A named person who owns the answer.
At 15 to 250 users there is no CISO and there is no budget for one. What there is, usually, is a practice administrator or a nurse who has been handed the HIPAA Security Officer title on top of an existing job. The vCISO engagement gives that person a counterpart: a named security officer at Chartline who owns the program, meets monthly, and writes the report that goes to the board.
Included in: Included in Chartline Compliant. Standalone retainer $3,500 – $9,500 per month.
Six things, described plainly.
No capability matrix and no maturity model. This is what we do, why it matters in a clinical environment, and where the number comes from.
A named individual, not a function
You get a person with a phone number, credentials, and a working knowledge of your estate. Not a shared inbox.
A monthly working session
Open findings, remediation status, upcoming obligations, and decisions that need a human with authority. Ninety minutes, with an agenda sent in advance.
A quarterly report written for a board
Physician-owner boards are slow, consensus-driven, and meet monthly. The report is built so your champion can forward one document rather than explain a program.
Framework mapping when somebody asks
HICP Technical Volume 1, NIST CSF, NIST SP 800-66 Rev. 2, HITRUST e1 readiness, SOC 2 readiness, PCI DSS 4.0.1 SAQ support. Mapping is a rendering of the same underlying evidence, not a second program.
Cyber insurance application support
We complete the technical sections with you and attest only to what we can evidence. In Travelers v. International Control Services a court permitted rescission of a cyber policy because an executive attested to MFA on privileged access that was not actually in place.
Escalation authority during an incident
The vCISO runs the response, coordinates counsel and the carrier, and owns the 60-day notification clock. Untimely notification is a separately penalized, stackable violation.
Which tier includes this.
Our rates are published. If a service you need is only in a higher tier, this page says so rather than making you find out in a proposal.
The rest of what we run.
Managed IT and help desk
The day-to-day. Tickets answered by a named pod, not a rotating queue.
Cybersecurity and 24/7 detection and response
24/7 monitored detection with contractual authority to contain, not just to alert.
HIPAA compliance program
The risk analysis, the risk management plan, and the evidence file. The flagship.