For dental, medical, tax, legal & insurance offices
Your staff is already using AI. Do you know what they're putting into it?
In most small offices somebody is pasting patient names, client financials, or case details into a chatbot on their own personal account — and nobody has ever been told not to. Kovyr finds every AI tool in use, tells you what each one does with your data, and hands you the policy that fixes it.
Why a checklist misses it
“We use ChatGPT” is not an answer. It's the start of the question.
The risk was never the tool's reputation. It's the combination of which account it runs on, who approved it, and what information gets typed in. The same product can be two completely different situations in two offices on the same street.
Office A
Business account, agreement on file, staff trained
Your data isn't used to train the vendor's models, there's a contract covering the relationship, and there are written rules about what can go in. Documented and defensible.
Low exposure
Office B
Same tool. Personal free account. Nobody told.
No contract exists at all — so this isn't a vendor problem you can fix with paperwork, it's an uncontrolled disclosure of client information to a company you have no relationship with. And it will not appear on any vendor list.
High exposure
The same distinction runs through everything else in the office — a meeting recorder sitting in on billing calls, an AI assistant that inherits whatever file permissions you already had, a free browser extension reading the screen inside your practice-management system, an automation with far more access than the job needs. None of it shows up as a line item. All of it touches your data.
What you get
Five documents, all written from your assessment.
AI Readiness Report
Where you actually stand: every AI tool in use, what data goes into each one, the risks ranked by severity, and a 30/60/90-day fix list. Written for your business, not a template.
Executive Summary
One page for the owner who will not read the report. Three risks, plain language, one decision to make.
AI Acceptable Use Policy
Drafted from your actual approved tools, your actual data, and your actual obligations — with a signature page for staff. Not a generic download.
Staff One-Pager
Three rules on a desk card. This is the piece that actually changes what people do on a Tuesday afternoon.
Approved Tools Register
The living list you keep afterward — what is allowed, on which account type, for which kind of information.
How it works
About an hour of your time.
1 · Before
A short note goes out to your staff first — framed so people actually admit what they use, instead of hiding it from the boss. That one email finds more than any scan.
2 · On site
One hour, in your office. We walk your tools one at a time and work through a structured set of governance questions, referenced to the NIST AI framework and ISO/IEC 42001.
3 · After
The quiet part: reviewing app permissions, network traffic, browser extensions, and expense records to find what nobody mentioned. Then your five documents.
If you already have a WISP or a HIPAA risk analysis
This isn't a second copy of that. It's the part it doesn't reach.
Your security program is wide and shallow by design — it covers backups, encryption, access, training, incident response, vendors. Its vendor section assumes a company with a contract. An employee on a personal AI account is not a vendor, so the program has nowhere to put them, and they never come up.
An AI inventory is a legitimate input to the written risk assessment you're already required to maintain, and adopting new tools is exactly the kind of change your program is supposed to be re-evaluated against. If Kovyr wrote your WISP or SRA, this folds into it.
Price
AI Readiness Assessment
One flat price for the whole engagement — the staff notice, the on-site hour, the technical discovery afterward, and all five documents. No per-user charge and no surprise scope.
It credits toward your compliance work.
If you go on to the full $1,497 Compliance Assessment — a HIPAA Security Risk Analysis or an FTC Safeguards WISP, with your first year of monitoring included — within 90 days, the entire $697 comes off. The AI work effectively costs you nothing, and you are never paying twice for overlapping findings.
Straight talk about what this is
- It is not a scan. Nothing gets installed and no automated tool touches your network. It's an interview and an investigation — the findings are only as good as the conversation, which is why the staff notice goes out first.
- It is not legal advice. The policy we hand you is a tailored draft. If you want it to carry contractual weight, your attorney should read it first — and we'll say so in writing.
- No law requires an AI policy today. Anyone telling you otherwise is selling something. What the law already requires — if you handle health, tax, or client financial data — is that you assess foreseeable risks to that data and control who it goes to. That's the hook, and it's enough.
- Vendor terms move. These companies change their training and retention defaults several times a year, so anything specific in your report gets confirmed against the vendor's current terms the week we write it — not pulled from a list.
Not sure whether this applies to you?
Call and ask. If your office genuinely isn't using any of this yet, I'll tell you that and you'll have spent twenty minutes.
The AI Readiness Assessment reflects your business's own information and our observations at a point in time. It is not legal advice, not a penetration test, and not a certification.