I will perform your hipaa security risk analysis
The Cyber Friend, where you can Trust Us, with your Security
Vetted by Fiverr Pro
Sam was selected by the Fiverr Pro team for their expertise.
Vetted for
Cybersecurity
About this Gig
Vetted Pro
If your practice bills Medicare, you attest annually that you have completed a security risk analysis. If you are a business associate, the BAAs you signed require the same thing. Most never actually complete one.
That holds up until it doesn't. When OCR opens an investigation following a breach or complaint, the risk analysis is the first document they request. A missing one, or a checklist someone downloaded, is what turns a contained incident into a finding with penalties attached.
I perform the analysis for you against 45 CFR 164.308, 164.310, 164.312, and 164.316.
You receive:
- A completed security risk analysis written to hold up under OCR review
- A gap list ranked by real exposure, not alphabetical order
- A remediation roadmap with timelines your staff can actually hit
- A findings call to walk through every item
I never touch your systems. You complete a structured questionnaire, I review and score it, and you receive the deliverables.
CISM. CMMC Registered Practitioner Advanced. Master's in Cybersecurity. I have carried multiple HIPAA-regulated organizations through assessment and policy work.
Expertise:
Data Protection
•
Gap Analysis
•
Risk Assesment
Technology:
Mail Services
•
Mobile
•
Physical
•
Saas
•
Databases
Regulation:
Other
Other Cybersecurity Services I Offer
FAQ
Will this satisfy my Medicare attestation?
Yes. The analysis is performed against 45 CFR 164.308(a)(1), which is the requirement your attestation points to. You receive a dated report you can retain as evidence.
Do you need access to our systems?
No. You complete a structured questionnaire covering your environment, safeguards, and workflows. I review and score it. Nothing gets installed, and I never touch your network.
How much work is this on our end?
Plan on two to four hours for whoever knows your systems and vendors. I handle everything after the questionnaire comes back.
What happens if OCR contacts us later?
You hand them the report. It is written in the structure OCR expects, with risk determinations and the remediation plan documented. That is the document they ask for first.
Will you sign an NDA?
Yes, before any information changes hands. Send yours, or I will provide one.
Do you work with practices our size?
I work with practices ranging from solo providers to about 100 staff, most of whom have no internal security person. Message me with your headcount, and I will tell you straight whether I am the right fit.

