Fixed-Fee Assessment — Small Healthcare Practices

Know where your client data goes when your staff use AI.

Three weeks from kickoff. One fixed fee. I map where patient and client information actually meets the AI tools your team already uses, check it against the HIPAA Security Rule, and hand you a prioritized fix list in plain English — documentation you own and can show. No records of any kind. No logins. One person doing the work, start to finish.

By the founder of HIPAAPath — built on the audit-trail discipline used to certify flight software.

Your staff are probably already using AI tools, and client data may be going with them. Not out of carelessness — the tools genuinely help, and nobody ever told anyone where that text ends up. That isn't a discipline problem. It's a map problem: you can't write rules for paths nobody has drawn, and “ban AI” just moves the same activity somewhere you can't see it.

This assessment draws the map. Over about three weeks I inventory the AI tools actually in use — the sanctioned ones, and the ones that surface once staff can answer without a name attached — trace where protected data meets them, measure that against the safeguards your obligations actually name, and hand you a prioritized fix list written so an owner can read it. The deliverable is the list, not a 200-page report.

Nobody gets to zero risk here, and nobody is asking you to. What changes is that “where does your client data go?” stops being a question you brace for and becomes a document with your name on it.

What you walk away with

A findings report in plain English

Owner-readable, in an audit-ready format — each gap scored against the HIPAA Security Rule safeguards as laid out in NIST SP 800-66, with what it means for you in a sentence, not a citation.

A one-page data-flow map

Where regulated data lives, where it moves, and every place it meets an AI tool. One page, deliberately — a map nobody opens tells you nothing.

A prioritized fix list, with effort levels

Ordered by what actually reduces exposure, each item marked with roughly what it will take — some of it is a settings change you can make the same afternoon. The order is a suggestion, not homework with a due date.

An AI acceptable-use policy, tailored and ready to adopt

Written for your practice and your tools, short enough that your staff will read it. Plus a checklist of the vendor agreements you're missing — Business Associate Agreements, the contract where a vendor commits in writing to handle protected information properly.

A 60-minute readout, and 30 days of questions

I walk you through the map, the findings, and the plan — then stay reachable by email for thirty days while you work the list.

Twelve months of HIPAAPath, included

My own product for small-practice HIPAA documentation, where what you write stays in your own storage. A year of it comes with the assessment, and what we captured along the way — your systems, your vendors, your paperwork — comes as a file you load straight in, so you start with your own practice already filled in rather than an empty tool.

The findings are also built to feed the written risk analysis HIPAA expects a covered practice to keep. This isn't that document and doesn't stand in for it — but the map, the systems inventory, and the gap findings are exactly the raw material it draws on, so that work starts from something instead of a blank page.

What it costs

21–50 staff, or multi-site from $15,000 custom

More locations and more entities mean more paths to trace. Quoted after the fit call, still fixed once quoted.

Right at the line between the two? The fit call sorts it — it usually comes down to sites and systems rather than headcount.

Half to schedule, half at the readout. No retainers, no hourly billing, no change orders — a fixed-fee box, so you know the number before you say yes.

If you're a solo practitioner or under five staff, don't hire me for this. You don't need a consultant at consulting prices; you need the documentation done properly. HIPAAPath does this at product prices, and I'll point you there.

How it works

  1. You email me. no form, no funnel Tell me what kind of practice you run and what's worrying you. That's enough to start.
  2. A 20-minute fit call, free. 20 minutes We work out whether this is the right thing for you. Sometimes the answer is no, and I'll say so — that's a cheaper conversation now than after an invoice.
  3. A fixed quote and a date. same week You get the number and the schedule in writing before anything starts.
  4. Kickoff, then the assessment. about three weeks from kickoff Kickoff is a short call on the agreed start date — it books everything and starts the clock. Then: a questionnaire for you, a five-minute no-names survey for staff, and three 45-minute conversations — you, whoever runs your front office, and one clinician. I do the analysis while your practice goes on running.
  5. The readout, and the documentation is yours. 60 minutes I walk you through the map, the findings, and the plan — bring whoever you want in the room. You keep everything: report, policy, and fix list.

How I run it: no records, no logins

The assessment runs entirely on metadata — what systems you have, what flows where, what your team actually does. I never ask to see records of any kind — patient or client — I never take credentials, and walkthroughs are screen-share, view only. That keeps my own footprint on your data at nearly zero, which is the point: an assessment that creates a new exposure while measuring your old ones isn't worth buying.

About the staff survey, plainly: in a team your size, a survey isn't really anonymous, and pretending otherwise would insult everyone taking it. So it's discreet rather than anonymous — nine checkbox questions, about five minutes, no names and no sign-in, and I only ever see totals. What actually makes it work isn't the survey design; it's you saying out loud at a staff meeting that nobody gets in trouble for anything that's already happened. We're fixing the system, not the people. And anyone who'd rather tell me something directly can: everything is reportable, nothing is attributable.

On my side, and you should ask this of anyone selling you AI governance: I use AI agents to do the drafting, the same way I do the rest of my engineering work. What they work from is the same metadata you gave me — system names, workflows, roles. There are no client records in it, because I never collected any, and findings are written by workflow rather than by person. Every one of them is then verified and signed by me. The judgment about your practice is mine, and you get one named person who will still take your call in six months.

What's in, and what isn't

In scope

  • AI-usage inventory — no-names staff survey plus three structured interviews
  • Obligation baseline against the HIPAA Security Rule and NIST SP 800-66
  • Findings report, in plain English
  • One-page data-flow map
  • Prioritized fix list with effort levels
  • Tailored AI acceptable-use policy, plus the vendor-agreement checklist
  • 60-minute readout and 30 days of email questions
  • Twelve months of HIPAAPath

Not in scope

  • Legal advice — I'm an engineer, not your attorney
  • Certification of any kind, and no claim that you are compliant
  • Implementing the fixes — if you want help after the readout, we scope that separately
  • Penetration testing or technical security auditing
  • Anything at hospital-system scale
Worth being direct about: no assessment makes anyone HIPAA compliant. Compliance is something you keep doing, not something you receive. What this gives you is an accurate picture of where you stand, a plan you can work, and documentation showing you took the question seriously — which is where a defensible answer starts, not where it ends.

It's technical mapping, not legal advice — and that's a feature. It gives your compliance counsel something concrete to work from instead of a conversation that starts at zero.

Who this is for

Small healthcare practices of roughly 5 to 50 staff — therapy groups, dental and medical practices, optometry, anywhere someone is accountable for patient or client information and nobody is entirely sure which AI tools the team has picked up.

Not sure that's you? Plenty of businesses handle patient information without thinking of themselves as healthcare — billing services, IT providers, law and accounting firms working for healthcare clients. Whether the rules reach you, and whether I'm the right person for the work, is exactly what the fit call is for. Twenty minutes, free, and I'd rather sort it there than have either of us guess from a web page.

Above about 50 staff, or at hospital-system scale, you want a firm with a bench rather than one person signing findings — and I'll tell you that rather than take the work.

One case where I'm the wrong call: if you think something has already gone wrong — data somewhere it shouldn't be, a breach you're not sure how to size — your first call is a breach attorney, not me. There are legal clocks involved, and protections an attorney has to put in place before anyone technical touches it. Get counsel in first; I'll still be here after.

If you'd like the do-it-yourself version first, I wrote one: where client data actually goes when your staff use AI → — the first two steps cost nothing but attention, and if that's all you need, take it and go.

Availability

I take a limited number of these — two a month, one in flight at a time. HIPAAPath is my primary work, and this assessment only works if the person signing the findings actually had time to think about your practice. If the next slot is a few weeks out, I'll tell you that on the fit call.

I've spent 25 years in software, 21 of them in regulated industries and 15 on certified avionics at Rockwell Collins and Collins Aerospace — DO-178B/C DAL B on flight management systems, where a mistake isn't an inconvenience. Between those tenures I led Transamerica's enterprise Agile transformation, on insurance systems handling PHI. I'm a named inventor on U.S. patents, and I run TDM Technologies and HIPAAPath — HIPAA compliance for small practices, where the documentation never leaves the practice's own storage. I work from Cedar Rapids, Iowa.