Healthcare compliance, done right and done faster
Sherpa, HIPAA Sherpa's AI compliance guide, reviews your evidence, drafts your findings and remediation, and answers questions about your posture. It guides your team through HIPAA, SOC 2, ISO 27001, the NIST frameworks, and 20+ built-in libraries in all, so assessments stay accurate and audit-ready.
Free 30-day evaluation · One full assessment · No credit card
Everything you need for compliance
From risk assessment to remediation, HIPAA Sherpa pairs structured, healthcare-specific workflows with AI that reviews evidence, drafts findings, and recommends your next action. Assessments move faster, score more accurately, and stay audit-ready.
Sherpa, your AI compliance guide
Sherpa reviews each answer and its evidence against the cited requirement, then passes it or drafts the fix, only clearing what it is highly confident in. Ask plain-language questions about your posture and get your three highest-impact next actions, grounded only in your own data.
Security & Privacy Rule Assessments
Guided workflows cover every HIPAA Security Rule safeguard (administrative, physical, and technical) plus Privacy Rule essentials like PHI handling, your Notice of Privacy Practices, patient rights, and minimum necessary. Automated scoring throughout, with Sherpa reviewing each answer against the cited requirement and flagging what falls short.
Risk Analysis & Scoring
Quantitative scoring by likelihood and impact, with gaps mapped to the regulatory citation they implicate. Sherpa drafts your risk-register entries from an assessment's deficiencies, ready for you to review and accept.
Evidence Collection
Upload, tag, and reuse policies, procedures, and documentation across assessments. Sherpa summarizes each document and suggests which questions it satisfies, so evidence lands where it belongs.
Remediation Planning
Sherpa drafts concrete, prioritized tasks from your findings, which you review and assign with owners, due dates, and status. Your team discusses the work in context with comments and @mentions. Show auditors a complete remediation history in one click.
Ongoing Compliance Operations
Compliance is a program, not a one-time report. Track a live compliance score, business associates and BAAs, security incidents and breach timelines, workforce training, access reviews, your PHI data-flow map, and a calendar of every recurring deadline.
Audit-Ready Reports
Generate complete risk assessment reports in one click, with custom branding and detailed technical findings. Sherpa writes the plain-language executive summary your board and auditors read first.
Multi-Framework Coverage
Map one assessment to 20+ built-in frameworks: HIPAA, SOC 2, ISO 27001/27701/42001, the NIST CSF/Privacy/AI RMF/800-53, HITRUST, HICP 405(d), CIS v8, PCI DSS, FedRAMP, CMMC, ONC Information Blocking, 42 CFR Part 2, and consumer-privacy law. Built-in control libraries and Sherpa's cross-framework mapping let you answer once and satisfy many.
Built by Compliance Experts
Certified healthcare security and privacy practitioners build and maintain HIPAA Sherpa, holding CISSP, CISA, and AI-governance credentials. Every question, citation, and AI judgment reflects real OCR, Security Rule, and Privacy Rule expertise, so your assessment holds up under audit scrutiny.
From kickoff to compliance in days, not months
Set up your organization
Define your locations, ePHI systems, and business associates. HIPAA Sherpa automatically tailors the assessment scope to your environment.
Complete the assessment
Work through guided question sets as a team. Assign sections to the right people across IT, HR, compliance, and operations, and track progress in real time.
Review findings and risks
The platform scores each risk area and cites the exact regulation. Sherpa reviews your answers and evidence against each requirement, flags what falls short with a concrete suggestion, and writes a board-ready executive summary, so review is faster and more consistent.
Remediate and report
Let Sherpa draft your remediation tasks from the findings, then assign owners and track progress. Ask what to tackle next, and export your complete risk assessment report for your board, auditors, or OCR.
Less time on the paperwork, more on the program
Structured workflows, reusable evidence, and grounded AI turn a months-long scramble into a repeatable process.
Frameworks in one assessment
HIPAA, SOC 2, ISO 27001/27701/42001, NIST CSF/Privacy/AI RMF/800-53, HITRUST, HICP 405(d), CIS v8, PCI DSS, FedRAMP, CMMC, ONC Information Blocking, 42 CFR Part 2, and consumer-privacy law, with answers reused across them. All 20+ on Professional and above; Starter includes one, with more as add-ons.
To a defensible assessment
Guided questions, built-in control libraries, and team assignment compress the first formal assessment from a quarter to a few weeks. The comparison reflects a typical manual or consultant-led engagement, not a measured benchmark.
Data retained by the AI
Sherpa runs under a BAA with our model provider on a zero-retention basis, so your content is not stored by the model or used to train it, and Sherpa never applies anything without a human review.
A structured platform, not another spreadsheet
The difference between answers in a file and an assessment that holds up to an audit.
Fits the stack you already run
Connect identity, alerting, and your own tooling. Standards-based, so there's nothing proprietary to lock into.
Simple, transparent pricing
No per-seat fees that punish collaboration. Pay for what your organization needs.
Starter
Perfect for small practices and clinics. Also available at $99/month on an annual commitment.
- ✓ 1 organization, up to 5 users
- ✓ 1 physical location and 1 ePHI system, with more available as add-ons
- ✓ 1 framework (HIPAA recommended), with more available as add-ons
- ✓ Security Rule and Privacy Rule assessments
- ✓ Sherpa AI compliance guide, included
- ✓ Employee HIPAA training + quarterly security reminders, included
- ✓ Evidence library and gap-analysis reports
- ✓ Signed BAA included
- ✓ Email support
Professional
For larger practices and compliance-focused organizations. Also available at $299/month on an annual commitment.
- ✓ Includes everything in Starter, plus:
- ✓ Unlimited users, with no per-seat fees
- ✓ All frameworks: HIPAA, SOC 2, ISO, NIST
- ✓ Advanced risk scoring and analytics
- ✓ BAA tracking and branded reports
- ✓ Priority support and guided review
Enterprise
For consultants and large health systems
- ✓ Includes everything in Professional, plus:
- ✓ Multi-tenant client management
- ✓ API access (REST + MCP)
- ✓ Custom integrations (EHR, GRC tools)
- ✓ Dedicated success manager
- ✓ SLA guarantees
Every plan starts with a free 30-day evaluation (one full assessment, no credit card). Paid plans include a signed Business Associate Agreement (BAA) and employee HIPAA training with quarterly security reminders.
Expert help when you want hands-on guidance
Beyond the platform, our certified security, privacy, and compliance team takes on hands-on engagements, scoped and priced to your needs.
Professional Services
Led by our certified security, privacy, and compliance team.
- ✓ Guided Security Assessments
- ✓ M&A due diligence
- ✓ SOC 2 preparation
- ✓ OCR investigation response
- ✓ Breach mitigation
- ✓ Cloud security reviews
- ✓ IAM access reviews
- ✓ Penetration testing
- ✓ Documentation creation
- ✓ On-site physical security assessments
- ✓ Incident investigation
Questions, answered
How is this different from doing our risk assessment in a spreadsheet? +
A spreadsheet captures answers but not the structure auditors expect: regulatory citations, threat-and-vulnerability scoring, evidence linkage, a tracked remediation plan, and an audit trail of who changed what and when. HIPAA Sherpa builds all of that as you work, so the output is a defensible assessment, not a static file that goes stale the moment you close it.
How long does a risk assessment take? +
Most teams complete a first formal Security Rule assessment in days rather than weeks. Guided questions, built-in control libraries, and cross-framework mapping mean you answer once and reuse it everywhere, and you can assign sections across your team and track progress as you go.
Do we need to sign a BAA? +
Yes. It is included with every plan, and the platform enforces it: evidence uploads and assessment answers stay blocked until you sign and we countersign. Sign ours in the app, route it to your own signatory, or upload your own paper for us to countersign, as soon as your account is active.
Will our data be safe? +
Tenants are isolated with organization-scoped, row-level access controls; data is encrypted with AES-256 at rest and TLS 1.3 in transit; sessions are server-side and revocable; and every action is written to a tamper-evident, six-year audit log. AI runs under a BAA with our model provider on a zero-retention basis: most features send only aggregate counts and labels, and the features that read your uploaded evidence, which may contain PHI, send it to that BAA-covered, zero-retention model, which is instructed never to reproduce it. See the security page for the full posture.
What happens after the free trial? +
The 30-day evaluation needs no credit card and includes one full assessment. If you continue, pick the plan that fits. If you do not, your workspace drops to the free tier rather than closing: you keep signing in and reading everything you have already recorded. Thirty days after signup the workspace becomes read-only, so your records stay legible for as long as you need them. Billing stays open the whole time, so you can pick a plan whenever you are ready, and we will provide a full export of your data on request in standard formats.
More on plans and data handling in our pricing FAQ and security overview.