Practice

Where We Help.

Healthcare cybersecurity work delivered as defined engagements. Fixed scope. Fixed price. Direct delivery by an experienced healthcare CISO, not a rotating analyst team.

Two practice areas. The primary focus is small and mid-sized healthcare providers (dental practices, physician groups, specialty practices, behavioral health networks, digital health clinics, urgent care, and multi-location outpatient clinics) that need real HIPAA security work at prices that fit a real practice budget. The secondary practice serves healthcare vendors and SaaS companies with deal-cycle and regulatory engagements.

Why Now

The proposed HIPAA Security Rule introduces stricter documentation and verification obligations on both sides of the business associate relationship. For smaller providers, that translates into harder audits, higher breach notification expectations, and a vendor risk burden that has historically been ignored. The buying window is short.

Read Our HSR Analysis
Practice Area One

For Healthcare Providers

For dental practices, physician groups, specialty practices, behavioral health networks, digital health clinics, urgent care, and multi-location outpatient clinics. Sized and priced for real practice budgets. Built to be useful inside the first two weeks of the relationship.

Foundational Engagement

HIPAA Compliance Starter

The foundational HIPAA security work for a practice that needs to be compliant on paper and defensible in reality. Risk assessment, policies, procedures, breach response plan, and a staff training framework, delivered as a complete package.

Who it's for: Practices that have never had a proper HIPAA security program, or that have inherited paperwork from a previous owner or admin and no longer trust it. Most common with dental practices, physician groups, behavioral health clinics, and specialty practices under 50 staff.

Why This Matters

Smaller healthcare practices carry the same HIPAA obligations as a hospital system, with a fraction of the staff and none of the budget. The result, almost universally, is a compliance program built from a template downloaded years ago, lightly customized, and never updated. It does not hold up to a real audit. It does not survive a real breach. And it does not actually protect patient data.

Under the proposed HIPAA Security Rule changes, the documentation bar is rising. The distinction between required and addressable safeguards is being eliminated. Annual risk analysis is becoming explicit. Encryption, MFA, and network segmentation move from best practices into obligations. A template-based program will not survive what is coming.

For most practices, the choice is no longer between doing it yourself and hiring a big consultancy. It is between staying on a template that will eventually fail an audit, or putting a real foundation in place at a price a practice can afford.

What It Entails

We begin with a structured intake covering your practice environment, the systems handling ePHI (EHR, billing, imaging, messaging, backup), your staff roles, your physical facility, and any prior compliance work. From there, we deliver a complete starter program.

That includes a HIPAA Security Rule risk assessment with identified gaps and prioritized remediation, a full set of written policies and procedures tailored to your environment (not a generic template), a breach response and notification plan with documented escalation, a staff training framework you can run yearly, and a one-page compliance summary your leadership team and your counsel can actually read.

Everything is delivered in 20 business days, ready to reference in an audit, with a refresh path so the program stays current year over year.

Why Choose Jackal Group

Built by an active healthcare CISO who has run real security programs in healthcare and regulated environments. Not a template generator. Not a $39/month compliance software platform that produces something the moment you fail an audit. Not a Big 4 firm pricing the engagement at five times what a practice can reasonably pay.

Everything is written in language your practice manager and your provider partners can read and act on. The deliverables are sized to a real practice, not a hospital. The pricing is sized to a real practice budget.

What You Receive

  • HIPAA Security Rule risk assessment with prioritized gaps
  • Written policies and procedures tailored to your environment
  • Breach response and notification plan
  • Staff training framework with annual refresh outline
  • Executive summary for leadership and counsel
  • Delivered in 20 business days

Pricing

Starter Program

One-time engagement

$4,500

Annual Refresh

Update of risk assessment, policies, and training

$1,500/yr

Or send a message.

Recurring Engagement

HIPAA Annual Risk Assessment

The annual HIPAA risk analysis required of every covered entity, done by an independent third party who has seen the inside of real healthcare environments. Delivered in two weeks with a written report that satisfies the regulation and informs your actual decisions.

Who it's for: Practices that already have a baseline HIPAA program but need their annual risk analysis completed by an independent source. Common follow-on for practices that have completed our HIPAA Compliance Starter, but available as a standalone engagement.

Why This Matters

HIPAA already requires an annual risk analysis. Under the proposed Security Rule changes, that requirement is being made explicit, formalized, and brought under stricter documentation expectations. A self-completed checklist printed off the internet does not meet the standard. It never really did.

When OCR audits, breach notifications, or insurance carriers ask to see your risk assessment, what they actually want is a current, methodologically sound, environment-aware document signed by someone with credentials. Practices that produce a template-based self-assessment in those moments consistently fare worse than practices that produced an independent analysis ahead of the request.

What It Entails

Structured intake covering your environment, your systems handling ePHI, your staff, and any meaningful changes in the past year. We review the safeguards in place, the gaps surfaced, and the trajectory of your program against the Security Rule's administrative, physical, and technical safeguard categories.

The deliverable is a written risk assessment report sized appropriately for a practice (typically 20 to 30 pages), paired with a one-page executive summary, a prioritized remediation list, and a signature from a credentialed practitioner. Delivered in 10 business days.

Why Choose Jackal Group

Independent third-party assessment by an active healthcare CISO. Faster than a Big 4 engagement and a fraction of the cost. More credible than a template you fill out yourself. More substantive than a $200 compliance app that scans your EHR and prints a checklist.

If you already have a HIPAA program in place, this is the most direct way to keep the annual requirement satisfied without consuming a quarter of your year on internal effort.

What You Receive

  • Written risk assessment report (20 to 30 pages)
  • Executive summary for leadership
  • Prioritized remediation list with effort estimates
  • Independent assessor signature
  • Delivered in 10 business days

Pricing

Annual Risk Assessment

Standalone engagement

$2,500

Or send a message.

Vendor Risk Program

Vendor Due Diligence Program

A healthcare-specific vendor risk methodology that turns the verification obligation under the proposed HIPAA Security Rule into something a small practice can actually operate. Sized for practices with under 30 business associates.

Who it's for: Practices that depend on a small number of critical vendors (EHR, billing service, cloud backup, secure messaging, imaging, scheduling, AI tools) and need to be able to defend that vendor relationship if anything goes wrong.

Why This Matters

Most healthcare practices carry significant operational risk through a small number of vendors that touch their ePHI. The EHR. The billing service. The cloud backup. The messaging app every staff member uses. The new AI scribe the providers just adopted. Each one of those is a business associate under HIPAA, and the responsibility for what they do with your patient data sits squarely on the practice.

Under the proposed HIPAA Security Rule, covered entities are required to verify each business associate annually, confirming they have deployed the required technical safeguards. Most practices have never done this in any formal way. The standard response when asked has been to point at a BAA signed years ago. That is no longer enough.

When a vendor is breached, your practice has to answer for the relationship. Insurance carriers, regulators, and litigants all start in the same place: show us your vendor due diligence.

What It Entails

The program build engagement is structured to produce three things you can put into operation immediately. A vendor risk scoring framework tiered by data sensitivity and system access, so you know which vendors need careful review and which need light-touch monitoring. A healthcare-specific assessment questionnaire built around HIPAA technical safeguards, with scoring guidance for each question. And a documentation template suite for due diligence records that withstands real scrutiny.

The program build includes deep-dive assessments of your top five vendors as a first pass. The ongoing program retainer keeps your vendor risk current as new tools and services are added to your environment.

Why Choose Jackal Group

Built by someone who has been on both sides of healthcare BAA relationships. Most vendor due diligence frameworks are written by lawyers focused on contract language or by GRC platforms focused on questionnaire delivery. The technical content suffers in both cases.

Our framework focuses on the questions that distinguish a credible vendor security program from one that survives only because the practice has never actually verified the answers. Sized to a small practice, not an enterprise vendor management office.

What You Receive

  • Tiered vendor risk scoring framework
  • Healthcare-specific assessment questionnaire
  • Due diligence documentation templates
  • Top 5 vendor deep-dive assessments as a first pass
  • BAA review and gap analysis

Pricing

Program Build

Framework + top 5 vendor assessments

$3,500

Ongoing Program Retainer

Vendor onboarding and reassessment

$500/mo

Or send a message.

Practice Exercise

Incident Response Tabletop

A facilitated tabletop exercise that walks your practice leadership through a realistic incident in two to four hours. Built around scenarios that actually happen to practices your size: ransomware, BA breach, lost laptop, phishing-driven account takeover, AI tool misuse.

Who it's for: Practices with an incident response plan that has never been tested, and practices preparing for an OCR audit where exercising the plan is now an expectation.

Why This Matters

Most practices have an incident response plan they have never run. The first time the plan is exercised is during the actual incident. That is the worst possible moment to discover the plan does not reflect how the practice actually operates.

Tabletop exercises surface the gaps cheaply, before they cost a HIPAA notification, a deposition, or a settlement. The proposed HIPAA Security Rule explicitly expects practices to test their plans. The insurance industry is starting to expect the same.

What It Entails

We pre-build a scenario tailored to your environment and current threat exposure. Two to four hours of facilitated discussion with your leadership team, walking through the scenario in stages with decision points at each stage. Injects are timed to mimic the pace of a real incident.

After the exercise, you receive a written debrief with observed strengths, identified gaps, and a prioritized list of plan updates and process improvements. The whole engagement is designed to be useful within a single business day.

Why Choose Jackal Group

Facilitated by an active healthcare CISO who has run real incident responses, not a moderator reading from a script. Scenarios are drawn from incidents that have actually happened to practices your size, not generic enterprise templates ported into healthcare.

The post-exercise debrief is the most important deliverable. It turns a few hours of conversation into a set of practical plan improvements your team can act on inside a quarter.

What You Receive

  • Pre-built scenario tailored to your environment
  • Two to four hour facilitated exercise
  • Written debrief with strengths, gaps, and recommended actions
  • Prioritized plan update list
  • Audit-ready documentation of the exercise

Pricing

Tabletop Exercise

Single exercise, full deliverable suite

$2,000

Or send a message.

Emerging Risk

AI Governance for Clinical Practices

A practical AI governance framework for practices adopting AI scribes, ambient documentation, clinical decision support, or chatbots. Policy, vendor assessment, and a use-case inventory you can actually maintain.

Who it's for: Practices that have started adopting AI tools and need a governance approach that fits a practice setting, not a hospital system. Especially relevant for dental, physician, behavioral health, and specialty practices using AI scribes or clinical AI vendors.

Why This Matters

Practices are adopting AI tools faster than the governance scaffolding around them can be built. The AI scribe that records every patient conversation. The clinical decision support that suggests differential diagnoses. The patient intake bot. The image analysis tool. Each one introduces AI into the patient relationship in a way that has regulatory, malpractice, and privacy implications most practices have never had to think about.

State legislatures are already moving on this. New York has proposed treating clinical AI guidance as the practice of medicine. California has adopted disclosure and anti-impersonation requirements. Audits and insurance carriers are starting to ask harder questions. Practices without a governance program are not failing because they are reckless. They are failing because no one has built the scaffolding yet.

What It Entails

We inventory your AI use cases (what tools you operate or call, what patient data they touch, who the users are, and what clinical decisions they are influencing). We then deliver a tailored AI policy pack, a use-case inventory template, and an AI vendor assessment framework.

Everything is sized for a practice, not a health system. Mapped to NIST AI RMF and current HHS guidance, with the governance burden scaled to what a practice can actually maintain.

Why Choose Jackal Group

One of the few governance offerings positioned for practice-sized organizations. Most AI governance consulting today is built for general enterprise AI deployments in financial services, retail, or manufacturing. Healthcare AI introduces clinical decision-making, PHI handling, and FDA validation considerations that generic frameworks do not address. Practice-scale healthcare AI introduces budget, time, and staff constraints those frameworks also do not address.

Our policy pack is written for HIPAA-regulated practice environments. The vendor assessment framework includes questions that surface the specific risks documented in recent adversarial AI research against clinical decision support systems.

What You Receive

  • AI policy pack tailored to your practice and use cases
  • AI use-case and tool inventory template
  • Vendor assessment framework with practice-specific questions
  • Mapping to NIST AI RMF and HHS guidance
  • Delivered in 10 business days

Pricing

Starter Pack

One-time engagement

$2,000

Ongoing Maintenance

Policy updates, vendor assessment support, regulatory tracking

$500/mo

Or send a message.

Practice Area Two

For Healthcare Vendors and SaaS

For business associates who sell into hospitals, health systems, payers, or practice groups: BA verification under the proposed HIPAA Security Rule, security questionnaire response when enterprise deals are stuck in security review, and RFP support when the security and compliance sections decide the shortlist.

Anchor for Vendors

Annual BA Verification

A written SME analysis of your technical safeguards and a certification letter, formatted to satisfy covered entity verification requests under the proposed HIPAA Security Rule.

Who it's for: Healthcare SaaS, vendors, and service providers operating as business associates under HIPAA, particularly those selling into hospitals, health systems, or payers.

Why This Matters

The proposed HIPAA Security Rule introduces an explicit annual verification requirement for business associates handling ePHI. BAs must produce a written analysis of their technical safeguards, certified by a person of authority, and provide it to covered entities at least once every twelve months.

Sophisticated healthcare buyers are already including verification language in new contracts ahead of the final rule. Every renewed covered entity contract is becoming a verification request. Without a ready document, deals stall.

What It Entails

A written analysis of your electronic information systems and technical safeguards, 40 to 60 pages depending on environment complexity, paired with an executive summary, a prioritized remediation roadmap, and a certification letter ready for your organization's person of authority to sign. Delivered in 15 business days.

Why Choose Jackal Group

Written by an active healthcare CISO who has spent two decades on the BA side of these conversations. Not lawyers writing for lawyers. Not a software platform generating a templated report that buyers can recognize. The document is structured around the questions sophisticated covered entities actually ask.

What You Receive

  • Written analysis of technical safeguards
  • Executive summary
  • Certification letter for “person of authority” signature
  • Prioritized remediation roadmap
  • Delivered in 15 business days

Pricing

Initial Verification

One-time engagement

$9,500

Annual Renewal

Year two and beyond

$5,500/yr

CE Response Concierge

Optional retainer: CE verification requests, ongoing analysis updates

$1,500/mo

Or send a message.

Wedge for Vendors

Healthcare SaaS Security Questionnaire Response

Complete responses to the security questionnaires your hospital and health system buyers send during enterprise procurement. Delivered in five business days, so your sales cycle does not stall.

Who it's for: Healthcare SaaS companies with deals stuck in security review, founders without an in-house security leader, and sales teams that need turnaround in days, not weeks.

Why This Matters

Security questionnaires are the gating step on every enterprise healthcare deal. A single SIG, CAIQ, HECVAT, or custom hospital questionnaire typically takes 25 to 40 hours of internal effort. The deal cycle stalls. The next deal gets the same treatment, because nothing is stored or reusable.

What It Entails

You forward the questionnaire. We complete it in your buyer's required format within five business days, paired with a Trust Library starter you keep and reuse on future deals. One round of follow-up answers included.

Why Choose Jackal Group

Your Trust Library is yours to keep and reuse. Most outsourced services charge per response and never give you the library. We give you the library on day one, so subsequent questionnaires close faster because the answers stack.

What You Receive

  • Completed questionnaire in required format
  • One round of follow-up answers
  • Trust Library starter
  • Delivered in 5 business days

Pricing

Per Questionnaire

One-time per response

$1,500

Unlimited Retainer

Fair use up to 4 questionnaires/month

From $2,500/mo

Or send a message.

Strategic Support

RFP and Proposal Response

End-to-end response support for healthcare system, payer, and government RFPs. Security narrative, control mapping, evidence packaging, and the technical sections that decide whether your proposal makes the shortlist.

Who it's for: Healthcare technology vendors pursuing complex RFPs where the security and compliance sections are make-or-break.

Why This Matters

The security and compliance sections of a healthcare RFP are scored independently, by people with deep technical expertise, and often determine whether the proposal makes the shortlist. Most vendors approach these sections by pulling boilerplate from old responses. The result reads like compliance theater. The deal is lost before the operational and commercial sections are even read.

What It Entails

You hand over the RFP and any prior responses on file. We complete the security, compliance, and risk sections end-to-end. Control framework mapping, evidence packaging, reference architecture diagrams. One round of revisions included.

Why Choose Jackal Group

Security-specific authorship by someone who has run the security program inside a healthcare technology vendor and reads RFP responses from the buyer side regularly. Most general RFP consultants write security sections from boilerplate. Most security consultants do not write RFPs. We sit in the overlap.

What You Receive

  • Completed security and compliance sections
  • Control framework mapping (HIPAA, SOC 2, HITRUST, NIST)
  • Evidence packaging and reference architecture diagrams
  • One round of revisions

Pricing

Per RFP

One-off engagement

$5,000

Retainer

Up to 2 RFPs/month

$7,500/mo

Or send a message.

How We Work

Direct Delivery. Defined Scope. No Surprises.

01

Fixed Scope, Fixed Price

Every engagement is scoped before it starts. You know what you are buying, when it will arrive, and what it will cost before a contract is signed.

02

Direct With a CISO

You work directly with an active healthcare CISO who has run real security programs in healthcare and regulated environments. Not a junior analyst learning on your time.

03

Sized for Your Reality

Engagements are scaled to the practice or vendor being served. We do not push hospital-grade deliverables on dental practices, and we do not push template work on enterprise buyers.

04

Outputs You Can Use

Audit-ready documentation, certification letters, and remediation roadmaps written in language your leadership team and your counsel can act on.

Get Started

Tell Us What You Need.

Every engagement starts with a short scoping conversation. No sales pressure. We will tell you whether we are the right fit, and if we are not, we will tell you who is.

Or send us a message or email info@jackalgrp.com