Six entry offers from $750 to $1,950. Designed for practices that want a focused look at one specific question without committing to a larger engagement.
The flagship Defensible Risk Assessment and Governance Implementation Sprint. For organizations ready to do the substantive work of putting a real program in place.
The Security Leadership (vCISO) Retainer. Steady oversight, monthly tracking, with a quarterly report for practice that want sustained progress between formal engagements.
Most engagements with Northline start here. Each entry offer answers one specific question and gives you something tangible to act on, a written deliverable you can take to your owner, your insurer, or your next leadership meeting. They’re priced under $2,000 so you can say yes without a procurement conversation, and they’re scoped tightly so you’re not buying a generalist’s wandering opinion.
A 90-minute structured conversation plus a scan of your top security gaps and immediate next steps.
Best for: A medical or dental office with no written security program, or one that got nervous after hearing what happened to another office nearby.
Time Commitment: 90 minute conversation and 30 minutes for review.
What you get: Written Security Snapshot Memo (2–3 pages): top gaps identified, risk level (High / Medium / Low), and 3–5 prioritized next steps.
Natural next step: Defensible Risk Assessment
You pay them every month. Do you know what you are actually getting?
An independent review of your current IT provider contract and practices, so you know where you are covered and where you are not. I ran an IT company for 24 years, so I know what a good contract looks like and what gets left out of a bad one.
Best for: A practice that hands all IT and security to one outside company and has no way to check the work.
Time Commitment: About two hours, plus copy of your contract.
What you get: IT Provider Scorecard (summary with ratings across 8–10 critical areas) plus a written narrative memo highlighting gaps, missing protections, and follow-up questions to bring to your IT provider.
Natural next step: Defensible Risk Assessment
Prepare for your renewal. Know what you’ll be asked and whether your current controls support your answers.
Best for: A practice facing renewal, rising premiums, or an insurer asking for documentation it never asked for before.
Time Commitment: About two hours, plus the application and your current policy.
What you get: Cyber Insurance Application Review Summary: current posture vs. insurer expectations, flagged gaps that could affect coverage or claims, and a short list of quick wins to improve position before renewal.
Natural next step: Defensible Risk Assessment
Every one of these ends with a document you own. Where you go next is your call, not mine.
A facilitated 2-hour walk-through of how your team would actually respond to a real scenario. For a practice that is usually ransomware or a data breach. So the first time isn’t the real thing.
Best for: A practice that heard about a local ransomware hit and wants to test its readiness. Leadership want to make sure that when an incident occurs, there is a plan.
Time Commitment: Two hours for leadership
What you get: Post-Tabletop Summary Memo: scenario overview, key gaps surfaced, roles and decisions that broke down, and 3–5 prioritized recommendations. Suitable for owner review.
Natural next step: Security Leadership (vCISO) Retainer or full Risk Assessment
A 60-minute staff training session built around how your office actually operates. For a practice it covers handling patient information under HIPAA.
Best for: A practice that has never done formal security awareness training, is onboarding new staff, or needs training documentation for an insurer, or a payer.
Time Commitment: 60 minutes of staff time.
What you get: Customized 60-minute staff briefing (on-site or virtual) covering phishing, device handling, password hygiene, and breach reporting. Includes attendance log template, a 1-page staff reference card, and a facilitator summary memo.
Natural next step: IT Provider Review, Snapshot, or Governance Sprint
A focused conversation about how you take card payments and where that data goes. For a practice that means patients and the network your EHR sits on.
Best for: A practice whose card terminal shares a network with the EHR or the billing system.
Time Commitment: About 90 minutes.
What you get: Payment Security Process Review Memo (2–3 pages): how card data currently flows, observed process gaps, risk observations (especially system / network adjacency), and 3–5 practical recommendations. Includes clarifying questions for your payment processor and IT provider.
Natural next step: Security Snapshot or full Risk Assessment
When you are ready to move beyond a single conversation and put a real program in place, these are the engagements that do the work. Both produce defensible documentation, ranked priorities, and clear ownership, not a stack of generic templates with your name pasted on.
THE FRAMEWORK BEHIND THE ASSESSMENT
Your assessment runs on SecurityStudio S2Org, an established risk assessment framework used by thousands of organizations. It looks at four areas: your policies and your people, your physical space, the technology inside your walls, and what an outsider can see about your practice from the internet.
Every assessment produces a HIPAA gap report that maps each finding back to the requirement it relates to. So when an insurer, an auditor, or an investigator asks how you know where you stand against the Security Rule, you have a document that answers it line by line. That is most of what makes an assessment defensible.
You also get an S2Score, a single number between 300 and 850 that works like a credit score. Your owners get one figure they can understand, track year over year, and hand to an insurer.
That fourth area is the one most owners have never seen. It looks at your practice the way an outsider would, without touching anything inside. What shows up in a search, what is reachable from the internet, what your public records give away.
I do not sell SecurityStudio and I earn nothing on it. It is what I measure with.
An independent Risk Assessment that shows where your risks are and what to fix first, with a remediation roadmap you can work from.
This is the core engagement most practices come to Northline for. You get decision-ready priorities, owners, timelines, and evidence expectations, so leadership can prove safeguards, reduce downtime risk, and move forward confidently without vendor pressure shaping the answer.
Price depends on two things: how many locations you have, and how many people can log in. Find yourself below.
Up to 20 logins
One Location
$5,950 · 3-4 weeks
Up to 50 logins
One or Two Locations
$7,950 · 4-5 weeks
more than 50 logins
Three or more locations
$8,950 to $13,950 · 5-6 weeks
The rule behind the numbers: start at $5,950, add about $1,000 for each additional location, and about $1,000 for every thirty people with a login.
Count logins, not employees. Part-time staff, contractors, billing help, and anyone working from home all have accounts, and every account takes time to review. Most practices guess low on this. If you are not sure, that is fine. Fifteen minutes on the phone gets you a firm number.
Patient records are why this work runs deeper than it does elsewhere. Vendor agreements, the Privacy Rule, breach notification, and finding every place records actually live are all part of the engagement. That is built into the numbers above rather than added later.
• More than one IT vendor, because each one is a separate conversation
• No existing documentation, or an assessment old enough that it predates your current systems
• Card payments, especially where a terminal shares a network with the EHR
• Review of business associates and other 3rd party vendors.
WHAT’S INCLUDED
HIPAA Risk Assessment covering Administrative, Physical and Technical controls
Ranked Risk Register
90-day Remediation Roadmap
Executive Summary
Board / Owner Briefing
Evidence Request and Gap Log
All platform and tool access needed to do the work, included in the price
HIPAA asks for two things: an assessment of your risks, and a plan to reduce them. The 90-day roadmap above is the second half, which is the half most practices skip.
HOW IT RUNS
Engagement runs three to six weeks. Discovery and mapping where patient records actually live, including the places nobody thinks about are first. Second is the assessment against the Security Rule. Third is interviews, the risk register, the roadmap, and the evidence work. Finally is review, the executive summary, and a live briefing with your owners.
Time Commitment: 10 to 15 hours across your team over the course of the engagement. 90 minutes for the final presentation.
Natural next step: Governance Implementation Sprint or Security Leadership Retainer
A governance-first build-out of policies, controls, vendor practices, and the evidence binder that proves your safeguards are actually operating.
A Risk Assessment tells you what’s wrong. The Governance Sprint puts the structure in place to keep it right. The outcome is plain-English findings and a practical governance cadence covering metrics, responsibilities, and a prioritized roadmap, so your organization stops relying on assumptions and starts managing security as an ongoing program. Designed to work even with lean internal IT or an outside provider doing it all.
WHAT’S INCLUDED
Customized policy set (written to how your organization actually operates, not dropped in from a template)
Evidence binder structure and roadmap
Assigned ownership across roles
Governance cadence setup (meeting and review rhythms)
Quarterly metric dashboard template
Access to GRC platform (Medcurity) for 12 months from start of engagement
HIPAA asks for two things: an assessment of your risks, and a plan to reduce them. You need to develop the 90-day roadmap and then show that you have made progress in addressing the found issues.
HOW IT RUNS
Engagement 8–12 weeks after you have completed the Risk Assessment. The bulk of the time is the customized policy set. Not boilerplate. Policies tailored to your EHR, your IT arrangement, your vendor mix, and how your staff actually work. Throughout, you’re building the muscle to run governance as an ongoing practice, not a one-time deliverable.
Time Commitment: About 20 to 30 hours across the team.
Natural next step: Security Leadership Retainer for ongoing oversight
A Risk Assessment and Governance Sprint produce documentation. Ongoing support produces results. The Security Leadership (vCISO) Retainer is for organizations that want continued forward motion and someone in their corner between formal engagements.
Price depends on how many people can log in. Locations do not change it, because the monthly work follows accounts and vendors, not buildings.
Up to 20 logins: $1,950 per month, up to 8 hours included
21 to 50 logins: $2,950 per month, up to 12 hours included
51 or more logins: from $3,950 per month, up to 18 hours included
Pragmatic cybersecurity and technology strategy support for organizations that need steady progress, not a one-time report.
Through a light monthly cadence and quarterly executive reporting, we track remediation, refresh the risk register, strengthen vendor and incident readiness, and turn security work into measurable outcomes and board or owner decisions. This is independent leadership and accountability that complements your IT provider, keeping priorities aligned to the work you actually do, uptime, and what’s actually achievable in an organization.
WHAT’S INCLUDED EACH MONTH
Monthly remediation tracking with status updates and owner follow-through
Roadmap/Risk register refresh: new vendors, staff changes, system changes flagged and scored
Vendor review/oversight (BAAs, new tools, IT provider spot-checks)
Incident readiness (tabletop prep, response plan review, backup verification)
Routine vulnerability scanning, external and internal, with findings added to your risk register
Quarterly executive reporting in board-ready language
Async advisory, email questions, quick calls, ad hoc guidance as needed
Time Commitment: About an hour per month, plus two hours every quarter for review.
Typical engagement vary by month. Light months when things are stable; heavier when something material changes, like a new system going in, an incident scare, an insurance renewal.
| Engagement | Price | Delivery | Best For |
|---|---|---|---|
| Security Snapshot | $1,500 | 5 business days | First look at security posture; no formal program yet |
| IT Provider Review | $1,500 | 5 business days | Independent check on what your IT provider is actually doing |
| Cyber Insurance Application Review | $1,950 | 5 business days | Renewal prep; ensuring controls match application answers |
| Incident Response Tabletop | $900 | 3 business days | Stress-testing your response before a real incident |
| Security Awareness Briefing | $750 | Scheduled | Staff training tailored to how your organization operates |
| Payment Security Review | $750 | 5 business days | How card data flows; risk where payment terminals meet other systems |
| Defensible Risk Assessment | From $5,950 | 3–6 wks | HIPAA Defensible assessment with ranked register and 90-day plan |
| Governance Implementation Sprint | $9,950 | 8–12 wks | Policies, evidence binder, governance cadence, ownership |
| Security Leadership (vCISO) Retainer | $1,950 to $3,950/mo | 12-mo min | Ongoing oversight; quarterly executive reporting |
Because hiding prices forces every visitor into a sales call to find out if they can afford a conversation. That’s not how I want to work, and it’s not how the people I respect want to buy. The prices on this page are the prices.
Two questions settle it most of the time. How many locations do you have, counting anywhere staff regularly work? And how many people have a login of any kind, counting part-timers, contractors, and anyone else with an account? Tell me those two numbers and I will give you a firm price on the call, not a proposal a week later. If something about your setup changes the scope, I will tell you before we start rather than after.
Your IT company sells you service and tools. I do not. No referral fees. No vendor partnerships. No commission on anything I recommend. When your IT company reviews their own work, you get the answer they’re comfortable giving you. When I review it, you get the answer.
Yes. Governance work is delivered through an established platform that hosts your risk register, evidence binder, policies, and remediation tracking. You have access while the engagement runs, and everything in it is delivered to you as documents you keep. Clients on a retainer keep that access open month to month, so the record stays current for renewals instead of aging out.
What I do not sell: security products, IT services, or anything I would earn a referral fee on. The platforms exist to support the work, not to lock you into a vendor relationship.
No. A good IT provider is doing real, valuable work. Patching, monitoring, backups, support. My role is independent oversight that complements that work and gives you confidence the right things are actually happening. Most of my clients keep their IT company and run me alongside.
Northline executes a Non-Disclosure Agreement with every client before any engagement begins. All work product is yours; nothing is shared with vendors or third parties without your written consent.
Maybe not. It depends on three things.
First, how old is it? HIPAA expects your risk analysis to be current, not done once and filed. If yours predates a new location, a new system, a change in who touches patient records, or meaningful staff turnover, it no longer describes your practice.
Second, who did it? If the company that produced it is the same company that runs your IT, they graded their own work. That is not a knock on them. It is just how conflicts work, and it is the reason an insurer or an investigator may not give it much weight.
Third, what happened next? If it came back with findings and nothing was done about them, the document is not helping you. It may be doing the opposite.
Send me what you have. If it holds up, I will tell you that and you will have saved yourself the money. If it doesn't, you will know exactly why.
It covers half of it, and that surprises most people.
The Security Rule asks for two things, not one. First, an accurate and thorough assessment of the risks to your patient information. Second, a plan to actually reduce those risks, and proof you are working it. Both requirements sit side by side in the same place in the rule, at 45 CFR 164.308(a)(1)(ii).
Most practices only ever do the first. They get an assessment, file it, and assume they are covered. Then an insurer or an investigator asks what they did about the findings, and there is no answer. An assessment with nothing after it can end up documenting that you knew about a problem and left it alone.
This engagement gives you both halves in writing: the assessment, and a 90-day plan with a name and a date next to every item. What it cannot do is the work itself. No assessment makes you compliant. Compliance is what happens after, when the things on that plan actually get done and you can show they got done.
That is the part I will tell you up front. If the plan sits in a drawer, you are where you started, just with better paperwork.
Then start with an entry offer. Every one of them produces something written you can act on, and none of them requires you to buy the next thing. Needing something and being able to afford it are two different problems. I would rather help you with the second one honestly than pretend the first one went away.
Yes. Engagements are delivered remotely, so location isn’t a barrier. Your risk register, evidence, and reporting are files you can open from anywhere. On-site work is available regionally. If you’re wondering whether distance is a problem, it probably isn’t. Reach out and we’ll talk.
Every engagement on this page is done by me, not handed off to a junior analyst. I am Tom Polk. Thirty years in IT leadership, most recently as CIO and Chief Security Officer for a multi-state healthcare group.
If you’re new and exploring. Book a 30-minute consultation. No pitch, no pressure. We’ll talk through what you’re actually worried about.
If you have a specific question. Pick the entry offer that fits and we’ll get on a call to scope it.
If you’re ready for a Risk Assessment. Send a note describing your practice (number of locations, EHR Platform, IT arrangement, staff size) and we’ll talk timing.
© 2026 NORTHLINE ADVISORS, LLC