For dental & medical practices

HIPAA requires a Security Risk Analysis. Most small practices don't have one.

The HIPAA Security Rule requires every covered entity to conduct and document a Security Risk Analysis — and it's the single most-cited deficiency in OCR enforcement. A missing or stale SRA is exactly what turns a small incident into a large fine. Kovyr produces your SRA and the full compliance packet, then keeps it current.

Your five-document packet

1

Security Risk Analysis (SRA)

The centerpiece OCR asks for first — where ePHI lives, the threats and gaps, and your posture against every §164.308/310/312 safeguard.

2

Policies & Procedures

The written policies for each Security Rule standard, retained and reviewable per §164.316.

3

Security Official Designation & Sanction Policy

Names your practice's Security Official (§164.308(a)(2)) and the workforce sanction policy.

4

Business Associate Agreement Tracker

Every vendor that touches ePHI, its BAA status, and ready-to-sign agreement language.

5

Incident Response & Breach Notification Plan

The §164.400–414 clocks (60-day individual notice, HHS, media at 500+) and your response procedures.

The important boundary: I'm your risk-analysis provider, not a Business Associate.

HIPAA requires your practice to designate its own Security Official (§164.308(a)(2)) — a member of your staff, not an outside vendor. Kovyr facilitates the risk analysis and produces the documentation from your external posture and the answers you provide. Kovyr does not create, receive, maintain, or transmit your ePHI, and is not a Business Associate. That keeps the arrangement clean: you get the required documentation without handing a vendor access to your patient records.

How it works

1 · Free scan

See what an attacker or OCR can see from the outside — in seconds, no obligation.

2 · Compliance Assessment

We collect your answers, run the analysis, and deliver the full five-document SRA packet. From $399.

3 · Trusted-Advisor Plan

Optional: we keep it current, help close the gaps, and monitor your exposure. $199/mo.

Start with a free look at your practice

Free, instant, and passive — we only read public information, the same as an attacker or insurance auditor would.

Ready for your SRA?

Book your Compliance Assessment — quoted per practice, from $399.

Book your assessment
Kendall Sorenson · Kovyr · 435-201-2646 · kendall@kovyr.com · Richfield, UT

Kovyr produces compliance documentation reflecting your practice's information and our external observations. It is not legal advice, not a penetration test, and not a HIPAA certification.