AI usage policy for law firms and dental offices
A copyable staff AI policy, plus browser and device controls to manage client data, approved tools and incident reporting.
Read articleSmall Business Security
Compare five SIEM options on evidence, retention, response, pricing, contract terms and minimums for a small practice.
For a small healthcare or professional practice, the useful SIEM comparison starts with which records you can retrieve and who investigates them. Retention, incident support and a fully operated SOC are separate buying questions.
Obsidian Ridge's Ridge Log managed SIEM add-on costs $8 per data source per month, with no minimum. The add-on contract term is not published; confirm it, source coverage and retention in the quote. Huntress's SOC monitors and acts 24/7; Obsidian Ridge provides CISSP-led follow-through within one business day, serving the Research Triangle and businesses across the United States. Obsidian Ridge publishes this comparison and includes our own service. It is not an independent ranking. Vendor pages were fetched October 2, 2026; a quote is still needed wherever a term or limit is not published.
| Provider | HIPAA evidence reports | Retention | Who responds | Pricing model | Term | Minimum | Sources |
|---|---|---|---|---|---|---|---|
| Huntress Managed SIEM | Search, compliance reporting and incident reports; ask for a HIPAA-specific sample | Up to seven years available; confirm the included period and archive price in the quote | Huntress SOC 24/7 | $3.50/data source/month at 100 sources | 12 months standard | 50 per product direct/reseller; none required through an MSP | Product, pricing |
| Blumira | HIPAA compliance mappings and reporting; obtain a sample | One year included; longer retention optional | Detect has business-hours support; Respond/Automate include 24/7 incident support. Confirm who owns alerts | Detect $12, Respond $16, Automate $21 per employee/month | Not published on pricing page | Not published on pricing page | Pricing, SIEM |
| Rapid7 Incident Command (SIEM) | Specific HIPAA report format not published in cited package/storage pages | Essential: 90-day logs; Advanced/Ultimate: 180-day logs. Alert/audit records: 13 months. Add-ons available | SIEM operation and a separate MDR service are different scopes; confirm the purchased package | Asset-based; quote, numeric price not published on package page | Not published | Not published | Packages, retention |
| Arctic Wolf MDR | Compliance support and Data Explorer evidence access; request HIPAA sample | 90 days under August 2026 MDR terms unless another period is purchased | Managed detection and response service; confirm authorized actions | Quote; numeric price not published in cited sources | Order-form scope; fixed term not published in cited sources | Not published | Compliance, MDR terms |
| Obsidian Ridge: Ridge Log | Scoped log exports and incident records; HIPAA report format agreed before purchase | Confirm selected search/archive periods in the proposal | Huntress SOC 24/7; Obsidian Ridge follow-through within one business day | $8/data source/month, add-on to a tier | Add-on term not published; confirm in quote | No minimum | Service, pricing |
Rapid7's current Incident Command package table separates log retention from alert/audit retention. Its older InsightIDR storage FAQ describes 13 months of searchable logs; do not transfer that period to a new Incident Command quote. Confirm the exact product and purchased retention. Current packages; InsightIDR storage FAQ.
These are different purchasing models. Blumira counts employees; Huntress and Ridge Log use data sources. Do not multiply all rows by the same headcount. Blumira's employee definition covers knowledge workers with corporate email and a workstation. Its pricing page also lists onboarding fees: $500 for Detect, $250 for Respond and included for Automate. Blumira pricing.
Ask for a redacted sample export and a demonstration of how to find a specific event. The report should identify the source and time period. Confirm whether the service provides raw records, a summary, an incident report or a framework mapping; those are different artifacts.
For an insurance application, compare the evidence with the carrier's exact question. A screenshot of a dashboard does not establish that every required device was monitored for the whole period. Use free application help and the questionnaire worksheet to identify the records you need.
HHS distinguishes documentation requirements from technical safeguards such as audit controls and activity review. Its six-year documentation rule is not a universal six-year requirement for every raw log. Set the retention policy using the type of record, risk analysis and other applicable requirements. HHS Security Rule summary.
Ask separately about searchable storage, archives, restore charges, export formats and access after cancellation. A vendor advertising a maximum period does not establish that the maximum is included in your base fee. Record the purchased period in the proposal.
Write a handoff that identifies alert review, containment authority, escalation and recovery. A support phone number alone does not prove that someone continuously reviews your events. Conversely, a managed service may act within its platform but still need the practice or IT provider to repair an application or restore files.
Our managed SIEM scope explains the log add-on. The dental programme and law-firm programme connect it to broader responsibilities. Obsidian Ridge's Ridge Core includes endpoint MDR and Microsoft 365 or Google Workspace ITDR at $25 per person per month, month-to-month with no minimum and business onboarding separate. Huntress's SOC monitors and acts 24/7; Obsidian Ridge provides CISSP-led follow-through within one business day, serving the Research Triangle and businesses across the United States. The base tier and the log add-on are separate charges.
Require named sources, billed units, retention, who operates the service, after-hours actions, onboarding and cancellation/export terms. Put unsupported sources and out-of-scope response work on the same page. Compare the total cost of that scope instead of ranking a per-user price against a per-source price.
The Readiness Sprint costs $1,500 to $3,500 once for a 7-business-day engagement. The deliverable is the same at each scope: a signed evidence pack and a record of controls and gaps. The Sprint is evidence work, not a bundled SIEM subscription. Pricing separates the offers; talk with us when your source inventory is ready.
Last updated
October 2, 2026. We refresh this content as the threat landscape and tools evolve.
FAQ
No blanket raw-log retention period follows from the six-year HIPAA documentation rule. Determine which records you need, the practice risk analysis and other applicable requirements. Write down searchable and archived retention separately.
No. A report can support answers, but the carrier decides what it accepts and the evidence must match the deployed scope. Ask which sources, time period and response activity the report actually covers.
Obsidian Ridge's Ridge Log managed SIEM add-on costs $8 per data source per month, with no minimum. The add-on contract term is not published; confirm it, source coverage and retention in the quote.
Huntress's SOC monitors and acts 24/7; Obsidian Ridge provides CISSP-led follow-through within one business day, serving the Research Triangle and businesses across the United States.
No. Access to an incident-support team and continuous outsourced monitoring are different scopes. Ask who reviews alerts, who can contain a threat and who completes follow-through.
Related reading
A copyable staff AI policy, plus browser and device controls to manage client data, approved tools and incident reporting.
Read articleMonthly costs for 5, 10 and 20 people, with onboarding, contract terms and the work a medical or dental practice still needs.
Read articleNine checks for a dental security provider: devices, accounts, HIPAA responsibilities, response, evidence, backups and the full price.
Read article