The Program

What Clinical Risk Monitor delivers

A managed program, not a software license. Each engagement is a recurring cycle of assessment, monitoring, maintenance, and expert-signed reporting — the standing risk function your organization needs, delivered as a partnership rather than a hire.

Clinical Risk Monitor in one paragraph

Clinical Risk Monitor in one paragraph. It is a recurring partner engagement from Austin-Zierke Clinical Risk Partners for pregnancy help organizations and healthcare nonprofits: security risk assessment, ongoing vulnerability and compliance monitoring, HIPAA-aligned policy and claims-language work, AI governance, accreditation readiness support, and board-ready reporting. Every formal cycle ends with a cover letter signed by a named compliance expert. Foundation pricing starts at about $249 per month by organization revenue; full tables are published below. The list price is the nonprofit price.

What your organization receives

  • Security risk assessments. Know exactly where your safeguards stand, so risks are found and addressed before they become incidents.
  • Cybersecurity vulnerability monitoring. Ongoing scanning of your systems catches weaknesses early, closing the gaps attackers look for first.
  • Third-party vendor reviews. Confidence that the software and service providers who touch your clients’ data are held to the same standard you are.
  • Agreement and BAA reviews. Your vendor agreements and, where applicable, business associate agreements stay current, complete, and enforceable — one of the most commonly missed obligations.
  • Public claims-language review. We audit your website and intake forms against your actual practices and true regulatory status, and give you language you can safely publish — the gap state regulators are actively pursuing.
  • Security awareness and phishing training. Your staff and volunteers become your strongest defense against the most common cause of healthcare breaches. (Foundation Plus and Executive.)
  • AI governance guidance. Adopt new tools with clear guardrails, so innovation never comes at the expense of client privacy.
  • An inventory of the AI already in use. A written list of the tools your organization relies on, including the features built into software you already own — which is where most organizations find theirs.
  • Device and media control review. Where client information is created, stored, copied, backed up, and eventually disposed of — including storage attached to clinical equipment, which routinely sits outside the IT inventory.
  • Policy maintenance. Your privacy and security policies stay aligned with current regulations and your actual practices — no more outdated binders on a shelf.
  • Incident response planning. If something ever goes wrong, your team knows exactly what to do in the first critical hours.
  • Executive compliance reporting. Clear, board-ready reports give your leadership visibility without technical translation.
  • Annual documentation review. A complete, organized compliance record — ready for insurers, auditors, or accreditation surveyors.
  • Coordination with your existing IT provider. We work alongside the people who already support you, adding compliance expertise without disruption.

Every formal deliverable carries a name

Each reporting cycle ends with a plain-language cover letter reviewed, edited, and signed by a named compliance expert — name, title, firm, and date, with the scope and limitations of the review stated explicitly. The letter summarizes your posture, the findings that matter, and who owns what next. It is written to be handed directly to your board, your insurer, or your surveyor.

This is the line we do not cross in either direction: our AI accelerates analysis but never signs, and no report leaves this firm without expert review. Human attestation and expert support — automation never replaces accountability.

Three Ways to Engage

Every clinic starts from the same base price, set by organizational revenue, then selects the level of ongoing oversight that matches its risk and staffing. Signed expert attestation is included at every level.

Foundation

Base price · $249–$749/mo by annual revenue

The base program. Every engagement includes:


  • Annual Security Risk Assessment
  • Annual HIPAA documentation review
  • Policy maintenance
  • Vendor and Business Associate Agreement tracking
  • Annual staff training
  • Quarterly compliance review
  • Annual incident-response tabletop exercise
  • Annual executive report
  • AAAHC alignment
  • Ongoing compliance question support

Executive

Base price + $250/mo

Everything in Foundation Plus, plus executive-level attention:


  • Monthly executive compliance report
  • Quarterly executive compliance call
  • Board-ready reporting
  • Priority response to HIPAA and cybersecurity questions
  • Cybersecurity insurance application review
  • AI system risk reviews
  • Two hours of consulting support per quarter

Core monthly investment by organization size

Core monthly investment by annual revenue
Annual revenueFoundationFoundation Plus (Recommended)Executive
Under $300,000$249$349$499
$300,000 to $599,999$329$429$579
$600,000 to $999,999$449$549$699
$1 million to $1.49 million$549$649$799
$1.5 million to $1.99 million$649$749$899
$2 million to $2.49 million$749$849$999

An annual contract, paid as ten monthly payments, gives your organization two months free for committing to a twelve-month term. A month-to-month arrangement is available at the listed monthly rate with a three-month minimum, though it does not include a waived onboarding fee.

Staffing and additional users

Revenue alone does not capture workload — a smaller clinic with a large part-time or volunteer workforce can generate more training, access-control, and documentation work than a larger clinic with a lean staff. Each revenue tier includes a paid workforce allowance.

Included workforce allowance and additional user pricing by revenue tier
Revenue tierIncluded paid workforceAdditional users
Under $300,000Up to 8 people$6 per person per month, $30 monthly minimum
Under $600,000Up to 10 people$6 per person per month, $30 monthly minimum
Under $1 millionUp to 20 people$6 per person per month, $30 monthly minimum
$1 million to $1.49 millionUp to 25 people$6 per person per month, $30 monthly minimum
Each additional $500,000Adds approximately 10 people$6 per person per month, $30 monthly minimum

Volunteers with no system or protected health information access are not charged. Regular volunteers with access to email, the EHR, scheduling, or the network count as users.

Additional locations

A second physical location, mobile medical unit, or satellite site adds physical safeguard reviews, device inventories, and additional workforce access questions, and is priced accordingly.

Monthly add-on pricing by additional location type
Additional location typeMonthly add-on
Administrative office, no patient services or stored PHI$50
Limited-service satellite, one or two days weekly$100
Full-time patient service location or mobile medical unit$150
Location with a separate IT network, EHR instance, or IT vendor$200

Onboarding

The initial Security Risk Assessment and implementation work is priced separately from the monthly fee. It involves documentation collection, a technology and vendor inventory, a policy gap review, an initial corrective action plan, leadership orientation, and setup of the compliance tracking system.

One-time onboarding fee by organization size
Organization sizeOnboarding fee
Under $300,000$500
$300,000 to $599,999$750
$600,000 to $999,999$1,000
$1 million to $1.99 million$1,500
$2 million and aboveStarting at $2,000

Onboarding is due in full for month-to-month arrangements, reduced by half for an annual contract paid monthly, and waived entirely when the full annual amount is prepaid. Where prior accreditation gap-analysis and implementation work has already covered much of the required assessment, onboarding is waived.

One-time professional services

The following fall outside the monthly subscription and are billed only when needed.

One-time professional services and fees
ServiceFee
Policy customization beyond annual maintenance$175 per hour
Live HIPAA or cybersecurity training$750 virtual; $1,500 onsite plus travel
Additional tabletop exercise$750 virtual; $1,500 onsite plus travel
Cybersecurity insurance application assistance$500 to $1,000

Affiliate network pricing

Networks of affiliated organizations qualify for volume pricing rather than a flat individual discount. Each affiliate signs its own agreement and remains responsible for implementing its own corrective actions, while the network benefits from shared templates, standardized reporting, and network-wide discounting. Custom state-specific work may carry additional fees beyond the discounted base rate.

Network discount by number of participating affiliates
Participating affiliatesNetwork discount
5 to 9 organizations5%
10 to 24 organizations10%
25 to 49 organizations12.5%
50 or more organizationsNegotiated, up to 15%

Every engagement includes our written portability commitment: your organization owns all reports, policies, findings, and evidence we produce, with export in standard formats and orderly offboarding support on request.

Pursuing accreditation?

The program is designed to complement AAAHC standards, helping accredited and accreditation-minded organizations demonstrate the continuous risk management, documentation, and quality oversight that surveyors expect — month after month, not just at survey time. If a survey is on your calendar, say so in your consultation request; readiness timelines shape how we scope the engagement.