Compliance & Risk Assessments

The security assessment your practice is required to have — done right.

If you handle patient, client, or financial data, the law already requires a documented security risk assessment. Most practices don't have one, or have a template regulators are unlikely to accept as a real analysis. We do it properly — local, independent, fixed price.

See your free exposure gradeGet a quote
It's not optional — and it's not a "someday." HIPAA §164.308(a)(1)(ii)(A) requires a Security Risk Analysis, reviewed periodically and whenever something material changes (in practice, at least annually). The FTC Safeguards Rule (GLBA, 16 CFR 314) requires a Written Information Security Plan (WISP) for tax & accounting firms — the IRS reinforces this at PTIN renewal. GLBA and the Interagency Security Guidelines (examined under FFIEC) apply to banks and credit unions. The only real question is whether the one you have would stand up when someone asks for it.

What we deliver

HIPAA Security Risk Assessment

For medical, dental & behavioral-health practices. The risk analysis OCR asks for first — mapped to NIST 800-30/66, evidence-backed, with a remediation plan.

IRS WISP & FTC Safeguards

For CPA, tax & accounting firms. The written security plan you're required to have and attest to at PTIN renewal — real, not a downloaded template.

External Security Review

What an attacker actually sees of your practice online — exposed logins, spoofable email, leaked credentials — with a prioritized fix list.

Why a template isn't enough

The $99 online tools give you a fill-in-the-blank PDF. If OCR or the FTC comes asking, that doesn't survive — they want a real analysis, with evidence and a remediation plan. That's what we do.

  • Framework-mapped (NIST 800-30/66, FTC Safeguards Rule 16 CFR 314)
  • Evidence-backed, not checkbox-only
  • Prioritized remediation plan with owners
  • A signed, evidence-backed document designed to withstand scrutiny
  • Free re-test after you fix the findings

Why Breakglass

  • Local. We drive out. You call a person 20 minutes away, not a 1-800 number.
  • Independent. Separate from whoever runs your IT — the way an assessment is supposed to be.
  • Credentialed. Veteran-owned; OSCP / GXPN / GCTI certified; we publish real threat research.
  • Fixed price, fast. Scoped to your size, no open-ended bills.

Who it's for

DentalMedicalBehavioral healthCPA / TaxLaw firmsBanks & Credit UnionsNonprofits

Serving Marion, Sumter, Lake, Alachua, Citrus & Levy counties — The Villages, Ocala, Gainesville and the Nature Coast. Nonprofits: if you hold donor, applicant-financial, or client data, funders and cyber-insurers now expect a risk assessment — we price it for mission budgets.

Start with a free 2-minute look.

We'll show you exactly where you stand — no cost, no obligation — then scope your assessment and send a fixed quote.

Get my free exposure gradeBook 15 minutes

Common questions

Do we really have to do this?

Yes. HIPAA requires a Security Risk Analysis, reviewed periodically and whenever something material changes (in practice, at least annually). The FTC Safeguards Rule (GLBA) requires a WISP for tax & accounting firms, and GLBA applies to banks and credit unions. It's a legal requirement, not a best practice — though how it applies to your specific organization is worth confirming with your own counsel.

We already did one / have a template.

Great — you're ahead of most. But it has to be current, and regulators have been clear that a fill-in template isn't a real analysis. We'll do a free look and tell you honestly whether yours would hold up.

Our IT company handles security.

They may run your systems well, but the assessment is supposed to be independent of whoever manages your IT — you can't grade your own homework. We work alongside IT providers all the time.

What does it cost?

It's scoped to your size and systems, then quoted at a fixed price — no surprises, and far less than a single fine. Start with the free exposure grade and we'll take it from there.