For healthcare practices, home health, financial advisers, law firms, and anyone with a cyber-insurance renewal
A real security lead for a practice that cannot hire one.
A full-time Chief Information Security Officer costs more than most practices earn from a provider. A vCISO retainer gives you the same named, credentialed person for a fraction of the cost, with HIPAA, Reg S-P, and your insurer handled.
- HIPAA Security Rule (45 CFR Part 164)
- HIPAA Breach Notification Rule
- SEC Regulation S-P (2024 amendments)
- NIST Cybersecurity Framework 2.0
- Cyber-insurance carrier requirements
Two clocks are already running
Verified September 2026HIPAA has always required a documented Security Rule risk analysis, and it remains the finding in nearly every OCR enforcement action. For advisers, the SEC's amended Regulation S-P took effect for smaller firms on June 3, 2026: every RIA now needs a written incident response program and a 30-day customer notification process. Insurers, meanwhile, are denying renewals to practices that cannot show MFA, backups, and a named owner.
Who this is for
- Medical, dental, and specialty practices
- Home health and assisted living operators
- Registered investment advisers and wealth managers
- Law firms and title companies
- Any business whose cyber-insurance renewal came with a questionnaire
What usually goes wrong
Your "risk analysis" is a checklist from your EHR vendor
OCR expects an accurate, thorough, practice-specific risk analysis of where ePHI lives and what threatens it. A vendor checklist covers their product, not your practice.
Your IT provider is not a security program
A good MSP patches, backs up, and monitors. HIPAA and Reg S-P require policies, risk analysis, vendor agreements, training, and a responsible person. Those are different jobs, and your MSP will usually say so.
The insurance questionnaire is now a legal document
Misstating your controls on a renewal is how carriers deny claims after a breach. Someone who understands the controls should be completing it.
The front desk is the attack surface
Phishing, fake patient portals, and voicemail scams target staff, not servers. Training twice a year with real examples changes outcomes more than any product.
What you end up with
Deliverables, not deliverable-shaped PDFs.
A defensible risk analysis
Written for your practice, updated annually, and ready to hand to OCR, an SEC examiner, or an insurer.
Policies people will actually follow
Short, specific, and matched to how your office works. Not a binder from a compliance vendor.
A named security lead
My name on the program, a direct line for your office manager, and quarterly time with ownership.
Vendors under control
BAAs in place, high-risk vendors identified, and a process for the next tool someone signs up for.
How the engagement runs
- 01
Discovery call (20 minutes)
Practice size, systems, what you have been asked for, and by whom. I recommend Essentials, Standard, or nothing.
- 02
Risk analysis and baseline (month 1)
Where the data is, who touches it, what the current controls are, and what the real gaps look like, ranked.
- 03
Program build (months 1-3)
Policies, incident response plan, vendor review, insurance questionnaire, and the first staff training. Fixes coordinated with your IT provider.
- 04
Run it (ongoing)
Quarterly or monthly cadence, annual re-assessment, exam and audit support, and a phone that gets answered.
Pricing
vCISO Retainers
Essentials
from $2,500 /month
A security program for a practice or firm with under about 20 staff.
- ✓HIPAA Security Rule risk analysis (or Reg S-P program for RIAs)
- ✓Policy set written for your practice, not a 200-page binder
- ✓Cyber-insurance questionnaire completed and defended
- ✓Quarterly review meeting with ownership
- ✓Vendor and Business Associate Agreement review
- ✓Staff training, twice a year
- ✓Incident response plan and first-call support
Best for: A single-location practice that needs a named security lead and a defensible program.
Standard
from $4,500 /month
Everything in Essentials, with monthly cadence and hands-on remediation oversight.
- ✓Everything in Essentials
- ✓Monthly working session with your owner or office manager
- ✓Oversight of your IT provider or MSP on security work
- ✓Annual penetration test coordination and remediation tracking
- ✓Audit and OCR or SEC-exam preparation
- ✓Board- or partner-level reporting
Best for: Multi-provider practices, RIAs with SEC exam exposure, or anyone who has already had a scare.
Embedded
custom
Roughly a day a week. For organizations that need a CISO in the room but not on payroll.
- ✓Everything in Standard
- ✓Weekly presence, on-site or remote
- ✓Security architecture and vendor selection
- ✓New-location, new-system, or acquisition security reviews
Best for: Groups with 50+ staff, multiple locations, or active regulatory pressure.
A full-time CISO in South Florida costs well over $200,000 a year plus benefits. Most practices need a fraction of that person.
FAQ
vCISO: questions people ask
We are a five-person dental office. Is this overkill?
Essentials is designed for exactly that size. HIPAA does not scale its requirements down for small practices, but the work to meet them does. Most of it is a well-run first quarter and then a light touch.
Do you replace our IT company?
No. I work alongside them. They keep things running; I own the security program and give them a clear, prioritized list. Most IT providers prefer this to being blamed for compliance.
What about the proposed HIPAA Security Rule changes?
HHS proposed significant updates in early 2025 (mandatory MFA, encryption, asset inventories, annual audits). Whatever the final rule looks like, a practice that has a real risk analysis and those controls in place already will not have to scramble. That is the program we build.
Can you handle the SEC side for our RIA?
Yes. The 2024 Reg S-P amendments require an incident response program, service-provider oversight, and 30-day customer notification. That maps closely to the same program, and I include it in the Standard tier.
Get your program started
Talk to Ed