If you handle patient, client, or financial data, the law already requires a documented security risk assessment. Most practices don't have one, or have a template regulators are unlikely to accept as a real analysis. We do it properly — local, independent, fixed price.
For medical, dental & behavioral-health practices. The risk analysis OCR asks for first — mapped to NIST 800-30/66, evidence-backed, with a remediation plan.
For CPA, tax & accounting firms. The written security plan you're required to have and attest to at PTIN renewal — real, not a downloaded template.
What an attacker actually sees of your practice online — exposed logins, spoofable email, leaked credentials — with a prioritized fix list.
The $99 online tools give you a fill-in-the-blank PDF. If OCR or the FTC comes asking, that doesn't survive — they want a real analysis, with evidence and a remediation plan. That's what we do.
Serving Marion, Sumter, Lake, Alachua, Citrus & Levy counties — The Villages, Ocala, Gainesville and the Nature Coast. Nonprofits: if you hold donor, applicant-financial, or client data, funders and cyber-insurers now expect a risk assessment — we price it for mission budgets.
We'll show you exactly where you stand — no cost, no obligation — then scope your assessment and send a fixed quote.
Yes. HIPAA requires a Security Risk Analysis, reviewed periodically and whenever something material changes (in practice, at least annually). The FTC Safeguards Rule (GLBA) requires a WISP for tax & accounting firms, and GLBA applies to banks and credit unions. It's a legal requirement, not a best practice — though how it applies to your specific organization is worth confirming with your own counsel.
Great — you're ahead of most. But it has to be current, and regulators have been clear that a fill-in template isn't a real analysis. We'll do a free look and tell you honestly whether yours would hold up.
They may run your systems well, but the assessment is supposed to be independent of whoever manages your IT — you can't grade your own homework. We work alongside IT providers all the time.
It's scoped to your size and systems, then quoted at a fixed price — no surprises, and far less than a single fine. Start with the free exposure grade and we'll take it from there.