Your HIPAA risk analysis, done and kept current.

Every dental practice is required to complete a Security Risk Analysis and keep written policies. ChairGuard does the whole thing for you, then keeps it current every quarter, so you are never scrambling when an auditor, an insurer, or an attorney asks.

Built by a Georgia IT and security team that has supported dental practices since 2015. Vendor neutral, so we work alongside whoever handles your IT.

Most practices think they are covered. Then they read the request letter.

The Security Risk Analysis is not a firewall or an antivirus subscription. It is a written, dated assessment with evidence behind it, and it has to be updated as your practice changes. Three things usually go wrong:

The SRA is old or missing

A checklist somebody filled out years ago, or one that came free with a software purchase. Neither survives a real review.

Policies exist but nobody follows them

A binder from a template pack, with no training log, no device inventory, and no signed BAAs to back it up.

Nobody owns it

The IT vendor assumes the office manager has it. The office manager assumes the IT vendor does. It sits untouched until something forces the issue.

What you actually receive

Real documents your team can hand to anyone who asks, not a portal login you will forget.

Security Risk Analysis report covering administrative, physical, and technical safeguards, with findings ranked by risk.
Written policy set tailored to your practice, not generic boilerplate.
Device and asset inventory of every workstation, server, imaging PC, and mobile device that touches patient data.
Business Associate Agreement tracker so you know which vendors are covered and which are not.
Workforce training log with dated attestations for every team member.
Breach response playbook with the exact steps and notification clocks if something happens.
Remediation plan with plain-English priorities and what each item costs to fix.
One page audit binder that summarizes your whole program on a single sheet.

How it works

1

Intake, 20 minutes

One call or an online questionnaire with your office manager. We ask business questions, not technical ones.

2

Evidence and analysis

We collect the technical evidence remotely, with your IT provider looped in. No disruption to patient hours.

3

Delivery in 10 business days

You get the full document set plus a walkthrough of the findings and what to fix first.

4

Quarterly refresh

We update the inventory, the training log, and the evidence each quarter so the program never goes stale.

5

Annual re-analysis

A fresh SRA every year, which is the cadence regulators expect.

6

If you get a request letter

We assemble the response package with you. That is the day this pays for itself.

Straightforward pricing

Single location practices. Multi location and DSO pricing on request.

Getting current
$1,450
one time, per location
  • Full Security Risk Analysis
  • Written policy set
  • Device and asset inventory
  • BAA tracker and training log
  • Remediation plan and findings walkthrough
Staying current
$189/mo
12 month term, starts after delivery
  • Quarterly evidence refresh
  • Policy updates as rules change
  • Annual re-analysis included
  • Breach playbook kept current
  • Support if you receive an audit or insurer request

ChairGuard performs and documents your risk analysis and compliance program. We are not a law firm and we do not issue certifications. No consultant can make a practice "HIPAA certified," and you should be careful with anyone who says otherwise.

Start with the free 10 point gap check

Ten questions, about five minutes of your time, and we send back a written snapshot of where your practice stands and what is most likely to bite you. No cost, no obligation, and no sales call unless you ask for one.

Prefer to talk? Email hello@chairguardcompliance.com.

Questions we get

Do we have to switch IT providers?

No. ChairGuard is vendor neutral and we work alongside your current IT provider. We give them a clear list of anything technical that needs fixing.

Is a risk analysis really required?

Yes. The HIPAA Security Rule requires a documented, current risk analysis for every covered entity, including single dentist practices. It is also the first item requested in most investigations and in many cyber insurance applications.

Our practice management vendor said we are covered.

Software vendors secure their software. The rule applies to your whole practice: workstations, imaging machines, phones, email, staff behavior, vendors, and physical access. That is what we assess.

How much of our staff time does this take?

About 45 minutes total for your office manager, spread across the intake and one follow up. Everything else is on us.

What if the analysis finds serious problems?

Good. That is the point, and finding them yourself is far better than an auditor or an attacker finding them. You get a prioritized plan with costs, and you decide what to fix and when.

Do you work outside Georgia?

Yes. The work is remote. We started in Middle Georgia and most of our dental experience is there.