Healthcare compliance support
HIPAA compliance mapping
HIPAA work is inventory work: where protected health information goes, who touches it, and which safeguard covers each hop. We map it standard by standard and deliver the documentation the Rules expect an organisation to hold.
- Published price
- $1,000–4,000 / assessment
- Turnaround
- 5 business days
- Without us
- $8,000–30,000
Fixed per unit, not hourly. No minimum engagement. Quoted before we start.
What you receive
A mapped assessment of data flows and safeguards against the HIPAA Security and Privacy Rules.
- A PHI data flow map: where it enters, where it is stored, who accesses it, where it leaves
- Safeguards mapped against each Security Rule standard and implementation specification
- Addressable specifications documented with the decision and its rationale, as the Rule requires
- Business associate coverage checked, with a list of relationships lacking an agreement
- Privacy Rule requirements assessed: notice, rights, minimum necessary and disclosure practices
- A prioritised remediation list separating documentation gaps from technical ones
What it costs, and what it replaces
Both figures are published ranges for the same unit of work. Ours is fixed before we start; if our process gets faster, that is our gain and your price does not move.
How engagements are structured →- Adnah Legal
- $1,000–4,000 / assessment
- Typical cost without us
- $8,000–30,000 / assessment
Roughly 87% lower at the midpoint of each published range.
How the work runs
01
Data flow mapping
We trace protected health information through the organisation's actual systems, including the paths people use rather than the ones on the architecture diagram.
02
Standard-by-standard assessment
Each Security Rule standard and implementation specification is assessed against the evidence, with addressable specifications documented as the Rule requires rather than skipped.
03
BAA coverage
Every relationship involving protected health information is checked for a current agreement, which is where the most easily fixed exposure usually sits.
04
Privacy Rule and remediation
Notice, individual rights and disclosure practices are assessed, and remediation is prioritised, separating what needs writing from what needs building.
What we need from you
- System and vendor inventories touching protected health information
- Existing policies, risk analyses and business associate agreements
- Network and access documentation
- Any prior assessment or breach history
What we check before delivery
- Every standard and implementation specification is assessed; none is silently skipped
- Addressable specifications carry a documented decision and rationale, as required
- BAA coverage is verified against an actual executed agreement, not a vendor list
- The data flow map is reconciled against system documentation and access records
When firms send us this
- Covered entities and business associates preparing for an audit
- Vendors needing to demonstrate compliance to healthcare customers
- Post-incident assessment of where safeguards failed
- Annual reassessment of an existing programme
Questions about hipaa compliance mapping
Is this the required risk analysis?
It produces the mapping and documentation the Rules expect, for the engaging attorney's review and adoption. Where a formal risk analysis with technical testing is required, this is the documentation layer that sits alongside it.
Do you perform technical testing?
No. We map controls and documentation against the standards; penetration testing and technical vulnerability assessment are a security-engineering function.
Can you draft the missing policies?
Yes, quoted alongside the mapping, so the gap list arrives with the documents that close it.
Firms who send us this usually also send
This service
Send one and judge the output.
HIPAA compliance mapping at $1,000–4,000 per assessment, 5 business days. No minimum, no scoping call, no onboarding cycle.