For dental & medical practices
HIPAA requires a Security Risk Analysis. Most small practices don't have one.
The HIPAA Security Rule requires every covered entity to conduct and document a Security Risk Analysis — and it's the single most-cited deficiency in OCR enforcement. A missing or stale SRA is exactly what turns a small incident into a large fine. Kovyr produces your SRA and the full compliance packet, then keeps it current.
Your five-document packet
Security Risk Analysis (SRA)
The centerpiece OCR asks for first — where ePHI lives, the threats and gaps, and your posture against every §164.308/310/312 safeguard.
Policies & Procedures
The written policies for each Security Rule standard, retained and reviewable per §164.316.
Security Official Designation & Sanction Policy
Names your practice's Security Official (§164.308(a)(2)) and the workforce sanction policy.
Business Associate Agreement Tracker
Every vendor that touches ePHI, its BAA status, and ready-to-sign agreement language.
Incident Response & Breach Notification Plan
The §164.400–414 clocks (60-day individual notice, HHS, media at 500+) and your response procedures.
The important boundary: I'm your risk-analysis provider, not a Business Associate.
HIPAA requires your practice to designate its own Security Official (§164.308(a)(2)) — a member of your staff, not an outside vendor. Kovyr facilitates the risk analysis and produces the documentation from your external posture and the answers you provide. Kovyr does not create, receive, maintain, or transmit your ePHI, and is not a Business Associate. That keeps the arrangement clean: you get the required documentation without handing a vendor access to your patient records.
How it works
1 · Free scan
See what an attacker or OCR can see from the outside — in seconds, no obligation.
2 · Compliance Assessment
We collect your answers, run the analysis, and deliver the full five-document SRA packet. From $399.
3 · Trusted-Advisor Plan
Optional: we keep it current, help close the gaps, and monitor your exposure. $199/mo.
Start with a free look at your practice
Free, instant, and passive — we only read public information, the same as an attacker or insurance auditor would.
Ready for your SRA?
Book your Compliance Assessment — quoted per practice, from $399.
Book your assessmentKovyr produces compliance documentation reflecting your practice's information and our external observations. It is not legal advice, not a penetration test, and not a HIPAA certification.