Buyer Tips

Point-in-Time or Ongoing: How to Read a Vendor's Risk-Management Model

Two vendors can both sell "HIPAA risk analysis" and be selling different products. One sells an assessment: a structured questionnaire or engagement that produces a dated report, repeated when you come back next year. The other sells a management model: the assessment plus whatever keeps the findings alive between assessments, such as remediation tracking, change-triggered reviews, and documentation that updates as your environment does. Marketing copy for both will use the same vocabulary. The purchase price often looks similar. What differs is who owns the eleven months between reports, and buyers who do not pin that down in the sales process usually discover the answer during an audit or a breach investigation.

Why the distinction matters

The HIPAA Security Rule treats risk analysis and risk management as two separate required specifications, and regulators probe them separately. When the HHS Office for Civil Rights asks for evidence after a breach, the request typically covers the analysis and what was done about its findings. A vendor whose product ends at the report leaves the second half to you. That can be a fine arrangement, but only if you know it is the arrangement.

The point-in-time model

The point-in-time product is built around an event. You complete an assessment, a report is generated, and the engagement is functionally over until the next cycle. Signals of this model: pricing framed per assessment rather than per year, deliverables described as reports, renewal conversations that begin near your anniversary, and little or no product surface for tracking remediation. Support exists to help you finish the questionnaire, not to work the findings.

There is honest value here. The report may be thorough, the price is usually lower, and a disciplined practice can run its own remediation from a spreadsheet. What the model cannot do is prompt you when something changes in July.

The ongoing model

The ongoing product treats the assessment as an input. Signals: annual subscription pricing that covers activity between assessments, a remediation or task view with owners and due dates, the ability to reopen and update the analysis mid-cycle after a change, documentation that regenerates from current answers rather than living in a frozen PDF, and human review or advisory time built into the tier. Vendors in this model can usually describe, concretely, what a customer does in the platform in an ordinary month with no assessment due.

The trade-off is cost and commitment. An ongoing platform you never log into converts quietly back into a point-in-time product at a subscription price.

The signals, side by side

What to look atPoint-in-time signalOngoing signal
Pricing unitPer assessment or engagementPer year, covering between-assessment work
Core deliverableA dated reportA current risk register plus the report
RemediationA findings list you exportTracked items with owners and dates in-product
Mid-year changeHandled at next assessmentReopens the relevant answers now
Vendor contact between cyclesRenewal outreachScheduled reviews or advisory sessions
Demo emphasisHow fast the report generatesWhat the dashboard shows in month six

Questions that separate the two in a demo

Ask what a customer sees when they log in six months after the assessment, with nothing due. Ask what happens in the product when you add a location or replace an EHR mid-year. Ask who on the vendor side, if anyone, looks at your remediation progress, and when. Ask whether the documentation an auditor would see reflects today's answers or the answers from the last assessment date. Vague responses to these are themselves an answer: the product's center of gravity is the report.

Which model fits which buyer

A solo or small practice with a stable environment, one location, and a capable office manager can buy point-in-time and run the rest itself, and for a constrained budget that is a defensible choice. The calculus shifts as complexity grows. Multiple sites, regular vendor turnover, M&A activity, or a compliance officer stretched across too many duties all raise the cost of owning the gap yourself, and organizations in that position tend to get more from the ongoing model. The failure mode to avoid is the mismatch: paying point-in-time prices while assuming ongoing coverage, or paying ongoing prices and using one twelfth of what you bought.