Save staff time and know your next HIPAA Security Risk Assessment is Audit Grade.

Not all SRA’s are equal.  They must cover Administrative, Physical and Technical controls. They must be comprehensive enough to stand OCR Audit scrutiny. It helps if they are conducted by certified information security experts with over 10 years of HIPAA SRA experience.

HIPAA SRA scoring that is easy to understand

HIPAA Security Risk Analysis

A HIPAA security risk analysis (SRA) is the best way to understand your organization’s risk of ePHI loss or unintentional disclosure. A HIPAA SRA is a comprehensive process of analyzing controls to ensure they are sufficient to ward off threats that exist in the world today. DueNorth's risk assessment process is effecient and results are easy to communicate with board members, staff, and auditors. DueNorth helps with remediation efforts and can provide updated reports after risks are mitigated.

Call Us

Let Us Know How We Can Help

Get More Information Today

"*" indicates required fields

Name*

Certified Experts

All Assessments are conducted by DueNorth Security staff members who hold at least one of the following certifications:

How can a security risk assessment improve our bottom line ?

Ransomware, malware, or a breach can cost tens of thousands of dollars and weeks of staff time for data recovery and reproduction. Not to mention fines if your firm is found in violation of any regulatory requirements. A third party assessment proves you are taking responsible steps towards information security.

How long does a risk assessment take?

The basic assessment can be completed in 2 weeks while a security program assessment can take up to 8 weeks.

What are the end deliverables?

All assessments include: Risk Score, Risk Action Plan, Full Security Risk Assessment Report, Executive Summary with recommendations and all supporting documents and findings. DueNorth can also help with your remediation efforts.

Other Assessment Options:

Network Vulnerability Tests
Penetration Testing
Social Engineering
Computer Access Test
Security Control Assessment
And Much More…

Information and security are critical in a health care environment and DueNorth builds and maintains a network to keep our patient records secure and available.

Zach Cook

Clinical Informatics Coordinator, McKenzie County Healthcare Systems

DueNorth Security has surpassed expectations. They have effectively worked with us to resolve IT security and HIPAA risks in a timely manner. We can count on their team to help problem solve and guide us with best practices to meet all federal, state, and local requirements.

Marianne Snell

Director of Human Resources, St. Luke’s Medical Center

When we were ready to launch our telehealth platform for eye care professionals we knew that our network security had to be ironclad. DueNorth helped us get there. As a result we received a very positive S2Score and continue to improve our score through continuous testing.

Bill Lard

Vice President, Compliance and Regulatory Affairs, EyecareLive, Inc

Awesome Clients

OCR Releases Version 3.6 of the HIPAA SRA Tool

OCR Releases Version 3.6 of the HIPAA SRA Tool

In September 2025, the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR), together with the Assistant Secretary for Technology Policy (ASTP), released version 3.6 of the Security Risk Assessment (SRA) Tool. This tool is designed to help...

Avoid a Fine, Align with a Recognized Security Practice

Avoid a Fine, Align with a Recognized Security Practice

On January 5, 2021, the HIPAA Safe Harbor Law was enacted as Public Law 116-321. This law requires the U.S. Department of Health and Human Services (HHS) and OCR to consider whether a covered entity or business associate has “recognized security practices” in place...

Patching is not Vulnerability Management

Patching is not Vulnerability Management

While often used interchangeably, vulnerability management and patching are distinct, yet complementary, processes. Understanding their differences is crucial for a well-rounded security strategy. What Is Vulnerability Management? Vulnerability management is a...