Practitioner-led healthcare compliance, priced up front.

Start with the Security Risk Assessment the rule requires: fixed scope, published price, delivered in days. A free Snapshot tells you where you stand.

The assessment the rule requires.

Every covered entity and business associate must conduct the security risk analysis under 45 CFR 164.308 — the most-cited deficiency in OCR investigations and the artifact MIPS reporters attest to each year. Rote delivers it fixed-scope, priced up front: starting at $3,500, 10 business days, every finding evidence-cited, attestation-ready.

Free / Self-Check
See where you stand

Run the open-source skills yourself, or take the free Snapshot for a maturity read and a routing recommendation.

Starting at $3,500 / Security Risk Assessment
The analysis the rule requires

Asset and ePHI inventory (AI surface included), threats scored, risk register, risk management plan, attestation-ready letter. 10 business days.

Starting at $8k / Risk Management Project
Close the gaps — AI included

Implements the plan: corrected policies, safeguard docs, BAA language, and AI-specific work where findings warrant it. Already have a risk analysis from someone else? Bring it.

Starting at $750/mo / Maintenance
Keep it current

Annual SRA refresh (MIPS requires a fresh analysis each year), quarterly reviews, SAFER Guide, Security Rule watch.

See the HIPAA Security Risk Assessment Get a free Snapshot first

A growing team of agents, on a growing library of skills.

The platform runs a team of compliance agents on top of the same skills the rest of Rote uses. They keep your program current between engagements: each runs on its own cadence, hands its findings to the next, and pauses for your review before anything changes.

The team is not a fixed set. New agents and new skills join as the regulations and the work change, the same way Rote's skill library grows. A few of the agents running today:

Gap Closure

Watches the findings from your last analysis, groups the ones that have not moved, and writes a specific next action for each. One nudge per theme.

Regulatory Watch

Reads the week's regulatory events from Sentinel, filters to what is relevant for your framework and org type, and says plainly whether a response is required.

Document Health

Tracks every document against its review cadence and flags what has fallen behind, so nothing quietly goes stale between reviews.

More as the work grows

The fleet expands with the regulations it covers and the skills it can draw on. The relationship stays the same. The roster does not.

See how the platform works →

The method is already in the field.

The skills behind the agents and the engagements are open source, and practitioners are running them on their own documents, not because they came bundled in something else.

1,500+
installs of the Risk Assessment skill on ClawHub: compliance practitioners running the Rote methodology in their own Claude environments.

The Rote compliance skills are open source and available on ClawHub. Practitioners download them, run them against their own documents, and use the output to drive their compliance programs. The skills have crossed 9,000 downloads, from compliance professionals who chose this framework specifically, not because it came bundled in something else.

Explore the open-source skills →

This is what a Snapshot looks like.

The Snapshot applies the Rote compliance methodology to your organization's current situation and delivers a structured maturity assessment. What you get back is a maturity stage, a service recommendation, and a 30/60/90-day roadmap.

Compliance Readiness Snapshot · [Client Redacted] Confidential
Maturity Stage
Active Management
Score: 68 / 100
Service Recommendation
Security Risk Assessment
Foundation before any AI program
Seven Elements Coverage
Written Standards & Policies
82%
Oversight & Governance
55%
Due Care & Training
71%
Communication & Education
60%
Monitoring & Auditing
40%
Enforcement & Discipline
78%
Incident Response
65%
Priority Finding

No formal HIPAA risk assessment completed in the past 12 months. Required under 45 CFR 164.308(a)(1). Recommend completing within 30 days as the highest-priority gap before any AI deployment expansion.

Representative example. Client details redacted. Your Snapshot reflects your organization's actual documents and posture.

Get your Snapshot See the full services

When a single regulation needs working end to end.

Some rules deserve a program of their own. The method is already mapped to each of these in Rote's regulatory knowledge base — a new regulation becomes a new program without changing how any of it works. Part 2 has its own page today; the rest run as scoped engagements.

Reading the field against the rule.

Rote publishes rolling, aggregate studies of publicly posted compliance artifacts, read against the regulation that governs them. The first reads posted 42 CFR Part 2 patient notices against the 2024 final rule. Findings are reported in aggregate, no organization is named, and the assessment is reproducible through an open skill.

See the research →

Recent writing

Analysis on HIPAA compliance, healthcare regulation, and the intersection of AI and regulated industries.

August 12, 2026
Buy, Compose, or Commission: Choosing AI Tooling When a Wrong Output Is a Finding

Buy versus build is one door short. Composing a workflow on top of a general model is now a real third option, and it changed where the cost of AI tooling actually sits. This is a decision you make per workflow rather than per organization, and in regulated work the door is decided by one thing: whether you can specify and verify a correct output.

April 21, 2026
Consent Architecture: Scope, Collection, and Persistence

Consent architecture is not a single event. The three stages (scope, collection, and persistence) have to run in sequence. Get the order right and the architecture holds over time. Get it out of order and you have three components that coexist without working together.

March 16, 2026
Building 'Skills'

AI models are good at reading, reasoning, and following instructions. What they don't have is the accumulated judgment of a practitioner who has done the task hundreds of times. Skills are how that judgment gets encoded, and why customizing one is the step most people skip.

All writing →

Know your gaps before
your next audit.

The Snapshot is free. The Rote methodology is applied to your organization's actual situation and delivered as a maturity stage, a priority finding, and a 30/60/90-day roadmap, all within one week.