For dental & medical practices

HIPAA requires a Security Risk Analysis. Most small practices don't have one.

The HIPAA Security Rule requires every covered entity to conduct and document a Security Risk Analysis — and it's the single most-cited deficiency in OCR enforcement. A missing or stale SRA is exactly what turns a small incident into a large fine. Kovyr produces your SRA and the full compliance packet, then keeps it current.

Your five-document packet

1

Security Risk Analysis (SRA)

The centerpiece OCR asks for first — where ePHI lives, the threats and gaps, and your posture against every §164.308/310/312 safeguard.

2

Policies & Procedures

The written policies for each Security Rule standard, retained and reviewable per §164.316.

3

Security Official Designation & Sanction Policy

Names your practice's Security Official (§164.308(a)(2)) and the workforce sanction policy.

4

Business Associate Agreement Tracker

Every vendor that touches ePHI, its BAA status, and the §164.314(a) clause language your attorney needs to paper each agreement.

5

Incident Response & Breach Notification Plan

The §164.400–414 clocks (60-day individual notice, HHS, media at 500+) and your response procedures.

The important boundary: for this service we're your risk-analysis provider, not a Business Associate.

HIPAA requires your practice to designate its own Security Official (§164.308(a)(2)) — a member of your staff, not an outside vendor. Kovyr facilitates the risk analysis and produces the documentation from your external posture and the answers you provide. In this engagement Kovyr does not create, receive, maintain, or transmit your ePHI, and is not a Business Associate. That keeps the arrangement clean: you get the required documentation without handing a vendor access to your patient records.

If you later add managed IT, that changes. Monitoring agents, remote access, and backup do reach systems that hold ePHI — so that engagement requires a signed Business Associate Agreement before any of it starts. We would rather tell you that plainly than let it happen quietly.

How it works

1 · Free scan

See what an attacker or OCR can see from the outside — in seconds, no obligation.

2 · Compliance Assessment

We collect your answers, run the analysis, and deliver the full five-document SRA packet. From $897, annual update $297/yr.

3 · Monitoring

Optional: continuous monitoring with your documentation kept current — $1,497 with your assessment for the first year, then $99/mo.

One thing your risk analysis probably doesn't cover.

A staff member pasting patient details into a chatbot on a personal account isn't a business associate — there's no agreement to review, so nothing in a standard program catches it. Our AI Readiness Assessment covers that gap — and credits in full toward the Compliance Assessment (from $897, or $1,497 with your first year of monitoring included) if you add it within 90 days.

Start with a free look at your practice

Free, instant, and passive — we only read public information, the same as an attacker or insurance auditor would.

Ready for your SRA?

Book your Compliance Assessment — quoted per practice, from $897.

Book your assessment
Kendall Sorenson · Kovyr · 435-201-2646 · kendall@kovyr.com · Richfield, UT

Kovyr produces compliance documentation reflecting your practice's information and our external observations. It is not legal advice, not a penetration test, and not a HIPAA certification.

HIPAA Security Risk Analysis for dental & medical practices — Kovyr