For healthcare practices, home health, financial advisers, law firms, and anyone with a cyber-insurance renewal

A real security lead for a practice that cannot hire one.

A full-time Chief Information Security Officer costs more than most practices earn from a provider. A vCISO retainer gives you the same named, credentialed person for a fraction of the cost, with HIPAA, Reg S-P, and your insurer handled.

  • HIPAA Security Rule (45 CFR Part 164)
  • HIPAA Breach Notification Rule
  • SEC Regulation S-P (2024 amendments)
  • NIST Cybersecurity Framework 2.0
  • Cyber-insurance carrier requirements

Two clocks are already running

Verified September 2026

HIPAA has always required a documented Security Rule risk analysis, and it remains the finding in nearly every OCR enforcement action. For advisers, the SEC's amended Regulation S-P took effect for smaller firms on June 3, 2026: every RIA now needs a written incident response program and a 30-day customer notification process. Insurers, meanwhile, are denying renewals to practices that cannot show MFA, backups, and a named owner.

Who this is for

  • Medical, dental, and specialty practices
  • Home health and assisted living operators
  • Registered investment advisers and wealth managers
  • Law firms and title companies
  • Any business whose cyber-insurance renewal came with a questionnaire

What usually goes wrong

Your "risk analysis" is a checklist from your EHR vendor

OCR expects an accurate, thorough, practice-specific risk analysis of where ePHI lives and what threatens it. A vendor checklist covers their product, not your practice.

Your IT provider is not a security program

A good MSP patches, backs up, and monitors. HIPAA and Reg S-P require policies, risk analysis, vendor agreements, training, and a responsible person. Those are different jobs, and your MSP will usually say so.

The insurance questionnaire is now a legal document

Misstating your controls on a renewal is how carriers deny claims after a breach. Someone who understands the controls should be completing it.

The front desk is the attack surface

Phishing, fake patient portals, and voicemail scams target staff, not servers. Training twice a year with real examples changes outcomes more than any product.

What you end up with

Deliverables, not deliverable-shaped PDFs.

A defensible risk analysis

Written for your practice, updated annually, and ready to hand to OCR, an SEC examiner, or an insurer.

Policies people will actually follow

Short, specific, and matched to how your office works. Not a binder from a compliance vendor.

A named security lead

My name on the program, a direct line for your office manager, and quarterly time with ownership.

Vendors under control

BAAs in place, high-risk vendors identified, and a process for the next tool someone signs up for.

How the engagement runs

  1. 01

    Discovery call (20 minutes)

    Practice size, systems, what you have been asked for, and by whom. I recommend Essentials, Standard, or nothing.

  2. 02

    Risk analysis and baseline (month 1)

    Where the data is, who touches it, what the current controls are, and what the real gaps look like, ranked.

  3. 03

    Program build (months 1-3)

    Policies, incident response plan, vendor review, insurance questionnaire, and the first staff training. Fixes coordinated with your IT provider.

  4. 04

    Run it (ongoing)

    Quarterly or monthly cadence, annual re-assessment, exam and audit support, and a phone that gets answered.

Pricing

vCISO Retainers

Essentials

from $2,500 /month

A security program for a practice or firm with under about 20 staff.

  • HIPAA Security Rule risk analysis (or Reg S-P program for RIAs)
  • Policy set written for your practice, not a 200-page binder
  • Cyber-insurance questionnaire completed and defended
  • Quarterly review meeting with ownership
  • Vendor and Business Associate Agreement review
  • Staff training, twice a year
  • Incident response plan and first-call support

Best for: A single-location practice that needs a named security lead and a defensible program.

Most common

Standard

from $4,500 /month

Everything in Essentials, with monthly cadence and hands-on remediation oversight.

  • Everything in Essentials
  • Monthly working session with your owner or office manager
  • Oversight of your IT provider or MSP on security work
  • Annual penetration test coordination and remediation tracking
  • Audit and OCR or SEC-exam preparation
  • Board- or partner-level reporting

Best for: Multi-provider practices, RIAs with SEC exam exposure, or anyone who has already had a scare.

Embedded

custom

Roughly a day a week. For organizations that need a CISO in the room but not on payroll.

  • Everything in Standard
  • Weekly presence, on-site or remote
  • Security architecture and vendor selection
  • New-location, new-system, or acquisition security reviews

Best for: Groups with 50+ staff, multiple locations, or active regulatory pressure.

A full-time CISO in South Florida costs well over $200,000 a year plus benefits. Most practices need a fraction of that person.

FAQ

vCISO: questions people ask

We are a five-person dental office. Is this overkill?

Essentials is designed for exactly that size. HIPAA does not scale its requirements down for small practices, but the work to meet them does. Most of it is a well-run first quarter and then a light touch.

Do you replace our IT company?

No. I work alongside them. They keep things running; I own the security program and give them a clear, prioritized list. Most IT providers prefer this to being blamed for compliance.

What about the proposed HIPAA Security Rule changes?

HHS proposed significant updates in early 2025 (mandatory MFA, encryption, asset inventories, annual audits). Whatever the final rule looks like, a practice that has a real risk analysis and those controls in place already will not have to scramble. That is the program we build.

Can you handle the SEC side for our RIA?

Yes. The 2024 Reg S-P amendments require an incident response program, service-provider oversight, and 30-day customer notification. That maps closely to the same program, and I include it in the Standard tier.

Get your program started

Talk to Ed

[email protected] · (772) 403-3088