Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

System · Risk Intelligence

An assessment tells you what is true. This tells you what it means.

Likelihood against impact, item by item, so a 331-question assessment comes back as a ranked list rather than a document.

Included in Basic·Starting at $39/mo

HIPAA mapping

Where this fits in the Security Rule.

4 provisions this capability contributes to, each with the specific Risk Intelligence behavior behind it. The obligation stays with your practice — the mapping shows which part of the work the platform carries.

§164.308(a)(1)(ii)(A)

Risk analysis

The risk analysis is your practice's act, and the Security Risk Assessment is where it is conducted and retained. Risk Intelligence reads what that assessment produced. It is the interpretation layer, not the analysis itself, and it cannot stand in for an assessment you have not completed.

§164.308(a)(1)(ii)(B)

Risk management

Requires security measures sufficient to reduce risk to a reasonable and appropriate level. Reasonable and appropriate is a judgement about which risks matter most, and a ranked list of findings by likelihood and impact is the input that judgement needs.

§164.308(a)(7)(ii)(E)

Applications and data criticality analysis

An addressable specification asking which applications and data are critical. High-impact items are separated from the rest here, which is the same question asked from the risk side.

§164.316(b)(1)

Documentation

The assessment and its interpretation are retained in the platform rather than in a spreadsheet on one person's laptop. The written policies and procedures the standard also requires remain your practice's to author.

What it does

The assessment is the hard part. The list is the useful part.

A practice finishes a security risk assessment and is left holding several hundred answers. Some describe controls that are in place. Some describe gaps. A few describe gaps that would end the practice. Nothing in the document itself tells you which is which, and the honest response of most owners — put it in a drawer and feel vaguely worse — is a rational response to an unranked list.

Risk Intelligence is the layer that reads the assessment back. Each item carries a likelihood and an impact, and the pairing produces a risk level rather than a yes or no: low, medium, high. The high-impact findings are pulled out separately, because a low-likelihood item that would expose every record in the practice is not the same kind of problem as a high-likelihood item that would expose a fax cover sheet, and a single ordered list flattens that difference.

It is worth being plain about where the picture comes from: today it is derived from the assessment. It moves when the assessment moves — when you answer an item, revise an answer, or close a finding. It is not a monitor watching your network, and it does not silently absorb every change elsewhere in the platform. What it does is turn work you have already done into an order of operations.

How it works

5 mechanisms keep Risk Intelligence working.

01

Likelihood against impact, not a single number.

Each assessment item is scored on how likely the exposure is and how bad it would be, and the two together place it on the matrix. This is the method NIST SP 800-30 describes and the one an OCR investigator recognises, which matters because the alternative — a single opaque percentage — cannot be defended when someone asks how you decided what to fix first.

02

Item-level risk, so the ranking is inspectable.

Risk is carried at the level of the individual assessment item, not only in a total. You can open any finding and see the two judgements behind its level rather than being handed a number to trust. A ranking nobody can take apart is a ranking nobody can argue with, which sounds like a strength until an auditor disagrees with it.

03

High-impact findings, separated.

Items whose impact is severe are surfaced apart from the general list, regardless of how likely they are. Practices with limited time work this list first. It is the difference between working through findings in the order the questionnaire happened to ask them and working through them in the order that reduces exposure.

04

Findings that carry through to work.

A finding is not a dead end. Compliance Advice items reference the specific assessment item behind them — the identifier is visible on the item — and carry their own severity, so the ranking here and the queue you actually work are looking at the same thing. Interpretation that does not connect to work is just a second document.

05

Category coverage, so gaps in the assessment are visible.

An assessment that is 40 percent answered produces an interpretation that is 40 percent informed, and the honest way to present that is to show which areas have been covered and which have not. Unanswered sections read as unknown rather than quietly counting as fine, which is the failure mode that makes self-assessment scores worthless.

Who this is for

Built for the practices that need it most.

Practices holding a finished assessment and no plan.

The assessment is the deliverable most consultants leave behind, and it is the point at which most practices stop. If you already have several hundred answers and no idea which twelve of them matter, the interpretation is the missing half of the work.

Practices with more findings than hours.

Nobody closes everything. An independent practice has a few hours a month for compliance, and the entire question is whether those hours go to the findings that reduce real exposure. Ranking is not a nicety here; it is the whole intervention.

Practices who have to explain a decision.

When an investigator asks why one gap was addressed in March and another is still open, “these were ranked higher by likelihood and impact” is an answer. “We got to them in order” is not.

What you get

5 outcomes you’ll feel in week one.

A ranked list, not a document.

Several hundred answers come back in an order you can act on.

Likelihood and impact kept apart.

The two judgements stay visible instead of collapsing into one number.

High-impact findings surfaced.

Severity is separated from probability, because they are different problems.

Item-level, so it is inspectable.

Open any finding and see what produced its level.

Unanswered reads as unknown.

Coverage is shown, so a thin assessment cannot look like a clean one.

FAQ

What people ask first.

6 questions cover most first-time evaluations. See all FAQs →

What does Risk Intelligence actually read?
Your Security Risk Assessment. That is the honest answer and it is worth stating rather than implying more: the interpretation is assessment-derived. It moves when the assessment moves. It is not watching your network, your devices or your vendors independently, and any product claiming to do that from outside your premises is describing something it cannot see.
How is this different from the Patient Protect Score?
They answer different questions. Risk Intelligence asks how exposed you are and which findings matter most — an interpretation of risk. The Patient Protect Score asks where the practice stands overall, as one composite of Setup, Compliance and Security. A practice can have a respectable Score and still be carrying one severe finding, which is exactly why both exist.
Is this the risk analysis HIPAA requires?
No, and it is important not to blur that. §164.308(a)(1)(ii)(A) requires your practice to conduct an accurate and thorough assessment of risks to ePHI. The Security Risk Assessment is where that work is structured, performed and retained. Risk Intelligence interprets what it produced. Completing the assessment is the act the regulation is asking for; nothing here does it for you.
What if my assessment is only partly finished?
The interpretation reflects what has been answered, and the areas that have not been covered are shown as uncovered rather than folded into a flattering total. A partial assessment produces a partial picture, and a product that hides that from you is not doing you a favor.
Can I change how items are weighted?
The likelihood-and-impact method is fixed, deliberately. A methodology a practice can adjust is a methodology a practice can adjust until the number looks acceptable, and the resulting ranking would not survive the first question about how it was produced.
How often does the picture change?
When the assessment changes. Answering an item, revising an answer or closing a finding changes what the interpretation has to work with. There is no separate schedule to remember and no report to run, and equally there is no claim that it reacts to unrelated activity elsewhere in the platform.

What it does not do.

  • A different job from the Patient Protect Score: this interprets risk, the score reports standing
  • No claim that it ingests every possible live state change

Several hundred answers, in the order that reduces exposure.

The assessment is the work. The ranking is what makes the work survivable for a practice with a few hours a month.