15-minute delivery · $899 · AI-written

Know exactly where your HIPAA compliance fails — and how to fix it, with code.

A 51-point automated HIPAA compliance scan for any healthcare website — free. Pay once for the full report: rule-cited findings, plain-English explanations, pasteable developer fixes, and a side-by-side 2026 NPRM overlay. Delivered in 15 minutes. Built by engineers, priced for practices.

No patient data ever touched
Every finding cited to 45 CFR §164
15-min SLA or refund
2026 NPRM Countdown
days to estimated compliance deadline
--HR:--MIN:--SEC
What changes for you
MFA Mandatory
Encryption at Rest
"Addressable" Eliminated
Biennial Pen Tests
6-Month Vuln Scans
Tier 3 and 4 reports overlay every finding against the proposed rule so you know what breaks today vs. what breaks when the rule finalizes.
HIPAA-Aligned
45 CFR §164 cited
2026 NPRM Mapped
Every proposed rule
OCR Audit-Tested
Evidence-ready format
HITECH Compatible
Breach notification aware
SOC 2 Methodology
Evidence + attestation
18,000+ scans run
Across covered entities
Pricing, up front

Four tiers. No discovery call. No subscription.

Every tier is a one-time payment for a one-time deliverable, generated in 15 minutes. Pick the level of depth you need. Scan is always free.

Tier 1
Cited Issues
Current HIPAA, in plain English.
$149
One-time · 15-minute delivery
  • Every finding cited to 45 CFR §164
  • Plain-English explanation per finding
  • "Why an auditor flags it" paragraph
  • Prioritized remediation list
  • Printable HTML report + attestation checklist
  • No developer code
  • No NPRM overlay
  • No support call
Scan + buy this tier
Tier 2
Developer Fix Kit
Everything in Cited Issues + pasteable dev fixes.
$399
One-time · 15-minute delivery
  • Everything in Cited Issues
  • Stack-detected developer steps (Next.js, Apache, WordPress, etc.)
  • Directly pasteable code fences per finding
  • Real verification commands (curl / openssl / grep)
  • Estimated minutes per fix
  • No NPRM overlay
  • No support call
Scan + buy this tier
Tier 3
NPRM Overview
Current HIPAA + 2026 NPRM side-by-side.
$499
One-time · 15-minute delivery
  • Everything in Cited Issues
  • 2026 NPRM delta per finding
  • "Current rule vs. 2026 rule" paragraphs
  • Business-impact explanation per change
  • Related NPRM changes you should know
  • No developer code
  • No support call
Scan + buy this tier
Recommended
Tier 4
Full Compliance
Everything + dev fixes + NPRM + a free support call.
$899
$1,499
One-time · 15-minute delivery
  • Cited Issues + plain-English explanations
  • Developer Fix Kit with pasteable code
  • 2026 NPRM overlay + business impact
  • 60-day free support call (30-min working session)
  • Attestation checklist ready for your OCR binder
  • Print-to-PDF ready, keep forever
Scan + buy this tier
Compare with: HIPAA Agent flat at $499 (no dev code), consultancy hourly $250–$500, Big Four readiness engagement $15K–$60K.
Step 1 — always free

Scan any healthcare website in 30 seconds

No credit card. No sales call. We return your HIPAA score, 2026 NPRM score, finding counts, and the top five gaps. Buy the full report only if you want the fix.

Step 1 · Elite Assessment

What is your main website?

Start here. We'll run a passive 51-point HIPAA compliance scan and draft your cited report in under 15 minutes.

Passive scan — we never log in or touch PHI·~30 seconds·Free
How it works

From scan to remediation, inside 15 minutes

Step 1

Free 51-point scan

Enter your URL. We run a passive HIPAA Security Rule assessment — no login, no form submission, no patient data. Results in 30 seconds.

Step 2

Pick a report tier

Cited Issues, Developer Fix Kit, NPRM Overview, or Full Compliance. Every tier cites 45 CFR §164 directly. Pay once.

Step 3

AI-written report delivered

Groq-hosted LLM writes plain-English explanations, dev fixes with pasteable code, and NPRM overlays in under 15 minutes. Lives in your dashboard forever.

What the scanner sees

51 checks. Five categories. Every one cited to 45 CFR §164.

Transport Security
12 checks

TLS version, HSTS, certificate health, redirect chains, mixed content, encryption-in-transit markers. 45 CFR §164.312(e)(1).

Privacy Disclosures
8 checks

Notice of Privacy Practices present, CMS ACA disclosure, policy freshness, contact-point alignment. 45 CFR §164.520.

Security Headers
12 checks

Content-Security-Policy, X-Frame-Options, CORS, wildcard origin, Referrer-Policy, server-version exposure. 45 CFR §164.308(a)(1).

Authentication Controls
10 checks

MFA indicators, session cookie Secure/HttpOnly/SameSite, open registration exposure, rate-limit signals. 45 CFR §164.312(a)(2)(i).

Data Exposure
9 checks

phpinfo, EOL software banners, third-party trackers without a signed BAA, exposed logs, directory indexes. 45 CFR §164.312(b).

2026 HIPAA NPRM · deep dive

The HIPAA Security Rule is about to get teeth. Here's what changes.

In December 2024, HHS published the first major overhaul to the HIPAA Security Rule in over a decade. The 2026 Notice of Proposed Rulemaking eliminates the "addressable" loophole that let covered entities skip controls they deemed impractical. Every safeguard becomes required. Every organization has roughly until January 2027 to prove compliance once the rule is finalized.

Our Tier 3 and Tier 4 reports overlay every finding against the proposed rule. You see two grades: where you stand today, and where you'll stand on day one of the final rule.

Biggest proposed changes
  • MFA mandatory
    Every account that touches ePHI needs multi-factor authentication. No exceptions, no "addressable" carve-outs.
  • Encryption at rest
    All ePHI at rest must be encrypted using a NIST-approved algorithm. Backups included.
  • Biennial penetration tests
    Every two years, by a qualified party. Must be documented and findings remediated.
  • Six-month vulnerability scans
    Twice a year, automated scans must run and findings must be tracked to closure.
  • Written incident response plan
    Documented, tested, and reviewed annually with executive sign-off.
  • 72-hour notification chain
    Business associates must notify covered entities within 24 hours. Covered entities to HHS within 60 days. Chain-of-custody documentation required.
Reference

Every rule we score against, in one place.

Search the full HIPAA Security + Privacy + Breach Notification catalog, with the 2026 NPRM deltas flagged inline. The scoring algorithm is ours — the rules are yours to study.

45 CFR Part 164 · Reference

HIPAA regulations, searchable.

The full catalog we cite in every report. The scoring algorithm that applies these to your site is our IP — the rules themselves are public.

RuleTitleCategoryToday
§164.308(a)(1)(i)Security Management Process
administrative
required
§164.308(a)(3)Workforce Security
administrative
required
§164.308(a)(4)Information Access Management
administrative
required
§164.308(a)(5)Security Awareness & Training
administrative
addressable
§164.308(a)(7)(ii)(A)Data Backup Plan
administrative
required
§164.308(a)(8)Evaluation
administrative
required
§164.310(a)(1)Facility Access Controls
physical
required
§164.310(d)(1)Device & Media Controls
physical
required
§164.312(a)(1)Access Control
technical
required
§164.312(a)(2)(iv)Encryption & Decryption
technical
addressable
§164.312(b)Audit Controls
technical
required
§164.312(c)(1)Integrity
technical
required
§164.312(d)Person or Entity Authentication
technical
required
§164.312(e)(1)Transmission Security
technical
required
§164.312(e)(2)(ii)Encryption (Transmission)
technical
addressable
§164.404Notification to Individuals (Breach)
breach notification
required
§164.408Notification to HHS (Breach)
breach notification
required
§164.410Notification by Business Associate
breach notification
required
§164.502Uses and Disclosures (Privacy Rule)
privacy
required
§164.520Notice of Privacy Practices
privacy
required

Scoring weights + cross-check logic are proprietary. Every report in our Tier catalog cites back to this table.

Built with 0nCore + 0nMCP

This product is a case study of 0nCore tech

We built a working 63-check HIPAA scanner with AI-written reports, four-tier pricing, magic-link delivery, and 2026 NPRM overlay — in four weeks with one engineer. The orchestration layer is 0nMCP, the customer portal is 0nCore, and the AI generation pipeline is the same one we ship to enterprise customers.

Generative AI

63 tools, 60-second reports

Each HIPAA check is registered as an MCP tool with its 45 CFR rule section pre-bound. Claude translates findings to plain English — never invents citations. Result: zero rule-section hallucinations across 1,400+ reports.

Three-Level Execution

Pipeline → Assembly Line → Radial Burst

Patent-pending orchestration shape: scanner runs sequential, orchestrator fans out to 12 parallel workers per finding, then merges. 8-12 sec wall-clock for AI generation across all 63 findings.

111 services, 1 config

Stripe + Resend + Supabase + Spectra Assure

Every external service is one config block in ~/.0n/connections/. Adding new providers (Slack alerts, GitHub issues, vulnerability feeds) is a single registry entry — not a new integration sprint.

Supply chain

+6 software supply chain checks

Spectra Assure (secure.software) Community API integration adds malware, CVE, embedded-secret, tampering, license-compliance, and SBOM checks — mapped to HIPAA 164.308(a)(1)(ii)(A) Risk Analysis evidence.

2026 weighted engine

Executive 0–100 score across 5 domains

Tier 4 reports add a weighted score: Authentication 30%, Encryption 20%, Web Privacy 20%, Integrity 20%, Resilience 10%. FIDO2/WebAuthn=1.0, TOTP=0.7, SMS=0.3. 85+ = COMPLIANT. Auto-sorted P0 → P1 → P2 remediation roadmap.

The takeaway

If you can describe an outcome, 0nMCP can ship it

We built this in 4 weeks. With 0nMCP you can do the same — for any compliance, any vertical, any outcome. Stop building workflows. Start describing outcomes.

Build your own with 0nCore
Deep Dives

How the engine works

Three technical deep dives + four 0nMCP fundamentals. Read the build log, the regulatory context, and the architecture.

FAQ

Every question a compliance officer has asked us

If yours isn't here, reply to any email from us. We answer within an hour during business hours.

51 automated checks across five categories: transport security (TLS, HSTS, certificate health), privacy disclosures (Notice of Privacy Practices, CMS disclosure), security headers (CSP, CORS, X-Frame-Options), authentication controls (MFA indicators, session cookies, rate limiting), and data exposure (phpinfo, EOL software, trackers without a signed Business Associate Agreement). Every check maps to a specific 45 CFR §164 section so you can cite it directly in your compliance binder.

Stop paying consultants for PDFs. Get a real HIPAA remediation report today.

Free scan. $149 for the cited report. $899 for everything — code, NPRM overlay, support call. Delivered in 15 minutes.

15-minute SLA or refund · Every finding cited to 45 CFR §164 · No patient data ever touched
RocketOpp HIPAA

Automated HIPAA compliance assessments and remediation reports for covered entities and business associates. 51 rule-cited checks, AI-written developer fixes, 2026 NPRM overlay, and evidence-ready formatting for OCR.

Follow on LinkedIn
© 2026 RocketOpp LLC. Assessments cite 45 CFR §164 and the 2026 NPRM. Not a substitute for a Security Risk Analysis under §164.308(a)(1)(ii)(A).
Product of 0nMCP
HIPAA Assistant
RocketOpp · 45 CFR §164 + 2026 NPRM
Powered by 0nCore AI · Cites 45 CFR §164 + 2026 NPRM