Request a proposal
Managed Security
MDR EssentialsMDR CompleteSMB Security EssentialSMB Full Stack Managed SecurityContinuous Compliance (Delve)Security Compliance SuiteSMB Premium + Compliance
Programs
Grid CommandMulti-Modal Threat IntelligencePhishing + Awareness TrainingTrust Center ManagedCompliance Audit + Remediation Project
Compliance Audits
SOC 2 Type I — Prep + Audit (Thoropass)SOC 2 Type II Audit (Thoropass)ISO 27001 Audit (Thoropass)HIPAA Compliance Audit (Thoropass)Full Compliance Build (HIPAA or SOC2)
Trust Center
Cybersecurity Trust Center BuildTrust Center Care Plan
Company
Managed PlansFree AssessmentAboutBlogContactRequest a proposal

HIPAA Compliance Audit (Thoropass)

Prove HIPAA compliance to covered entities and partners

A HIPAA Security, Privacy and Breach Notification Rule assessment with a third-party attestation report, managed by TenGrid and delivered through Thoropass.

$18,000

Reserve your audit window — $2,500 deposit Book a Scoping Call

The $2,500 engagement deposit reserves your audit window and is credited in full against the $18,000 project price. The balance is invoiced after the scoping call, before fieldwork begins. Deposits are refundable if we determine on the scoping call that we are not a fit.

How this is delivered

TenGrid Security is a white-label partner of Thoropass. TenGrid scopes and manages your engagement and is your single point of contact; the readiness platform, evidence collection and the independent CPA audit are delivered through Thoropass and its licensed audit firm. Your report is issued by the independent auditor, not by TenGrid.

Who this is for

Health-tech vendors, business associates and covered entities that need an independent HIPAA report for hospital, payer or partner due diligence.

What’s included

  • HIPAA scoping: PHI data flows, systems and business associate relationships
  • Security Rule risk analysis and control mapping on the Thoropass platform
  • Policy and procedure set aligned to the Security, Privacy and Breach Notification Rules
  • Gap tracking to closure before the assessment
  • Independent HIPAA assessment and attestation report through Thoropass
  • Report delivered, plus BAA and ongoing risk-analysis guidance

How it works

  1. Scoping call: frameworks, systems in scope, timeline and auditor availability
  2. Readiness: Thoropass platform connected to your stack, gaps and evidence tracked to closure
  3. Audit: independent CPA firm performs fieldwork through Thoropass; TenGrid manages requests and evidence
  4. Report delivered, plus a plan for what comes next

Questions

Timeline?

Typically 8–12 weeks.

Is this a government certification?

No. HHS does not certify HIPAA compliance. This is an independent third-party assessment and attestation, which is what partners and customers request.

Can we add SOC 2?

Yes. A HIPAA + SOC 2 combined program shares most evidence; ask on the scoping call.

Is the assessment fee included?

Yes. The $18,000 covers engagement management, platform access for the engagement period and the independent assessment.

HIPAA Compliance Audit (Thoropass)

$18,000

Reserve your audit window — $2,500 deposit Book a Scoping Call

The $2,500 engagement deposit reserves your audit window and is credited in full against the $18,000 project price. The balance is invoiced after the scoping call, before fieldwork begins. Deposits are refundable if we determine on the scoping call that we are not a fit.