Two vendors can both sell "HIPAA risk analysis" and be selling different products. One sells an assessment: a structured questionnaire or engagement that produces a dated report, repeated when you come back next year. The other sells a management model: the assessment plus whatever keeps the findings alive between assessments, such as remediation tracking, change-triggered reviews, and documentation that updates as your environment does. Marketing copy for both will use the same vocabulary. The purchase price often looks similar. What differs is who owns the eleven months between reports, and buyers who do not pin that down in the sales process usually discover the answer during an audit or a breach investigation.
Why the distinction matters
The HIPAA Security Rule treats risk analysis and risk management as two separate required specifications, and regulators probe them separately. When the HHS Office for Civil Rights asks for evidence after a breach, the request typically covers the analysis and what was done about its findings. A vendor whose product ends at the report leaves the second half to you. That can be a fine arrangement, but only if you know it is the arrangement.
The point-in-time model
The point-in-time product is built around an event. You complete an assessment, a report is generated, and the engagement is functionally over until the next cycle. Signals of this model: pricing framed per assessment rather than per year, deliverables described as reports, renewal conversations that begin near your anniversary, and little or no product surface for tracking remediation. Support exists to help you finish the questionnaire, not to work the findings.
There is honest value here. The report may be thorough, the price is usually lower, and a disciplined practice can run its own remediation from a spreadsheet. What the model cannot do is prompt you when something changes in July.
The ongoing model
The ongoing product treats the assessment as an input. Signals: annual subscription pricing that covers activity between assessments, a remediation or task view with owners and due dates, the ability to reopen and update the analysis mid-cycle after a change, documentation that regenerates from current answers rather than living in a frozen PDF, and human review or advisory time built into the tier. Vendors in this model can usually describe, concretely, what a customer does in the platform in an ordinary month with no assessment due.
The trade-off is cost and commitment. An ongoing platform you never log into converts quietly back into a point-in-time product at a subscription price.
The signals, side by side
| What to look at | Point-in-time signal | Ongoing signal |
|---|---|---|
| Pricing unit | Per assessment or engagement | Per year, covering between-assessment work |
| Core deliverable | A dated report | A current risk register plus the report |
| Remediation | A findings list you export | Tracked items with owners and dates in-product |
| Mid-year change | Handled at next assessment | Reopens the relevant answers now |
| Vendor contact between cycles | Renewal outreach | Scheduled reviews or advisory sessions |
| Demo emphasis | How fast the report generates | What the dashboard shows in month six |
Questions that separate the two in a demo
Ask what a customer sees when they log in six months after the assessment, with nothing due. Ask what happens in the product when you add a location or replace an EHR mid-year. Ask who on the vendor side, if anyone, looks at your remediation progress, and when. Ask whether the documentation an auditor would see reflects today's answers or the answers from the last assessment date. Vague responses to these are themselves an answer: the product's center of gravity is the report.
Which model fits which buyer
A solo or small practice with a stable environment, one location, and a capable office manager can buy point-in-time and run the rest itself, and for a constrained budget that is a defensible choice. The calculus shifts as complexity grows. Multiple sites, regular vendor turnover, M&A activity, or a compliance officer stretched across too many duties all raise the cost of owning the gap yourself, and organizations in that position tend to get more from the ongoing model. The failure mode to avoid is the mismatch: paying point-in-time prices while assuming ongoing coverage, or paying ongoing prices and using one twelfth of what you bought.