RiskWatch
RiskWatch International · Founded 1993 · Sarasota, FL, USA
Multi-framework healthcare compliance platform with HIPAA + HITECH + NIST 800-66 in one tenant.
Summary
RiskWatch ships a healthcare compliance assessment platform built around pre-mapped control libraries for HIPAA, HITECH, NIST 800-66 (HIPAA Security implementation guide), HITRUST CSF, ISO 27001, SOC 2, NIST 800-53, and 35+ additional frameworks. The platform runs on a survey-based assessment engine plus an evidence vault, a BAA tracker, and a cross-mapping engine that auto-detects shared controls across HIPAA, HITRUST, and ISO 27001. Customers include US state Medicaid agencies, regional health systems, and clinical-research networks. RiskWatch is sold quote-only, and single-tenant deployment lets buyers retain control of ePHI residency.
Strengths
- Pre-built HIPAA Security Rule library mapped to §164.308 administrative safeguards, §164.310 physical safeguards, and §164.312 technical safeguards out of the box
- NIST 800-66 r2 implementation guide library mapped to the HIPAA Security Rule, plus HITRUST CSF and ISO 27001 cross-mapping in the same tenant
- 33-year operating history with US state Medicaid programmes, federal healthcare customers (VA), and regional health systems
- Single-tenant deployment with customer-owned data residency for ePHI; useful for systems whose legal team will not approve multi-tenant SaaS for PHI
- Vendor risk module includes BAA lifecycle management with renewal alerts and 60-day breach-clock tracking aligned to §164.410
- Physical security assessment module (ASIS-aligned) runs in the same tenant as cyber and HIPAA assessments; useful for hospital facilities and clinics
- Survey-based assessment engine works for non-technical control owners (HIM directors, privacy officers) without SQL or workflow-builder skills
Weaknesses
- RiskWatch is sold quote-only; the public site routes buyers through a quote workflow rather than listing prices
- No native Joint Commission tracer-survey module out of the box; assessment engine adapts but is not pre-templated to TJC chapter structure the way Origami Risk is
- Workforce-training and clinical-credentialing are not first-party modules; large health systems running combined training-plus-compliance buying briefs need a second tool (MedTrainer, symplr)
Mid-market and large healthcare buyers running 3+ frameworks (HIPAA + HITECH + ISO 27001 or HITRUST) who want one tenant for compliance, vendor risk, BAA tracking, and physical security assessment with ePHI residency control.
Solo practitioners and small medical practices under 20 staff who want a $99/month HIPAA-only tool with a coach; Compliancy Group fits that brief better.
Key features
- Pre-built HIPAA Security Rule library (§164.308 / §164.310 / §164.312) and Privacy Rule control set
- NIST 800-66 r2 implementation guide library mapped to HIPAA Security Rule
- HITRUST CSF v11 control library with cross-mapping to HIPAA and NIST
- BAA lifecycle management with renewal alerts and §164.410 60-day breach-clock tracking
- Survey-based assessment engine for HIM and privacy officers
- Evidence vault with versioning and OCR-audit-ready export
- Physical security assessment module (ASIS-aligned) for hospital and clinic sites
- Single-tenant deployment for ePHI residency
Integrations
25+ native. Notable: Microsoft Entra ID (SAML SSO), Okta, Microsoft 365 / SharePoint, Slack, Jira, Salesforce, Custom REST API.
Target size
100 to 25,000 employees · US · Canada · EU · UK · AU