A HIPAA Security Risk Analysis that is conducted, not filled in.
Published price: $2,895 · one engagement, no subscription.
Sentinel examines where your electronic patient information actually lives, the threats specific to your practice, and the safeguards you already have — then records a risk determination with the reasoning behind it. You receive a written analysis, a Remediation Register naming an owner and a target date for every finding, and a scheduled return at six months to document what actually happened.
Requesting the standalone SRA opens a short form. We confirm scope and timing with you before anything begins, and no payment is taken from the form.
- The conducted analysis and written report
- The Remediation Register
- Federal exclusion screening, twice
- The six-month remediation review
Paid once, before the engagement begins. Nothing further is due when we return at six months.
Ask the questions you’d ask before requesting an SRA.
Georgia, Sentinel’s AI assistant, can explain the standalone Security Risk Analysis, what the published price includes, and what happens at the six-month review. No contact details required to ask.
Please don’t include patient information in this chat.
One defined engagement. One usable record. One scheduled return.
Grouped by what each part is for, rather than listed as one long column.
The analysis
- Where your electronic patient information lives — the systems, the flows, and the people who touch them
- Threats and existing safeguards, examined against the practice you are actually running
- Documented risk levels, each with the rationale recorded rather than assumed
- A dated written analysis for the practice record
The path forward
- A Remediation Register: every finding with an assigned owner, a target date, and the evidence required to close it
- Findings prioritised, so the practice knows what to address first
- Each finding records what Sentinel reviewed and what the practice reported
The follow-through
- Federal exclusion screening at the assessment, and again at the six-month review
- A Six-Month Remediation Review against the Register
- A written status report: what closed, what is still open, and what changed
Four steps, and you always know which one you are in.
-
1
Scope and confirm
We confirm what is being assessed — providers, locations, systems — and the expected start date, before anything begins. For a single independent practice the price is the published $2,895; multi-location groups are scoped first, so the number is known before any work starts.
-
2
Structured intake
A guided intake covering systems, vendors, safeguards and documentation, followed by a working session with the people who actually run the practice. Sentinel does not require standing access to your network, and does not need patient records.
-
3
Analysis and delivery
Sentinel rates likelihood and impact, records the reasoning, and delivers the written analysis with the Remediation Register. Every item names an owner, a target date, and the evidence that would close it.
-
4
The six-month review
Sentinel returns on schedule, reviews every Register item against the evidence the practice can produce, and issues the status report. Included in the one-time fee.
Finding the risk is the first half. Showing what happened next is the second.
A risk analysis records findings at a point in time. Sentinel includes a Remediation Register and a six-month review so your practice can revisit the findings, document its progress and keep unresolved items visible.
This engagement includes a scheduled return. Six months after the analysis, Sentinel reviews every item on the Remediation Register against the evidence the practice can produce, and issues a Six-Month Remediation Status Report: what closed, what is still open, and what changed.
If nothing has been closed, the report says so plainly. That is the point of asking.
What the six-month review is not. It is not a second Security Risk Analysis. It does not re-rate risk or re-evaluate safeguards. It documents what happened to the findings from the analysis it reports against, and it says so on its face. There is no second invoice for it.
Read a complete engagement before you buy one.
Both documents, exactly as delivered — prepared for a fictional practice, so nothing has to be withheld.
Sample Security Risk Analysis
The full analysis and Remediation Register as a practice receives them — findings, risk determinations with their reasoning, owners, target dates, and the evidence required to close each item.
Open the sample (PDF) → Fictional practice · demonstrationSample Six-Month Status Report
The report sent six months later, showing what actually happened to each finding in the analysis above — including the items that were not closed.
Open the sample (PDF) →These are demonstration documents prepared for a fictional practice. They show what the deliverable is — they are not the results of any client engagement.
A representation and a reviewed document are not the same fact.
A practice answering “yes, we have backups” is a representation. A backup log Sentinel actually read is evidence. Most reports render the two identically, which quietly turns an answer into a verification. Every safeguard and every finding in this analysis carries its own classification, and the report states which is which.
What this engagement does not do
This is a point-in-time Security Risk Analysis. Sentinel documents the risks, provides the Remediation Register, and returns once at six months to document remediation status. The practice remains responsible for implementing corrective actions. Sentinel does not perform penetration testing, vulnerability scanning or managed IT, does not implement technical safeguards, and does not provide legal advice.
Exclusion screening scope, stated precisely. Screening covers the federal sources — the OIG List of Excluded Individuals and Entities and the GSA SAM exclusions. Texas practices are additionally screened against the Texas HHSC exclusion list. Screening against another state’s list is confirmed with you before the engagement rather than assumed.
Delivered remotely, anywhere in the United States. The HIPAA Security Rule reads the same in Ohio as it does in Texas. The engagement is conducted through a structured intake, a working session with the people who run the practice, and a guided walkthrough of the physical environment where that matters. Sentinel is based in Houston; on-site onboarding remains available across Greater Houston for practices that prefer it.
Reassessment pacing. Sentinel recommends annual reassessment as a professional operating standard. The Security Rule names no fixed interval; an updated analysis is called for sooner after material change.
Yes, it is required. No, the rule does not say annually.
The HIPAA Security Rule lists risk analysis as a required implementation specification, and § 164.306(d)(2) says a covered entity must implement the specifications marked Required. Its words are to “conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information.”
45 C.F.R. § 164.308(a)(1)(ii)(A)
What the rule does not do is name a deadline. HHS guidance is explicit that no frequency is specified, and that the analysis should be reviewed and updated as your circumstances change. Annual is a professional operating standard — ours included — not a legal one.
The practical test is not the date on your last analysis. It is whether that analysis still describes the practice you are actually running. An updated analysis is called for sooner after material change: new systems, new locations, new vendors, a security incident, a change in how patient information moves.
Follows HHS OCR, Guidance on Risk Analysis Requirements under the HIPAA Security Rule (July 14, 2010). The Remediation Register implements its corrective-action element.
Is the analysis included in the managed program?
Yes. The Security Risk Analysis is included in Sentinel’s fully managed program. This $2,895 engagement exists for practices that want the analysis on its own — fixed scope, defined end, no membership required. If you later move to the managed program, this fee is credited toward it, so starting here costs you nothing in the end.
What the analysis costs, in detail · how the managed service works
Could we use the free HHS tool instead?
Sometimes, yes. We have written out the difference — including when the free tool is the right choice for a practice.
Will you sign a Business Associate Agreement?
Yes, and we would rather have one in place than argue about whether it is required. Worth knowing why that is an easy yes: the analysis looks at how you protect patient information, not at the information itself, so patient records are not something you send us and not something we hold.
How soon can you start?
Usually within a few business days of the engagement being confirmed. Exact timing depends on current availability and how quickly the practice can provide the initial information. We confirm the expected start date before the engagement begins rather than promising a turnaround we have not checked.
What if we need to cancel?
If you cancel before substantive work begins, you receive a full refund. Once work has begun, cancellation is based on the stage of the engagement and the work already performed, and Sentinel explains any applicable amount before processing it. Once the final analysis is substantially complete or delivered, there is no cancellation refund.
Tell us about your practice.
We confirm scope, price and timing with you before anything begins. No obligation, and no payment is taken from this form.