Boondoc, I did the security risk analysis myself using tools my REC gave me.
Ours in Maine will not do the risk analysis for us, but they pointed us to a company who will do it for a cost of about $1,200. That price they quoted you is a bargain. And as you discovered, it's very difficult to actually comply with the security measures because they are numerous and somewhat complicated. It's much more difficult than simply having passwords on the computers and a firewall router.

It should not dissuade you from going for it however. I did the security assessment in about 6 hours of my personal time, spread out over several days to make it manageable. Good luck in your attestation attempt!

If you would like the toolkits, I'm willing to send to you. It's larger than one email can handle (>10MB) but I can split it up. Just PM or email me if you want to do this yourself.


Adam Lauer, DO (solo FP)
Twin City Family Medicine
Brewer, ME