Notifications
You're all caught up.

Simple pricing. No surprises.

No per-seat fees that punish collaboration. Every plan — including the free one — includes unlimited users, a signed BAA, every register and report, exports, the API, SSO, and employee HIPAA training with automatic quarterly security reminders. Plans differ in only two ways: how much you can put in scope, and whether Ryland, our AI compliance guide, is included.

  • A permanently free tier, no credit card
  • Unlimited users on every plan
  • Signed BAA with every customer
  • SOC 2 Type II audited
  • AES-256 at rest · TLS 1.3 in transit

Pay for the year up front and save close to two months.

Free

$0

For a single small practice documenting a HIPAA Security Rule review. Permanent, not a countdown — there is no read-only cutover.

  • ✓ 1 assessment per year
  • ✓ 1 physical location and 1 ePHI system
  • ✓ HIPAA Security Rule (45 CFR §164.302–318) — the Privacy and Breach Rules, and every other framework, need a paid plan
  • ✓ Unlimited users, with no per-seat fees
  • Employee HIPAA training, included: annual Security & Privacy courses with quizzes and certificates, delivered by email to unlimited employees
  • ✓ Quarterly security-update reminders to your whole workforce, automatic
  • ✓ Gap-analysis reports and PDF/CSV exports
  • ✓ Risk, incident, breach, policy, vendor/BAA, access-review, data-flow and change-log registers
  • ✓ Evidence library, with unlimited storage
  • ✓ Auditor access links and a public trust page
  • ✓ REST and MCP API, webhooks, SSO (SAML 2.0) and SCIM
  • ✓ Signed BAA included
  • — No Ryland AI features
  • — No custom frameworks of your own (the 24 built-in libraries are included)
Get started free

Advanced

$2,999/year

For multi-location health systems, and for consultants managing multiple client organizations.

  • Everything in Premium, plus:
  • ✓ Unlimited assessments — no yearly limit
  • ✓ Unlimited locations and ePHI systems, with no add-on fees
  • ✓ All 24 frameworks at once: HIPAA, SOC 2, ISO 27001/27701/42001, NIST CSF/Privacy/AI RMF/800-53, HITRUST, HICP, CIS, PCI DSS, FedRAMP, CMMC, ONC, 42 CFR Part 2, GDPR/CCPA
  • ✓ Ryland across every framework you have in scope
  • ✓ Dedicated customer success manager
  • ✓ SLA guarantees
  • ✓ Penetration test reports on request
  • ✓ Quarterly compliance reviews
Get started free

Professional Services

Custom

Hands-on engagements led by our certified security, privacy, and compliance team, scoped and priced to your needs.

  • ✓ Guided Security Assessments
  • ✓ M&A due diligence
  • ✓ SOC 2 preparation
  • ✓ OCR investigation response
  • ✓ Breach mitigation
  • ✓ Cloud security reviews
  • ✓ IAM access reviews
  • ✓ Penetration testing
  • ✓ Documentation creation
  • ✓ On-site physical security assessments
  • ✓ Incident investigation
Contact sales

Start on the free plan — no credit card, no countdown. Run a complete HIPAA Security Rule assessment, finalize it, and export it. Upgrade when you need the Privacy and Breach Rules, Ryland, or more scope.
The assessment is annual. Pay for the year up front and save close to two months, or spread the same twelve-month term over monthly payments.

Frequently asked questions

Can we pay for the annual assessment monthly? +

Yes. There are two ways to pay. You pick at checkout. An Annual Assessment paid monthly is $299 a month on Advanced for a twelve-month term, so you commit to the year and pay nothing up front. An Annual Assessment paid up front is $2,999 for the year, which works out to roughly ten months at the same rate, so prepaying saves you about two months. Both are the same twelve-month term with exactly the same features. The only thing that changes is when you pay.

Which compliance frameworks does Prusik Health support? +

Prusik Health ships with 24 built-in control libraries. Frameworks with full assessment question banks include HIPAA (Security and Privacy Rules), SOC 2 (AICPA Trust Services Criteria, including Privacy), ISO/IEC 27001:2022, ISO/IEC 42001:2023 (AI management), the NIST Cybersecurity Framework 2.0, NIST AI Risk Management Framework and Privacy Framework, CIS Controls v8 IG1, GDPR, CCPA/CPRA, and 42 CFR Part 2. Additional frameworks (NIST SP 800-53, HITRUST CSF, HHS 405(d) HICP, CIS v8, PCI DSS v4.0, FedRAMP, CMMC 2.0, ISO/IEC 27701, and ONC Information Blocking under the Cures Act) are covered through cross-framework mapping. How many you can put in scope depends on your plan: Free covers the HIPAA Security Rule (45 CFR 164.302-318) and not the Privacy or Breach Notification Rules, Premium includes any one framework you choose in full with more as paid add-ons, and Advanced includes all 24. Mapping reuses overlapping answers across whichever frameworks you have in scope.

Is employee HIPAA training included? +

Yes, on every plan including Free, at no extra cost. Upload your employee roster (or sync it from your HR system via the API, which is also on every plan) and assign the built-in annual HIPAA Security Awareness and Privacy Essentials courses. Employees take them from a personal email link, with no accounts or passwords, pass a quiz, and receive a certificate. The platform sends weekly reminders until each person completes their training, emails your whole workforce a short security refresher every quarter (the periodic security updates HIPAA expects in addition to annual training), and keeps an exportable org-wide transcript for auditors.

Do I need to sign a BAA to use Prusik Health? +

Yes, and the platform enforces it: evidence uploads, assessment answers, and the rest of the regulated surface stay blocked until the agreement is signed by your organization and countersigned by us — or, for customers who accepted our BAA before 2026-07-29, until that recorded acceptance is on file. You can sign ours in the app as soon as your account is active, route it to whoever is authorized to bind your organization, or upload your own paper for us to countersign.

Is Ryland, the AI compliance guide, on every plan? +

No — Ryland is the one capability that depends on your plan. Premium and Advanced include it in full; the Free tier includes no AI features. Everything else in the platform, including the registers, exports, the API, SSO and employee training, is on every plan.

How do the AI features handle our data? +

AI processing runs under a Business Associate Agreement with our model provider, with zero data retention. Your content is used only to generate the response and is never retained or used to train models. Most features send only aggregate counts and labels. Two kinds of content may contain PHI and are sent to that same service: the contents of evidence files you upload (evidence summarization and answer evaluation), and free text you or your staff type — assessment notes, an incident description, a finding title or description, or a question you ask Ryland. AI is opt-in per organization, every AI action is audit-logged, and nothing the AI produces (verdicts, drafted risks, remediation, summaries) is ever applied automatically. A person always reviews before it counts, and AI answers are grounded only in your own assessment data.

What counts as an "organization"? +

An organization is a single covered entity or distinct business unit with its own HIPAA compliance program. A hospital and its affiliated physician group that maintain separate risk assessments would count as two organizations.

Can I upgrade or downgrade my plan? +

Yes, at any time. Upgrades take effect immediately; downgrades take effect at the next billing cycle.

Is our data isolated from other customers? +

Yes. Every customer's data is logically isolated at the database level, where every query is scoped to your organization and enforced by row-level access controls, and all data is encrypted at rest with AES-256.

What security controls protect our data? +

Prusik Health holds itself to the standard it helps you meet. Authentication is NIST SP 800-63B aligned: Argon2id password hashing, a breached-password check, and MFA via authenticator apps (TOTP), passkeys, or hardware security keys (FIDO2/WebAuthn) — on by default for every new account and enforceable as an organization-wide policy. Data is encrypted with AES-256 at rest and TLS 1.3 in transit. Tenants are isolated with organization-scoped, row-level access controls, and all data is encrypted at rest with AES-256. Sessions are server-side and revocable. Every action is written to a tamper-evident (SHA-256 hash-chained) audit log retained for six years. The platform is SOC 2 Type II audited and penetration-tested annually, and we sign a BAA with every customer. Penetration test reports are available on request under NDA.

Can we export all our data if we leave? +

Yes, on every plan including Free. You can export assessment data, evidence, and reports in standard formats at any time, and we also provide a full data export within 30 days of account closure. During a free evaluation, exports unlock when the plan starts.

Questions? Talk to our team.

We're happy to walk you through the right plan for your organization.