2013)

Breach notification & audits

Strengthened breach notification obligations and formalized OCR's audit program, increasing the odds an undocumented gap gets discovered.

Note: proposed 2026 updates to the Security Rule (mandatory encryption, MFA, and vulnerability scanning) are not yet final law. We build every recommendation on what's currently enforceable, and we'll flag anything that's still just a proposal — not present it as a requirement it isn't yet.

No Cost To Start

What you get before you ever pay us anything

The goal of the free work is simple: show you exactly where you stand, in plain English, with no pressure to buy anything else.

Free

30-Minute Gap Analysis Call

A plain-English walkthrough of where your practice stands against the Security Rule's risk analysis requirement — no jargon, no obligation, no sales script.

Free

Risk Register & Control-Gap Summary

Built on the federal government's own ONC assessment tool. Every gap we find is mapped to the specific CFR citation it falls under, so you know it's real.

Free

Insurance Marketplace Shopping

We compare cyber liability carriers and place your policy at no direct fee to you — we're compensated by the carrier through a standard placement commission, not by billing you.

The Part Most Consultants Skip

How the assessment can lower what you pay for cyber insurance

  1. Insurers ask before they quote

    Most cyber liability applications now ask directly: do you have a documented HIPAA risk analysis, MFA, and encryption in place?

  2. Undocumented practices get the worst outcome

    No documentation typically means the highest rate tier, coverage exclusions, or an outright decline — regardless of how secure the practice actually is.

  3. Our report becomes your underwriting file

    The same assessment you're required to have doubles as the evidence carriers want to see, strengthening your position before we ever request a quote.

  4. We shop it across carriers, at no cost to you

    Placement is commission-based, so there's no added fee for having us find and compare options on your behalf.

Without documentation
With a completed risk analysis on file

Illustrative only — actual premiums and rate classes vary by carrier, claims history, and practice risk profile. We don't guarantee a specific discount; we do guarantee you'll walk into the underwriting conversation with real documentation instead of none.

Why Choose Us

One relationship, not a compliance dashboard and a separate insurance agent

Integrated by design

Assessment, ongoing compliance, and insurance placement come from one point of contact — not a software subscription plus a separate broker call.

Every finding is cited

No vague "industry best practice" language — each gap ties back to the actual federal regulation, so you know exactly what you're required to fix.

48-hour turnaround

A written proposal within two business days of your gap call — not a multi-week sales cycle.

A human, not just a login

You're working with a Maryland-based expert who answers questions in plain English, not a checkbox SaaS portal.

Aligned incentives on insurance

We're only compensated on placement if you actually get covered — the incentive is getting your practice protected, not billing hours.

No lock-in on insurance

The assessment stands on its own. Placing insurance through us is optional and free to explore — never a condition of the audit.

Not ready to commit? Try us first.

Book the free 30-minute gap call, see the actual findings on your practice, and decide from there — no pressure, no contract required to start.

Try us — book the free call
What We Actually Deliver

Three pieces, one engagement

01 · One-Time

Risk Assessment

A comprehensive Security Risk Analysis using the federal ONC tool, delivered as a written report.

  • Executive summary in plain English
  • Control-gap findings with CFR citations
  • Prioritized remediation checklist
Pricing discussed on your free call
02 · Ongoing

Managed Compliance

Monthly support that keeps your documentation audit-ready year-round instead of stale after 12 months.

  • Remediation tracking
  • Policy & BAA updates
  • Staff training coordination
Pricing discussed on your free call
03 · Passive

Insurance Placement

We shop your completed assessment across cyber liability carriers to find the strongest available rate class.

  • Multi-carrier comparison
  • No direct cost to you
  • Optional, never required
Always free to you
The Process

From free call to audit-ready, in five steps

  1. 01

    Free 30-minute gap call

    We walk through where your practice stands today — no cost, no obligation.

  2. 02

    Risk analysis

    We run the assessment using the federal ONC tool and a technical vulnerability scan.

  3. 03

    Written report, within 48 hours

    A findings report and prioritized remediation roadmap you can act on immediately.

  4. 04

    Insurance shopping (optional)

    We use the documentation to compare cyber carriers and place a policy, at no direct cost to you.

  5. 05

    Ongoing managed compliance

    A monthly retainer keeps everything current so next year's review starts from "already documented," not zero.

Who We Serve

Small practices and the businesses that support them

Risk assessments are available nationwide. Insurance placement is currently licensed in Maryland, with broker partnerships expanding coverage elsewhere.

Physicians & family medicine Dental practices Chiropractic Physical therapy Behavioral health Medical billing companies EHR hosting providers Healthcare IT / MSPs
Questions

Before you book the call

Is this only for Maryland practices? +

No. Risk assessments are available to practices and business associates nationwide. Insurance placement is currently licensed in Maryland, and we're expanding to other states through broker partnerships.

What if we've never done a risk analysis before? +

That's the norm, not the exception — most small practices haven't. It's also the first thing OCR looks for after any complaint or breach, so starting now is better than waiting for a reason to.

Why not just use one of the compliance software subscriptions? +

Those tools are fine for tracking paperwork once it exists. Where they fall short is getting you there in the first place — someone still has to interpret the questions correctly, judge the actual risk level, and turn findings into a plan your insurer will accept. We do that part as a person, not a login, and the documentation we produce works whether or not you ever touch a dashboard.

Do I have to buy insurance through you? +

No. The assessment stands on its own as a compliance deliverable. Insurance shopping is optional, free to explore, and never a condition of the audit.

What does the free call actually cost me? +

Nothing. Thirty minutes of your time, no obligation, and no follow-up pressure if it's not a fit.

Will my premium definitely go down? +

We can't promise a specific number — that depends on the carrier and your practice's overall risk profile. What we can promise is that undocumented risk is one of the most common reasons small practices get quoted high or declined outright, and this fixes that gap.

Get Started

Book your free 30-minute HIPAA gap call

Pick whatever's easiest — call, message, or email us directly, or fill out the form and we'll reach out to you.

Not ready to talk yet? Check your own risk score first — a free 60-second self-assessment, right here on the site, no call required.

Prefer to schedule ahead? Fill this out and we'll call you back — no spam, no obligation.