Notifications
You're all caught up.
AI-powered HIPAA risk & compliance for healthcare

Healthcare compliance, done right and done faster

Sherpa, HIPAA Sherpa's AI compliance guide, reviews your evidence, drafts your findings and remediation, and answers questions about your posture. It guides your team through HIPAA, SOC 2, ISO 27001, the NIST frameworks, and 20+ built-in libraries in all, so assessments stay accurate and audit-ready.

Free 30-day evaluation  ·  One full assessment  ·  No credit card

HIPAA
SOC 2
ISO 27001
ISO 27701
ISO 42001
NIST CSF
NIST 800-53
NIST AI RMF
NIST Privacy
HITRUST CSF
HICP 405(d)
CIS v8
PCI DSS
FedRAMP
CMMC 2.0
ONC Info Blocking
42 CFR Part 2
GDPR
CCPA/CPRA
State Privacy Laws
SOC 2 Privacy

Everything you need for compliance

From risk assessment to remediation, HIPAA Sherpa pairs structured, healthcare-specific workflows with AI that reviews evidence, drafts findings, and recommends your next action. Assessments move faster, score more accurately, and stay audit-ready.

Sherpa, your AI compliance guide

Sherpa reviews each answer and its evidence against the cited requirement, then passes it or drafts the fix, only clearing what it is highly confident in. Ask plain-language questions about your posture and get your three highest-impact next actions, grounded only in your own data.

Security & Privacy Rule Assessments

Guided workflows cover every HIPAA Security Rule safeguard (administrative, physical, and technical) plus Privacy Rule essentials like PHI handling, your Notice of Privacy Practices, patient rights, and minimum necessary. Automated scoring throughout, with Sherpa reviewing each answer against the cited requirement and flagging what falls short.

Risk Analysis & Scoring

Quantitative scoring by likelihood and impact, with gaps mapped to the regulatory citation they implicate. Sherpa drafts your risk-register entries from an assessment's deficiencies, ready for you to review and accept.

Evidence Collection

Upload, tag, and reuse policies, procedures, and documentation across assessments. Sherpa summarizes each document and suggests which questions it satisfies, so evidence lands where it belongs.

Remediation Planning

Sherpa drafts concrete, prioritized tasks from your findings, which you review and assign with owners, due dates, and status. Your team discusses the work in context with comments and @mentions. Show auditors a complete remediation history in one click.

Ongoing Compliance Operations

Compliance is a program, not a one-time report. Track a live compliance score, business associates and BAAs, security incidents and breach timelines, workforce training, access reviews, your PHI data-flow map, and a calendar of every recurring deadline.

Audit-Ready Reports

Generate complete risk assessment reports in one click, with custom branding and detailed technical findings. Sherpa writes the plain-language executive summary your board and auditors read first.

Multi-Framework Coverage

Map one assessment to 20+ built-in frameworks: HIPAA, SOC 2, ISO 27001/27701/42001, the NIST CSF/Privacy/AI RMF/800-53, HITRUST, HICP 405(d), CIS v8, PCI DSS, FedRAMP, CMMC, ONC Information Blocking, 42 CFR Part 2, and consumer-privacy law. Built-in control libraries and Sherpa's cross-framework mapping let you answer once and satisfy many.

Built by Compliance Experts

Certified healthcare security and privacy practitioners build and maintain HIPAA Sherpa, holding CISSP, CISA, and AI-governance credentials. Every question, citation, and AI judgment reflects real OCR, Security Rule, and Privacy Rule expertise, so your assessment holds up under audit scrutiny.

From kickoff to compliance in days, not months

01

Set up your organization

Define your locations, ePHI systems, and business associates. HIPAA Sherpa automatically tailors the assessment scope to your environment.

02

Complete the assessment

Work through guided question sets as a team. Assign sections to the right people across IT, HR, compliance, and operations, and track progress in real time.

03

Review findings and risks

The platform scores each risk area and cites the exact regulation. Sherpa reviews your answers and evidence against each requirement, flags what falls short with a concrete suggestion, and writes a board-ready executive summary, so review is faster and more consistent.

04

Remediate and report

Let Sherpa draft your remediation tasks from the findings, then assign owners and track progress. Ask what to tackle next, and export your complete risk assessment report for your board, auditors, or OCR.

Less time on the paperwork, more on the program

Structured workflows, reusable evidence, and grounded AI turn a months-long scramble into a repeatable process.

20+

Frameworks in one assessment

HIPAA, SOC 2, ISO 27001/27701/42001, NIST CSF/Privacy/AI RMF/800-53, HITRUST, HICP 405(d), CIS v8, PCI DSS, FedRAMP, CMMC, ONC Information Blocking, 42 CFR Part 2, and consumer-privacy law, with answers reused across them. All 20+ on Professional and above; Starter includes one, with more as add-ons.

Days, not months

To a defensible assessment

Guided questions, built-in control libraries, and team assignment compress the first formal assessment from a quarter to a few weeks. The comparison reflects a typical manual or consultant-led engagement, not a measured benchmark.

0

Data retained by the AI

Sherpa runs under a BAA with our model provider on a zero-retention basis, so your content is not stored by the model or used to train it, and Sherpa never applies anything without a human review.

A structured platform, not another spreadsheet

The difference between answers in a file and an assessment that holds up to an audit.

Regulatory citations on every question
Quantitative risk scoring and a 5×5 matrix
Evidence linked to the control it supports
Findings tracked through to remediation
Cross-framework reuse across 20+ standards (HIPAA, SOC 2, ISO, NIST, HITRUST, PCI, FedRAMP, CMMC, ONC…)
A live compliance score, snapshotted daily
Vendor & BAA tracking, incidents, training, and access reviews in one place
Tamper-evident audit trail of every change
AI review of answers and evidence, with a human in the loop
One-click auditor packet

Fits the stack you already run

Connect identity, alerting, and your own tooling. Standards-based, so there's nothing proprietary to lock into.

SAML 2.0 SSO Single sign-on with your identity provider
OAuth Sign in with Google or Microsoft
SCIM provisioning Automated user provisioning and deprovisioning
Webhooks Subscribe to events with signed, retried delivery
Slack Compliance notifications in your channels
SIEM export Stream the audit log to your SIEM
REST API A versioned API for findings, assessments, and more
Custom integrations Build on the API and webhook catalog

Simple, transparent pricing

No per-seat fees that punish collaboration. Pay for what your organization needs.

Starter

$999/year

Perfect for small practices and clinics. Also available at $99/month on an annual commitment.

  • ✓ 1 organization, up to 5 users
  • ✓ 1 physical location and 1 ePHI system, with more available as add-ons
  • ✓ 1 framework (HIPAA recommended), with more available as add-ons
  • ✓ Security Rule and Privacy Rule assessments
  • ✓ Sherpa AI compliance guide, included
  • ✓ Employee HIPAA training + quarterly security reminders, included
  • ✓ Evidence library and gap-analysis reports
  • ✓ Signed BAA included
  • ✓ Email support
Start free trial

Enterprise

Custom

For consultants and large health systems

  • Includes everything in Professional, plus:
  • ✓ Multi-tenant client management
  • ✓ API access (REST + MCP)
  • ✓ Custom integrations (EHR, GRC tools)
  • ✓ Dedicated success manager
  • ✓ SLA guarantees
Contact sales

Every plan starts with a free 30-day evaluation (one full assessment, no credit card). Paid plans include a signed Business Associate Agreement (BAA) and employee HIPAA training with quarterly security reminders.

Expert help when you want hands-on guidance

Beyond the platform, our certified security, privacy, and compliance team takes on hands-on engagements, scoped and priced to your needs.

Professional Services

Custom

Led by our certified security, privacy, and compliance team.

  • ✓ Guided Security Assessments
  • ✓ M&A due diligence
  • ✓ SOC 2 preparation
  • ✓ OCR investigation response
  • ✓ Breach mitigation
  • ✓ Cloud security reviews
  • ✓ IAM access reviews
  • ✓ Penetration testing
  • ✓ Documentation creation
  • ✓ On-site physical security assessments
  • ✓ Incident investigation
Contact sales

Questions, answered

How is this different from doing our risk assessment in a spreadsheet? +

A spreadsheet captures answers but not the structure auditors expect: regulatory citations, threat-and-vulnerability scoring, evidence linkage, a tracked remediation plan, and an audit trail of who changed what and when. HIPAA Sherpa builds all of that as you work, so the output is a defensible assessment, not a static file that goes stale the moment you close it.

How long does a risk assessment take? +

Most teams complete a first formal Security Rule assessment in days rather than weeks. Guided questions, built-in control libraries, and cross-framework mapping mean you answer once and reuse it everywhere, and you can assign sections across your team and track progress as you go.

Do we need to sign a BAA? +

Yes. It is included with every plan, and the platform enforces it: evidence uploads and assessment answers stay blocked until you sign and we countersign. Sign ours in the app, route it to your own signatory, or upload your own paper for us to countersign, as soon as your account is active.

Will our data be safe? +

Tenants are isolated with organization-scoped, row-level access controls; data is encrypted with AES-256 at rest and TLS 1.3 in transit; sessions are server-side and revocable; and every action is written to a tamper-evident, six-year audit log. AI runs under a BAA with our model provider on a zero-retention basis: most features send only aggregate counts and labels, and the features that read your uploaded evidence, which may contain PHI, send it to that BAA-covered, zero-retention model, which is instructed never to reproduce it. See the security page for the full posture.

What happens after the free trial? +

The 30-day evaluation needs no credit card and includes one full assessment. If you continue, pick the plan that fits. If you do not, your workspace drops to the free tier rather than closing: you keep signing in and reading everything you have already recorded. Thirty days after signup the workspace becomes read-only, so your records stay legible for as long as you need them. Billing stays open the whole time, so you can pick a plan whenever you are ready, and we will provide a full export of your data on request in standard formats.

More on plans and data handling in our pricing FAQ and security overview.

Ready to get compliant?

Join hundreds of healthcare organizations that rely on HIPAA Sherpa.