OCR Response & Breach Readiness

If OCR comes knocking or a breach occurs, you need someone who has been inside a healthcare organization during an audit — not a consultant who has only read about them.

Kristen Sherrill has managed HIPAA audits and breach responses from inside healthcare organizations. That experience is what we bring to this engagement.

Four situations where this engagement applies: OCR complaint investigation (a patient filed a complaint and OCR has opened an investigation); breach notification (a breach has occurred and you need to assess notification requirements); proactive audit preparation (you have reason to believe an audit is coming); post-breach remediation (OCR requires a corrective action plan after a breach closes).

Typical engagement timeline: Day 1 — initial assessment and risk identification; Days 2–5 — documentation review; Days 5–10 — response preparation; Ongoing — support through resolution.

This engagement is priced as a fixed fee, tiered by scope. A quote is provided after an initial assessment. Contact us before you respond to anything.

Book a Discovery Call →