Obsidian Ridge

Small Business Security

Managed SIEM for HIPAA and cyber-insurance evidence

Compare five SIEM options on evidence, retention, response, pricing, contract terms and minimums for a small practice.

SMB

For a small healthcare or professional practice, the useful SIEM comparison starts with which records you can retrieve and who investigates them. Retention, incident support and a fully operated SOC are separate buying questions.

Obsidian Ridge's Ridge Log managed SIEM add-on costs $8 per data source per month, with no minimum. The add-on contract term is not published; confirm it, source coverage and retention in the quote. Huntress's SOC monitors and acts 24/7; Obsidian Ridge provides CISSP-led follow-through within one business day, serving the Research Triangle and businesses across the United States. Obsidian Ridge publishes this comparison and includes our own service. It is not an independent ranking. Vendor pages were fetched October 2, 2026; a quote is still needed wherever a term or limit is not published.

How do the five options compare?

ProviderHIPAA evidence reportsRetentionWho respondsPricing modelTermMinimumSources
Huntress Managed SIEMSearch, compliance reporting and incident reports; ask for a HIPAA-specific sampleUp to seven years available; confirm the included period and archive price in the quoteHuntress SOC 24/7$3.50/data source/month at 100 sources12 months standard50 per product direct/reseller; none required through an MSPProduct, pricing
BlumiraHIPAA compliance mappings and reporting; obtain a sampleOne year included; longer retention optionalDetect has business-hours support; Respond/Automate include 24/7 incident support. Confirm who owns alertsDetect $12, Respond $16, Automate $21 per employee/monthNot published on pricing pageNot published on pricing pagePricing, SIEM
Rapid7 Incident Command (SIEM)Specific HIPAA report format not published in cited package/storage pagesEssential: 90-day logs; Advanced/Ultimate: 180-day logs. Alert/audit records: 13 months. Add-ons availableSIEM operation and a separate MDR service are different scopes; confirm the purchased packageAsset-based; quote, numeric price not published on package pageNot publishedNot publishedPackages, retention
Arctic Wolf MDRCompliance support and Data Explorer evidence access; request HIPAA sample90 days under August 2026 MDR terms unless another period is purchasedManaged detection and response service; confirm authorized actionsQuote; numeric price not published in cited sourcesOrder-form scope; fixed term not published in cited sourcesNot publishedCompliance, MDR terms
Obsidian Ridge: Ridge LogScoped log exports and incident records; HIPAA report format agreed before purchaseConfirm selected search/archive periods in the proposalHuntress SOC 24/7; Obsidian Ridge follow-through within one business day$8/data source/month, add-on to a tierAdd-on term not published; confirm in quoteNo minimumService, pricing

Rapid7's current Incident Command package table separates log retention from alert/audit retention. Its older InsightIDR storage FAQ describes 13 months of searchable logs; do not transfer that period to a new Incident Command quote. Confirm the exact product and purchased retention. Current packages; InsightIDR storage FAQ.

These are different purchasing models. Blumira counts employees; Huntress and Ridge Log use data sources. Do not multiply all rows by the same headcount. Blumira's employee definition covers knowledge workers with corporate email and a workstation. Its pricing page also lists onboarding fees: $500 for Detect, $250 for Respond and included for Automate. Blumira pricing.

What evidence should a practice request before buying?

Ask for a redacted sample export and a demonstration of how to find a specific event. The report should identify the source and time period. Confirm whether the service provides raw records, a summary, an incident report or a framework mapping; those are different artifacts.

For an insurance application, compare the evidence with the carrier's exact question. A screenshot of a dashboard does not establish that every required device was monitored for the whole period. Use free application help and the questionnaire worksheet to identify the records you need.

How should HIPAA affect retention decisions?

HHS distinguishes documentation requirements from technical safeguards such as audit controls and activity review. Its six-year documentation rule is not a universal six-year requirement for every raw log. Set the retention policy using the type of record, risk analysis and other applicable requirements. HHS Security Rule summary.

Ask separately about searchable storage, archives, restore charges, export formats and access after cancellation. A vendor advertising a maximum period does not establish that the maximum is included in your base fee. Record the purchased period in the proposal.

Who acts after the SIEM finds something?

Write a handoff that identifies alert review, containment authority, escalation and recovery. A support phone number alone does not prove that someone continuously reviews your events. Conversely, a managed service may act within its platform but still need the practice or IT provider to repair an application or restore files.

Our managed SIEM scope explains the log add-on. The dental programme and law-firm programme connect it to broader responsibilities. Obsidian Ridge's Ridge Core includes endpoint MDR and Microsoft 365 or Google Workspace ITDR at $25 per person per month, month-to-month with no minimum and business onboarding separate. Huntress's SOC monitors and acts 24/7; Obsidian Ridge provides CISSP-led follow-through within one business day, serving the Research Triangle and businesses across the United States. The base tier and the log add-on are separate charges.

What should the final quote say?

Require named sources, billed units, retention, who operates the service, after-hours actions, onboarding and cancellation/export terms. Put unsupported sources and out-of-scope response work on the same page. Compare the total cost of that scope instead of ranking a per-user price against a per-source price.

The Readiness Sprint costs $1,500 to $3,500 once for a 7-business-day engagement. The deliverable is the same at each scope: a signed evidence pack and a record of controls and gaps. The Sprint is evidence work, not a bundled SIEM subscription. Pricing separates the offers; talk with us when your source inventory is ready.

Sources

Last updated

October 2, 2026. We refresh this content as the threat landscape and tools evolve.

FAQ

Questions readers usually ask next

Does HIPAA require six years of all raw SIEM logs?

No blanket raw-log retention period follows from the six-year HIPAA documentation rule. Determine which records you need, the practice risk analysis and other applicable requirements. Write down searchable and archived retention separately.

Is a SIEM compliance report enough for cyber insurance?

No. A report can support answers, but the carrier decides what it accepts and the evidence must match the deployed scope. Ask which sources, time period and response activity the report actually covers.

What does Obsidian Ridge managed SIEM cost?

Obsidian Ridge's Ridge Log managed SIEM add-on costs $8 per data source per month, with no minimum. The add-on contract term is not published; confirm it, source coverage and retention in the quote.

Huntress's SOC monitors and acts 24/7; Obsidian Ridge provides CISSP-led follow-through within one business day, serving the Research Triangle and businesses across the United States.

Is 24/7 support the same as a managed SOC?

No. Access to an incident-support team and continuous outsourced monitoring are different scopes. Ask who reviews alerts, who can contain a threat and who completes follow-through.

Full bio & provenanceSee related service

Related reading