Service 07 · Subscription
A Risk Analysis That Is
Never Out Of Date.
HIPAA does not treat the Risk Analysis as a one-time project. 45 CFR 164.306(e) requires ongoing review, and OCR asks for the current document, not the one you commissioned three years ago. This subscription keeps it current: a full written Risk Analysis every year, plus updates whenever a new vendor, system, location, or incident changes the picture. You are always able to produce a document that matches the practice as it actually exists.
Why A Subscription
The Requirement Is Ongoing.
Most Documents Are Not.
A Risk Analysis is a snapshot of a practice on the day it was written. Practices change. You add a cloud backup, switch billing companies, open a second location, bring in a scribe tool. Every one of those changes the risk picture, and none of them update the document sitting in your compliance folder. HHS addresses this directly: 45 CFR 164.306(e) requires ongoing review and modification of security measures, and 45 CFR 164.316(b)(2)(iii) requires documentation to be reviewed periodically and updated in response to operational change. A three-year-old analysis describing systems you no longer run is not an accurate assessment of current risk, and that is the version OCR would be reading.
This is the right service for a practice that wants the Risk Analysis handled permanently rather than rebuilt from scratch every few years, usually under deadline pressure from an insurer, an auditor, or an OCR letter.
Engagement Summary
Full Risk Analysis, Every Year
Each subscription year produces a complete written Risk Analysis mapped to all nine elements of HHS Final Guidance and the five evaluation criteria in the HHS Audit Protocol. Not a diff, not an addendum. A standalone dated and signed document you could hand to an investigator on its own.
Trigger-Event Updates Between Cycles
When something material changes, you report it and the analysis is updated to match. New vendor touching PHI, new or replaced EHR, a new location, a security incident, or a regulatory change. The document keeps pace with the practice instead of drifting away from it.
Maintained Risk Management Plan
The companion document required under 45 CFR 164.308(a)(1)(ii)(B). Each risk above a Low rating carries a decision, a named owner, a specific safeguard, and a target date. On a subscription those items get carried forward and closed out year over year, which is the remediation history OCR looks for.
Living Vendor and BAA Inventory
Every vendor that creates, receives, maintains, or transmits PHI, with current BAA status for each. Vendor churn is the most common reason an inventory goes stale, so it is refreshed at each cycle and whenever you report a new one.
Annual Workforce Training Review
Your training records checked against the standard each year: content, attendance, retraining cadence, and sanctions policy. Turnover is constant in small practices, and training documentation is a recurring citation in enforcement actions.
Annual Readout and Priority Plan
A 60-minute session each cycle covering what changed since last year, what closed, what is still open, and the 30-60-90 day priorities ahead. Over time this becomes a documented trend rather than a one-off report.
How It Works
Year One Builds It.
Every Year Keeps It.
Year One Baseline
The full three-week engagement: structured intake, on-site or remote walkthrough, written Risk Analysis, Risk Management Plan, vendor inventory, training review, and readout. This becomes the baseline every later cycle builds on.
Weeks 1 to 3
Trigger Reporting
Through the year you flag material changes as they happen. A short form for each one: new vendor, new system, new location, incident, or regulatory change. No scheduled meetings required.
Ongoing
Interim Updates
Each reported trigger is assessed and the affected sections of the analysis are updated and re-dated. Scope, threat pairs, and risk scores are adjusted where the change actually moves them, and the revision is logged.
Within 10 business days
Annual Refresh
A condensed two-week cycle each year: refreshed walkthrough, re-scored register, closed items carried forward, and a new signed document with the readout session. Faster than year one because the baseline already exists.
2 weeks, annually
Time Investment
Heaviest In Year One.
Light After That.
Year one is the real build: roughly 6 to 7 hours of practice time spread across a few people over three weeks. Renewal years are substantially lighter because the baseline, the vendor list, and the system inventory already exist and only need to be confirmed and updated. Trigger reporting during the year is a short form, not a meeting.
Year One, All Staff
6 to 7 hrs
Full baseline engagement, distributed across owner, office manager, IT, and billing over three weeks
Each Renewal Year
2 to 3 hrs
Confirm what changed, refreshed walkthrough of affected areas, readout session
Per Trigger Event
10 to 15 min
A short form describing the change; follow-up questions only if the change is complex
Between Cycles
0 hrs
No standing meetings, no portal to maintain, no questionnaire to re-enter
Across a three-year subscription the practice spends roughly 12 hours total and never has a period where the Risk Analysis on file is out of date. The alternative most practices run is a rebuild every few years under deadline pressure, which costs more staff time and produces a document with visible gaps in its history.
Who This Is For
Built for practices that change
faster than their paperwork.
- You already had a Risk Analysis done and do not want to be back at square one in two years
- You add or switch vendors regularly: billing, IT, imaging, scheduling, backup, AI or scribe tools
- You are opening locations or acquiring practices and the compliance program has to follow the footprint
- Your cyber insurance carrier asks for current HIPAA Security Rule documentation at each renewal
- You have no in-house compliance officer and no one whose job it is to notice the analysis went stale
- You want the remediation history that shows OCR a pattern of active compliance, not a single snapshot
- You would rather budget a predictable annual line item than an unplanned project every few years
Common Questions
FAQ
Want to estimate the OCR fine range for a HIPAA violation before committing to a Risk Analysis? Use the free HIPAA Penalty Calculator: verified against the 2026 Federal Register adjustment.
How often does HIPAA actually require the Risk Analysis to be updated?
HHS treats risk analysis as an ongoing process rather than a one-time project. 45 CFR 164.306(e) requires covered entities to review and modify security measures continuously to keep protecting ePHI, and 45 CFR 164.316(b)(2)(iii) requires documentation to be reviewed periodically and updated in response to environmental or operational change. There is no fixed expiration date written into the rule, which is exactly why analyses drift. The working standard is at least annually, and sooner on any material change.
What counts as a trigger event?
Any change that moves the risk picture before the next annual cycle. Onboarding a vendor that touches PHI, adding or replacing a major system such as an EHR or imaging platform, opening a location, a security incident or breach, or a regulatory change affecting the Security Rule. You report it with a short form and the affected sections of the analysis are updated and re-dated within ten business days.
Why is the subscription more per year than the one-time analysis?
The one-time Risk Analysis is $3,500 and gives you an accurate document on the day it is signed. The subscription is $4,500 per year and additionally covers unlimited trigger-event updates between annual cycles, carries your Risk Management Plan items forward year over year, and keeps the vendor and BAA inventory current. You are paying the difference for the document never going stale, and for the remediation history that builds up behind it.
Why does a stale Risk Analysis matter if I have one on file?
OCR asks for the current analysis. A document dated several years back, describing vendors you left and systems you replaced, does not demonstrate an accurate and thorough assessment of the risks you face now. Across the 2026 OCR settlements we reviewed, failure to conduct an accurate and thorough risk analysis was cited in every case, and settlements routinely carry a corrective action plan running two to three years.
Can I start with the one-time analysis and switch later?
Yes. A practice that received a one-time Risk Analysis can move onto the subscription at the next renewal point. The existing document becomes the baseline, so the first subscription cycle runs as a two-week refresh rather than a full three-week rebuild.
Does this help with cyber insurance renewals?
Yes, and the timing is the main advantage. Carriers increasingly ask for evidence of Security Rule compliance at each renewal, and they ask for it on their schedule rather than yours. On a subscription the current Risk Analysis, Risk Management Plan, and vendor inventory already exist when the attestation form arrives, so the renewal does not turn into a scramble.
Keep it current, permanently.
Book a free 30-minute discovery call and we will confirm this is the right starting point for your situation.