A Security Risk Analysis is Required under the HIPAA Security Rule, not addressable, not optional, for every covered entity and every business associate. Risk-analysis failures appear over and over in OCR enforcement actions. The trouble is rarely bad intent. It is that nobody produced the named document, current and defensible, before it was asked for. Aegis AI™ produces it: every safeguard in the Security Rule accounted for, your risks prioritized, and a plan you can act on.
What you get for $995
- Full Security Rule accounting. All 68 safeguards in 45 CFR §164 Subpart C, each one addressed in the analysis or explicitly listed as not-asserted-compliant. Nothing un-measured is ever counted as passing.
- ePHI scope summary. Where ePHI is created, received, maintained, and transmitted across your environment, grounded in your intake.
- Per-safeguard risk register. Threat by vulnerability, likelihood, impact, current measures, the remediation step, and the evidence that would validate it.
- Risk-management plan. The §164.308(a)(1)(ii)(B) follow-on, sequenced 0–30, 31–60, and 61–90 days.
- Required vs. Addressable, stated correctly. "Addressable" means implement or document a reasoned alternative. The report never treats it as optional.
- Board-readable executive summary. Plain language an owner, administrator, or compliance officer can hand to counsel or an auditor.
How it runs
- Minute 0. Stripe processes the $995 payment. Your intake link arrives by email immediately.
- Minutes 5–15. Short intake about your environment, never patient data: your HIPAA role, where ePHI lives, your EHR and major systems, last documented SRA, locations, business associates. The form collects environment details only. No PHI, ever.
- Hours 1–8. Aegis AI runs the analysis against the full Security Rule catalog, generates the PDF, and emails it. No call. No 300-question binder.
Who this is for
- Covered entities. Practices, clinics, health plans, and clearinghouses that need the named §164.308 artifact, current, documented, and defensible, without a consulting engagement.
- Business associates. Vendors and service providers handling ePHI for covered entities. The SRA requirement applies to you directly, and your customers' auditors increasingly ask to see it.
What this is not
- Not legal advice. Aegis AI is not a law firm. The SRA is a compliance work product prepared from your intake, not a law-firm opinion.
- Not an audit or attestation. Audits and attestations are performed by independent firms. This is the analysis you complete before one arrives, and the document HHS expects you to already have.
- A point-in-time analysis. HHS expects the SRA to be reviewed as your environment changes. Aegis AI™ subscription tiers keep the underlying posture monitored continuously.
Subscribe to any Aegis AI™ tier within 30 days and the full $995 credits toward your first month. Month-to-month, no long-term contract.
Get my Security Risk Analysis · $995 →
OFAC and Authorized Signatory certification at intake, for organizations not subject to U.S. sanctions and signed by an officer authorized to bind the entity. Secure Stripe checkout; your intake link arrives by email right after payment.
Common questions
- Is this the document HIPAA actually requires? Yes. The Security Risk Analysis required by 45 CFR §164.308(a)(1)(ii)(A), shaped to the elements OCR's guidance describes: scope, threats and vulnerabilities, current measures, likelihood, impact, and documented results, plus the §164.308(a)(1)(ii)(B) risk-management follow-on.
- Do you need access to patient data? No. The intake collects environment details only: where ePHI lives, never what is in it. The welcome email and the form both say this explicitly.
- What if our posture is rough? Then the SRA is exactly the place it gets documented honestly. Every safeguard is either addressed or listed as not-asserted-compliant, and the 90-day plan sequences the fixes by impact. An honest baseline beats an optimistic one in front of any auditor.
- Not sure HIPAA is your only gap? Run the free multi-framework gap check first. It covers HIPAA alongside SOC 2, ISO 27001, PCI DSS, and NIST CSF, on screen in about two minutes, no email required.
Get your Security Risk Analysis
Get my Security Risk Analysis · $995 →
Secure Stripe checkout. Your intake link arrives by email immediately after payment.