Skip to main content
Pricing

Calm pricing for a stressful topic.

Free triage and self-check forever. Annual subscriptions for the full library and a 4-hour incident-response SLA on the Retainer tier.

In an incident right now? Upgrade to Retainer same-day — 4-hour SLA.
Talk to us now →
Who you'll be talking to

Travis Barlow — 25+ years in incident response, 580+ engagements, founder of AtlSecCon, one of Canada's longest-running security conferences. No SDR, no junior associate — you talk to the person who's run this incident before.

Prices in CAD
Free
$0forever

Use it during an incident or as a tabletop exercise.

Get started →
Most popular
Practice
CA$849/ year · or CA$85 / month

Less than the fine for a 5-record breach with no documentation.

Get started →
Practice + Retainer
CA$2,850/ year

A named contact and a 4-hour incident-response SLA.

Get started →
What's includedFreePractice+ Retainer
Triage toolIncludedIncludedIncluded
HIPAA self-checkIncludedIncludedIncluded
Phase 1 playbooks (4 available now)IncludedIncludedIncluded
All 12 incident playbooksIncludedIncludedIncluded
Regulatory grid updatesNot includedIncludedIncluded
Annual SRA checklistNot includedIncludedIncluded
BAA at signingNot includedIncludedIncluded
Annual tabletop exerciseNot includedNot includedIncluded
Priority incident responseNot includedNot included4-hr SLA
Insurer questionnaire helpNot includedNot includedIncluded
Named point of contactNot includedNot includedIncluded

Multi-location practices: location 2 at 60% of base rate, locations 3+ at 50%. Volume break begins at 3 sites.

Playbook library

Twelve playbooks, all live.

Every incident scenario in the library is published and open to everyone.

Browse the playbooks →

Pricing FAQ

Does the free tier require a login?+

No. The triage tool and the HIPAA self-check are use-without-signing-in by design. Nothing you click on either page leaves your device.

What is a BAA and why does it matter?+

A Business Associate Agreement is a contract required under HIPAA between a covered entity (your practice) and any vendor that handles PHI on your behalf. Without a signed BAA, sharing PHI with the vendor is itself a HIPAA violation. We include a current BAA at signing on the paid tiers.

Is pricing under most state single-quote thresholds?+

Yes — pricing is designed to fall under the single-vendor-quote thresholds most Medicare-billing practices operate against, so procurement is straightforward.

Can I pay monthly?+

Yes, on the Practice tier (CA$85/month). The Retainer tier is annual only because it includes a tabletop exercise and a named contact.

What if I'm in an active incident — can I upgrade right now?+

Yes. Same-day upgrades from Free to Practice or Retainer are routine. Email hello@medical.hackfirstaid.com or use the contact form — we respond within one business hour during US Eastern business hours.

Built by

Travis R. Barlow.

25+ years in incident response. 580+ engagements. Founder of AtlSecCon, one of Canada's longest-running security conferences. No SDR, no junior associate — you talk to the person who has run this incident before.

25+
years IR
580+
engagements
1–25
provider ICP
Scenarios we have walked practices through

Illustrative composites drawn from practitioner conversations. No patient or practice identifiers.

  • Ransomware · Friday afternoon

    Walked the office manager of an 8-provider primary-care clinic through the first three hours — who to call, what not to touch, and what the 60-day HIPAA clock meant.

  • Cyber-insurer renewal

    A 3-provider dermatology clinic pulled the playbooks, customized two pages, and the underwriter accepted the plan — instead of a $9,000 consulting engagement.

  • BEC wire-fraud attempt

    A 5-provider OB/GYN group had read the Front-Desk Email Compromise playbook the week before. Their dual-approval rule caught the wire and prevented the loss.

  • MSP handoff to physician-owner

    The HIPAA self-check produced a one-page gap list an MSP could hand to a physician-owner — no jargon translation required.

Upgrade — vCISO

Your MIPS-ready SRA — and a named owner for the 60-day clock.

Training gets your people ready and advisory is there when something breaks. When you need someone to own the program — the HIPAA Security Rule, your annual SRA, and 405(d) “reasonable security” — and be the name your OCR, cyber insurer, EHR/clearinghouse business associates, and (in Canada) your provincial health privacy commissioner can point to, that’s the HackFirstAid vCISO: a security leader on retainer. Built for the EHR/vendor ransomware event mid-clinic-day, where the breach clock starts before the schedule clears.

We own your program

Strategy, risk register, roadmap, governance, cadenced reviews, and the OCR, cyber-insurer, EHR/clearinghouse BA, and provincial privacy commissioner conversations.

Independent partners execute

DFIR, SOC, pen-testing, tooling, legal, brokerage — coordinated by your vCISO, never sold by us.

Small Practice
CA$1,800/mo
Solo & the smallest offices — quarterly cadence
Foundations
CA$3,000/mo
Managed
CA$6,500/mo
Most chosen
Embedded
CA$12,000/mo

Billed annually. Every tier includes a named vCISO, a 90-day on-ramp, and household coverage.