HIPAA Security Risk Assessment for New Jersey Medical & Dental Practices

The HIPAA Security Rule requires covered entities to conduct an accurate and thorough risk analysis and maintain appropriate documentation. FINT System performs documented security risk assessments for practices across New Jersey, led by a CISA-certified IT auditor, for a fixed fee.

What the rule actually requires

Under 45 CFR §164.308(a)(1)(ii)(A), covered entities must conduct an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information. HHS guidance describes risk analysis as an ongoing process and does not prescribe one universal review interval; timing depends on changes and circumstances in the environment. Separately, eligible clinicians participating in the MIPS Promoting Interoperability performance category should review the current CMS Security Risk Analysis measure requirements for the applicable performance year.

In practice, most small practices we speak with are in one of three positions: no risk analysis has ever been performed, one was done years ago and never revisited, or the current IT vendor has given a verbal assurance that "everything is covered" with nothing documented. None of those three would hold up if the practice were asked to produce evidence.

What you receive

A written report, not a checklist. Specifically:

  • On-site technical review — network and firewall configuration, workstations and servers, endpoint protection, patch status, backup existence and restore testing, Microsoft 365 or Google Workspace security configuration, multi-factor authentication coverage, wireless network segmentation, and remote access
  • Administrative and access review — user account inventory, permission levels, offboarding process for departed staff, vendor and business associate inventory, and written policy gaps
  • Findings mapped to the Security Rule — each finding tied to the specific administrative, physical or technical safeguard it relates to
  • Risk ranking — findings ordered by actual risk to the practice, not presented as an undifferentiated list
  • Remediation plan — what to fix, in what order, with effort and cost estimates so you can budget it
  • Executive summary — a first page a practice owner can read and understand without technical background

Turnaround is two weeks from the on-site visit. The on-site portion typically takes half a day and does not require closing the office.

Independent of your IT company

This is the part practices ask about most, so we will be direct: this engagement does not require you to change your IT provider.

If the same provider both manages an environment and evaluates its own controls, the review is not independent of that provider. That does not mean the provider is incompetent or that its internal review has no value. FINT System can provide a separate assessment perspective, document the findings, and give the practice a remediation plan it can use with its current IT provider or another provider.

If you would like us to perform the remediation, we can. But the assessment is a standalone deliverable and is priced as one.

Pricing

Up to 15 endpoints
$2,500
16–35 endpoints
$3,500
36–60 endpoints
$4,500

Fixed fee, quoted and agreed before any work begins. No hourly billing on assessment engagements. Larger practices and multi-location groups are scoped individually.

What this is, and what it isn't

We think it is worth being precise, because there is a lot of loose language in this market.

This engagement covers the technical and administrative safeguards assessment required under the HIPAA Security Rule, delivered as documented, defensible work product.

This engagement does not constitute legal advice, does not cover Privacy Rule policy drafting or workforce training programs, and does not make a practice "HIPAA certified" — no such certification exists, and any vendor offering one is selling something that isn't real. Practices needing Privacy Rule policy work should coordinate that with healthcare counsel; we are glad to work alongside them.

We sign a Business Associate Agreement before beginning any engagement involving access to systems containing ePHI.

Who this is for

Medical practices, dental practices, physical therapy and chiropractic offices, and specialty clinics across New Jersey — typically 3 to 60 staff, without an internal IT department, where the practice owner or office manager makes the decision.

Assessments are performed on-site by the person who writes the report. Nothing is subcontracted. We are based on the Route 9 corridor and travel statewide for assessment work.

About the auditor

FINT System's compliance work is led by a CISA-certified IT auditor with seven years of banking IT audit experience covering ITGC, SOX and information security controls. That background is why the assessment is structured as an audit deliverable — scoped, evidenced, risk-ranked and defensible — rather than as a vendor questionnaire.

See what a real assessment looks like

A redacted sample HIPAA Security Risk Assessment — the same format we deliver, with client-identifying detail removed. No sales call attached.

We'll email the report and nothing else unless you ask. No newsletter, no drip sequence.

HIPAA Security Risk Assessment — Frequently Asked Questions

Is a HIPAA risk analysis really required every year?

The Security Rule requires an accurate and thorough risk analysis and an ongoing risk-management process, but HHS does not prescribe one universal interval for every covered entity. The appropriate review cycle depends on the organization and changes to systems, operations, threats, vendors, and ePHI. Eligible clinicians participating in MIPS Promoting Interoperability should also follow the current CMS Security Risk Analysis measure requirements for the applicable performance year.

Our IT company says they handle this. Is that enough?

Ask what documented risk-analysis work has been completed, when it was last updated, what systems and ePHI were in scope, and how identified risks are being managed. Your IT provider may already perform valuable security work. FINT System is useful when you want a separately scoped, documented assessment and a prioritized remediation plan.

How long does it take, and how disruptive is it?

The on-site portion is typically half a day and runs alongside normal operations — we are looking at configurations and documentation, not taking systems offline. The written report follows within two weeks.

Do you sign a Business Associate Agreement?

Yes, before any engagement involving access to systems containing ePHI. We can work from your BAA or provide ours.

If you find problems, do we have to hire you to fix them?

No. The report is yours. Many practices hand it to their existing IT vendor. We are available for remediation if you want us, and we will quote that separately — but the assessment is not a sales instrument for follow-on work.

Does this make our practice HIPAA compliant?

No, and be cautious of anyone who says otherwise. There is no official HIPAA certification. Compliance is an ongoing obligation covering areas beyond information technology, including Privacy Rule policies, workforce training and business associate management. A risk analysis is one required component of it — an important one, and the one most commonly missing — but it is a component, not a certificate.

Starting price
From $2,500

Fixed fee, scoped to practice size. Quoted and agreed before any work begins.

Before we begin
  • Business Associate Agreement signed before every healthcare engagement
  • NJ Telecommunications Contractor License #34TE00315100
  • Performed by a CISA-certified auditor with 7 years of banking IT audit experience

Quick request form

Call, email, or send your project details. We will review your request and provide the best next step.

Contact: 848-458-1000 · info@fintsystem.com
Address: 81 Division St, South River, NJ 08882