SENTINEL COMPLIANCE COMMAND
SECURITY RISK ANALYSIS

THE SECOND HALF

Your Security Risk Analysis is only the first half.

Finding the risk is the first half. Showing what happened next is the second.

The analysis identifies the risk. The work doesn’t end there. A useful assessment should leave the practice with documented risks, clear priorities, and a path for addressing what was found.


Finding documented· Risk prioritized· Owner assigned· Target date established· Closure documented

A report tells you what was found. A usable risk analysis gives you a way to act on it.

Sentinel structures and documents the remediation. Your practice remains responsible for implementing the corrective actions — and now has a place to record that they were.

Watch

WHAT YOU RECEIVE — A COMPLETE SECURITY RISK ANALYSIS

One defined engagement. One usable record. One scheduled return.

SEE EXACTLY WHAT YOU RECEIVE

Sample Security Risk Analysis and Remediation Register

A complete example prepared for a fictional practice — both documents, exactly as delivered. The analysis, and the status report sent six months later showing what actually happened to each finding.

The Security Risk Analysis (PDF) The Six-Month Status Report (PDF)

$2,895

Paid once. The analysis, both exclusion screenings, and the six-month review.

There is nothing further to pay when we come back at six months. The return visit is part of the engagement, not an add-on. A published price, the same for everyone — no subscription, no automatic renewal, no invoice you did not expect.


THE SECOND HALF — WE COME BACK

Most risk analyses end as a PDF. Six months later nobody can say which findings were actually closed, and the practice is holding a document that describes a day that has passed.

This engagement includes a scheduled return. Six months after the analysis, Sentinel reviews every item on the Remediation Register against the evidence the practice can produce, and issues a Six-Month Remediation Status Report: what closed, what is still open, and what was reported complete but not yet evidenced.

If nothing has been closed, the report says so plainly. That is the point of asking.

The six-month review is included in the one-time fee. There is no second invoice for it.

The six-month review is not a second Security Risk Analysis. It does not re-rate risk or re-evaluate safeguards. It documents what happened to the findings from the analysis it reports against, and it says so on its face.


WHAT WE REVIEWED, AND WHAT YOU TOLD US

A practice answering “yes, we have backups” is a representation. A backup log Sentinel actually read is evidence. Most reports render the two identically, which quietly turns an answer into a verification.

Every safeguard and every finding in this analysis carries its own classification — documented, reported, not identified, or not applicable — and the report states which is which. Where something was not examined, it says that too, rather than leaving a blank you might read either way.


DELIVERED REMOTELY, ANYWHERE IN THE UNITED STATES

The HIPAA Security Rule reads the same in Ohio as it does in Texas. This engagement is conducted remotely — a structured intake, a working session with the people who actually run the practice, a guided walkthrough of the physical environment where that matters, and the documents reviewed as they are provided. No site visit is required, and none is charged for.

Sentinel is based in Houston and conducts this engagement for independent practices across the country. On-site onboarding remains available across Greater Houston for practices that prefer it.

Exclusion screening scope, stated precisely: screening covers the federal sources — the OIG List of Excluded Individuals and Entities and the GSA SAM exclusions. Texas practices are additionally screened against the Texas HHSC exclusion list. Screening against an individual state’s Medicaid exclusion list outside Texas is arranged on request; Sentinel will tell you before the engagement begins whether your state’s list is covered.


This is a point-in-time Security Risk Analysis. Sentinel documents the risks, provides the Remediation Register, and returns once at six months to document remediation status. The practice remains responsible for implementing corrective actions. Sentinel does not certify regulatory compliance, and beyond the deliverables named above this engagement does not establish continuous monitoring or an ongoing advisory relationship.

Sentinel recommends annual reassessment pacing as a professional operating standard. The Security Rule names no fixed interval; an updated analysis is called for sooner after material change — new systems, new locations, new vendors, a security incident, a change in ownership, or significant workforce change.

The Security Risk Analysis is required by 45 C.F.R. § 164.308(a)(1)(ii)(A). This engagement follows HHS OCR’s Guidance on Risk Analysis Requirements under the HIPAA Security Rule (July 14, 2010); the Remediation Register implements its corrective-action element.

REQUEST THE ANALYSIS

Tell us about your practice.

No obligation. We’ll confirm scope and timing before anything begins.

No spam. No sales call without your permission. Just a conversation when you’re ready.

Thank you.

We received your request and will be in touch within one business day.

KNOW WHERE YOU STAND.