Right-sized engagements for healthcare practices that want straight answers.

From a $750 briefing to a full HIPAA Risk Assessment to ongoing security leadership. Every engagement is independent, plain-language and actionable from day one.

TIER 1

START HERE

Six entry offers from $750 to $1,950. Designed for practices that want a focused look at one specific question without committing to a larger engagement.

TIER 2

GO DEEP

The flagship Defensible Risk Assessment and Governance Implementation Sprint. For organizations ready to do the substantive work of putting a real program in place.

TIER 3

KEEP IT GOING

The Security Leadership (vCISO) Retainer. Steady oversight, monthly tracking, with a quarterly report for practice that want sustained progress between formal engagements.

TIER 1 — ENTRY OFFERS

Most engagements with Northline start here. Each entry offer answers one specific question and gives you something tangible to act on, a written deliverable you can take to your owner, your insurer, or your next leadership meeting. They’re priced under $2,000 so you can say yes without a procurement conversation, and they’re scoped tightly so you’re not buying a generalist’s wandering opinion.

01. SECURITY SNAPSHOT

A first look at your security posture with actionable first steps

$1,500 flat fee   |   Delivered within 5 business days

A 90-minute structured conversation plus a scan of your top security gaps and immediate next steps.

Best for: A medical or dental office with no written security program, or one that got nervous after hearing what happened to another office nearby.

Time Commitment: 90 minute conversation and 30 minutes for review.

What you get: Written Security Snapshot Memo (2–3 pages): top gaps identified, risk level (High / Medium / Low), and 3–5 prioritized next steps.

Natural next step: Defensible Risk Assessment

02. IT PROVIDER REVIEW

You pay them every month. Do you know what you are actually getting?

$1,500 flat fee   |   Delivered within 5 business days

An independent review of your current IT provider contract and practices, so you know where you are covered and where you are not. I ran an IT company for 24 years, so I know what a good contract looks like and what gets left out of a bad one.

Best for: A practice that hands all IT and security to one outside company and has no way to check the work.

Time Commitment: About two hours, plus copy of your contract.

What you get: IT Provider Scorecard (summary with ratings across 8–10 critical areas) plus a written narrative memo highlighting gaps, missing protections, and follow-up questions to bring to your IT provider.

Natural next step: Defensible Risk Assessment

03. CYBER INSURANCE APPLICATION REVIEW

You are facing rising premiums and tougher applications.

$1,950 flat fee   |   Delivered within 5 business days

Prepare for your renewal. Know what you’ll be asked and whether your current controls support your answers.

Best for: A practice facing renewal, rising premiums, or an insurer asking for documentation it never asked for before.

Time Commitment: About two hours, plus the application and your current policy.

What you get: Cyber Insurance Application Review Summary: current posture vs. insurer expectations, flagged gaps that could affect coverage or claims, and a short list of quick wins to improve position before renewal.

Natural next step: Defensible Risk Assessment

Every one of these ends with a document you own. Where you go next is your call, not mine.

04. INCIDENT RESPONSE TABLETOP

$900 flat fee   |   Summary delivered within 3 business days

A facilitated 2-hour walk-through of how your team would actually respond to a real scenario. For a practice that is usually ransomware or a data breach. So the first time isn’t the real thing.

Best for: A practice that heard about a local ransomware hit and wants to test its readiness. Leadership want to make sure that when an incident occurs, there is a plan.

Time Commitment: Two hours for leadership

What you get: Post-Tabletop Summary Memo: scenario overview, key gaps surfaced, roles and decisions that broke down, and 3–5 prioritized recommendations. Suitable for owner review.

Natural next step: Security Leadership (vCISO) Retainer or full Risk Assessment

05. SECURITY AWARENESS BRIEFING

$750 flat fee   |   Scheduled at your convenience

A 60-minute staff training session built around how your office actually operates. For a practice it covers handling patient information under HIPAA.

Best for: A practice that has never done formal security awareness training, is onboarding new staff, or needs training documentation for an insurer, or a payer.

Time Commitment: 60 minutes of staff time.

What you get: Customized 60-minute staff briefing (on-site or virtual) covering phishing, device handling, password hygiene, and breach reporting. Includes attendance log template, a 1-page staff reference card, and a facilitator summary memo.

Natural next step: IT Provider Review, Snapshot, or Governance Sprint

06. PAYMENT SECURITY REVIEW

$750 flat fee   |   Delivered within 5 business days

A focused conversation about how you take card payments and where that data goes. For a practice that means patients and the network your EHR sits on.

Best for: A practice whose card terminal shares a network with the EHR or the billing system.

Time Commitment: About 90 minutes.

What you get: Payment Security Process Review Memo (2–3 pages): how card data currently flows, observed process gaps, risk observations (especially system / network adjacency), and 3–5 practical recommendations. Includes clarifying questions for your payment processor and IT provider.

Natural next step: Security Snapshot or full Risk Assessment

TIER 2 — FLAGSHIP & SPRINT ENGAGEMENTS

When you are ready to move beyond a single conversation and put a real program in place, these are the engagements that do the work. Both produce defensible documentation, ranked priorities, and clear ownership, not a stack of generic templates with your name pasted on.

FLAGSHIP.  DEFENSIBLE RISK ASSESSMENT

Measured against the HIPAA Security Rule. Covers the administrative, physical, and technical safeguards the rule requires.

THE FRAMEWORK BEHIND THE ASSESSMENT

Your assessment runs on SecurityStudio S2Org, an established risk assessment framework used by thousands of organizations. It looks at four areas: your policies and your people, your physical space, the technology inside your walls, and what an outsider can see about your practice from the internet.

Every assessment produces a HIPAA gap report that maps each finding back to the requirement it relates to. So when an insurer, an auditor, or an investigator asks how you know where you stand against the Security Rule, you have a document that answers it line by line. That is most of what makes an assessment defensible.

You also get an S2Score, a single number between 300 and 850 that works like a credit score. Your owners get one figure they can understand, track year over year, and hand to an insurer.

That fourth area is the one most owners have never seen. It looks at your practice the way an outsider would, without touching anything inside. What shows up in a search, what is reachable from the internet, what your public records give away.

I do not sell SecurityStudio and I earn nothing on it. It is what I measure with.

$5,950 to $13,950 depending on size | 3 to 6 weeks

An independent Risk Assessment that shows where your risks are and what to fix first, with a remediation roadmap you can work from.

This is the core engagement most practices come to Northline for. You get decision-ready priorities, owners, timelines, and evidence expectations, so leadership can prove safeguards, reduce downtime risk, and move forward confidently without vendor pressure shaping the answer.

What it costs

Price depends on two things: how many locations you have, and how many people can log in. Find yourself below.

Up to 20 logins

One Location
$5,950 · 3-4 weeks

Up to 50 logins

One or Two Locations
$7,950 · 4-5 weeks

more than 50 logins

Three or more locations
$8,950 to $13,950 · 5-6 weeks

The rule behind the numbers: start at $5,950, add about $1,000 for each additional location, and about $1,000 for every thirty people with a login.

Count logins, not employees. Part-time staff, contractors, billing help, and anyone working from home all have accounts, and every account takes time to review. Most practices guess low on this. If you are not sure, that is fine. Fifteen minutes on the phone gets you a firm number.

Patient records are why this work runs deeper than it does elsewhere. Vendor agreements, the Privacy Rule, breach notification, and finding every place records actually live are all part of the engagement. That is built into the numbers above rather than added later.

What else can move the price

•      More than one IT vendor, because each one is a separate conversation

•      No existing documentation, or an assessment old enough that it predates your current systems

•      Card payments, especially where a terminal shares a network with the EHR

•      Review of business associates and other 3rd party vendors.

WHAT’S INCLUDED

  • HIPAA Risk Assessment covering Administrative, Physical and Technical controls

  • Ranked Risk Register

  • 90-day Remediation Roadmap

  • Executive Summary

  • Board / Owner Briefing

  • Evidence Request and Gap Log

  • All platform and tool access needed to do the work, included in the price

HIPAA asks for two things: an assessment of your risks, and a plan to reduce them. The 90-day roadmap above is the second half, which is the half most practices skip.

HOW IT RUNS

Engagement runs three to six weeks. Discovery and mapping where patient records actually live, including the places nobody thinks about are first. Second is the assessment against the Security Rule. Third is interviews, the risk register, the roadmap, and the evidence work. Finally is review, the executive summary, and a live briefing with your owners.

Time Commitment: 10 to 15 hours across your team over the course of the engagement. 90 minutes for the final presentation.

Natural next step: Governance Implementation Sprint or Security Leadership Retainer

SPRINT.  GOVERNANCE IMPLEMENTATION SPRINT

$9,950, after Risk Assessment  |   8–12 weeks

A governance-first build-out of policies, controls, vendor practices, and the evidence binder that proves your safeguards are actually operating.

A Risk Assessment tells you what’s wrong. The Governance Sprint puts the structure in place to keep it right. The outcome is plain-English findings and a practical governance cadence covering metrics, responsibilities, and a prioritized roadmap, so your organization stops relying on assumptions and starts managing security as an ongoing program. Designed to work even with lean internal IT or an outside provider doing it all.

WHAT’S INCLUDED

  • Customized policy set (written to how your organization actually operates, not dropped in from a template)

  • Evidence binder structure and roadmap

  • Assigned ownership across roles

  • Governance cadence setup (meeting and review rhythms)

  • Quarterly metric dashboard template

  • Access to GRC platform (Medcurity) for 12 months from start of engagement

HIPAA asks for two things: an assessment of your risks, and a plan to reduce them. You need to develop the 90-day roadmap and then show that you have made progress in addressing the found issues.

HOW IT RUNS

Engagement 8–12 weeks after you have completed the Risk Assessment. The bulk of the time is the customized policy set. Not boilerplate. Policies tailored to your EHR, your IT arrangement, your vendor mix, and how your staff actually work. Throughout, you’re building the muscle to run governance as an ongoing practice, not a one-time deliverable.

Time Commitment: About 20 to 30 hours across the team.

Natural next step: Security Leadership Retainer for ongoing oversight

TIER 3 — ONGOING SUPPORT

A Risk Assessment and Governance Sprint produce documentation. Ongoing support produces results. The Security Leadership (vCISO) Retainer is for organizations that want continued forward motion and someone in their corner between formal engagements.

RETAINER. SECURITY LEADERSHIP (vCISO) RETAINER

$1,950 to $3,950 per month depending on size | 12-month minimum

Price depends on how many people can log in. Locations do not change it, because the monthly work follows accounts and vendors, not buildings.

Up to 20 logins: $1,950 per month, up to 8 hours included

21 to 50 logins: $2,950 per month, up to 12 hours included

51 or more logins: from $3,950 per month, up to 18 hours included

Pragmatic cybersecurity and technology strategy support for organizations that need steady progress, not a one-time report.

Through a light monthly cadence and quarterly executive reporting, we track remediation, refresh the risk register, strengthen vendor and incident readiness, and turn security work into measurable outcomes and board or owner decisions. This is independent leadership and accountability that complements your IT provider, keeping priorities aligned to the work you actually do, uptime, and what’s actually achievable in an organization.

WHAT’S INCLUDED EACH MONTH

  • Monthly remediation tracking with status updates and owner follow-through

  • Roadmap/Risk register refresh: new vendors, staff changes, system changes flagged and scored

  • Vendor review/oversight (BAAs, new tools, IT provider spot-checks)

  • Incident readiness (tabletop prep, response plan review, backup verification)

  • Routine vulnerability scanning, external and internal, with findings added to your risk register

  • Quarterly executive reporting in board-ready language

  • Async advisory, email questions, quick calls, ad hoc guidance as needed

Time Commitment: About an hour per month, plus two hours every quarter for review.

Typical engagement vary by month. Light months when things are stable; heavier when something material changes, like a new system going in, an incident scare, an insurance renewal.

Quick reference for everything above:

Engagement Price Delivery Best For
Security Snapshot $1,500 5 business days First look at security posture; no formal program yet
IT Provider Review $1,500 5 business days Independent check on what your IT provider is actually doing
Cyber Insurance Application Review $1,950 5 business days Renewal prep; ensuring controls match application answers
Incident Response Tabletop $900 3 business days Stress-testing your response before a real incident
Security Awareness Briefing $750 Scheduled Staff training tailored to how your organization operates
Payment Security Review $750 5 business days How card data flows; risk where payment terminals meet other systems
Defensible Risk Assessment From $5,950 3–6 wks HIPAA Defensible assessment with ranked register and 90-day plan
Governance Implementation Sprint $9,950 8–12 wks Policies, evidence binder, governance cadence, ownership
Security Leadership (vCISO) Retainer $1,950 to $3,950/mo 12-mo min Ongoing oversight; quarterly executive reporting

COMMON QUESTIONS

WHY IS YOUR PRICING VISIBLE? MOST CONSULTANTS HIDE THEIRS.

Because hiding prices forces every visitor into a sales call to find out if they can afford a conversation. That’s not how I want to work, and it’s not how the people I respect want to buy. The prices on this page are the prices.

HOW DO I KNOW WHICH PRICE APPLIES TO US?

Two questions settle it most of the time. How many locations do you have, counting anywhere staff regularly work? And how many people have a login of any kind, counting part-timers, contractors, and anyone else with an account? Tell me those two numbers and I will give you a firm price on the call, not a proposal a week later. If something about your setup changes the scope, I will tell you before we start rather than after.

HOW ARE YOU DIFFERENT FROM OUR IT PROVIDER?

Your IT company sells you service and tools. I do not. No referral fees. No vendor partnerships. No commission on anything I recommend. When your IT company reviews their own work, you get the answer they’re comfortable giving you. When I review it, you get the answer.

DO YOU USE ANY TOOLS DURING ENGAGEMENTS?

Yes. Governance work is delivered through an established platform that hosts your risk register, evidence binder, policies, and remediation tracking. You have access while the engagement runs, and everything in it is delivered to you as documents you keep. Clients on a retainer keep that access open month to month, so the record stays current for renewals instead of aging out.

What I do not sell: security products, IT services, or anything I would earn a referral fee on. The platforms exist to support the work, not to lock you into a vendor relationship.

DO YOU REPLACE OUR IT COMPANY?

No. A good IT provider is doing real, valuable work. Patching, monitoring, backups, support. My role is independent oversight that complements that work and gives you confidence the right things are actually happening. Most of my clients keep their IT company and run me alongside.

HOW DO YOU HANDLE CONFIDENTIALITY?

Northline executes a Non-Disclosure Agreement with every client before any engagement begins. All work product is yours; nothing is shared with vendors or third parties without your written consent.

WE'VE ALREADY DONE A RISK ASSESSMENT, DO WE NEED ANOTHER ONE?

Maybe not. It depends on three things.

First, how old is it? HIPAA expects your risk analysis to be current, not done once and filed. If yours predates a new location, a new system, a change in who touches patient records, or meaningful staff turnover, it no longer describes your practice.

Second, who did it? If the company that produced it is the same company that runs your IT, they graded their own work. That is not a knock on them. It is just how conflicts work, and it is the reason an insurer or an investigator may not give it much weight.

Third, what happened next? If it came back with findings and nothing was done about them, the document is not helping you. It may be doing the opposite.

Send me what you have. If it holds up, I will tell you that and you will have saved yourself the money. If it doesn't, you will know exactly why.

DOES THIS SATISFY WHAT HIPAA REQUIRES?

It covers half of it, and that surprises most people.

The Security Rule asks for two things, not one. First, an accurate and thorough assessment of the risks to your patient information. Second, a plan to actually reduce those risks, and proof you are working it. Both requirements sit side by side in the same place in the rule, at 45 CFR 164.308(a)(1)(ii).

Most practices only ever do the first. They get an assessment, file it, and assume they are covered. Then an insurer or an investigator asks what they did about the findings, and there is no answer. An assessment with nothing after it can end up documenting that you knew about a problem and left it alone.

This engagement gives you both halves in writing: the assessment, and a 90-day plan with a name and a date next to every item. What it cannot do is the work itself. No assessment makes you compliant. Compliance is what happens after, when the things on that plan actually get done and you can show they got done.

That is the part I will tell you up front. If the plan sits in a drawer, you are where you started, just with better paperwork.

WHAT IF THE FULL ASSESSMENT IS OUT OF REACH RIGHT NOW?

Then start with an entry offer. Every one of them produces something written you can act on, and none of them requires you to buy the next thing. Needing something and being able to afford it are two different problems. I would rather help you with the second one honestly than pretend the first one went away.

DO YOU WORK WITH ORGANIZATIONS OUTSIDE INDIANA?

Yes. Engagements are delivered remotely, so location isn’t a barrier. Your risk register, evidence, and reporting are files you can open from anywhere. On-site work is available regionally. If you’re wondering whether distance is a problem, it probably isn’t. Reach out and we’ll talk.

Every engagement on this page is done by me, not handed off to a junior analyst. I am Tom Polk. Thirty years in IT leadership, most recently as CIO and Chief Security Officer for a multi-state healthcare group.

More about how I got here.

Three ways to start the conversation, depending on where you are:

If you’re new and exploring. Book a 30-minute consultation. No pitch, no pressure. We’ll talk through what you’re actually worried about.

If you have a specific question. Pick the entry offer that fits and we’ll get on a call to scope it.

If you’re ready for a Risk Assessment. Send a note describing your practice (number of locations, EHR Platform, IT arrangement, staff size) and we’ll talk timing.

© 2026 NORTHLINE ADVISORS, LLC