Frequently asked questions
Direct answers for assessment buyers and reviewers.
Clear scope, careful claims, and no mystery about what the engagement can—and cannot—produce.
01What do we receive from an assessment?+
The engagement can produce a signed assessment with an executive summary, scoped AI inventory, data-flow documentation, evidence-backed findings, risk prioritization, framework references, limitations, and remediation recommendations. Exact contents depend on the agreed scope.
02Can we use the assessment during a hospital or healthcare security review?+
You may provide the assessment as evidence during relevant security, vendor-risk, procurement, or partner diligence. Each reviewer decides what evidence it requires, who may rely on the report, and whether the assessment is sufficient.
03What procedures can be included?+
A scope may include document review, stakeholder interviews, configuration inspection, observation, demonstrations, and sampling. The written scope states which procedures were performed and which were not.
04Does the assessment include technical testing?+
Not automatically. Penetration testing, source-code review, model-performance evaluation, AI red-teaming, and continuous monitoring are excluded unless separately scoped and documented.
05How is missing or conflicting evidence handled?+
The report identifies unavailable, stale, conflicting, client-represented, and not-tested evidence. Conclusions are qualified when evidence quality or coverage limits confidence.
06How current is the assessment?+
The report is point-in-time. It states its assessment date or period, evidence cutoff, scope, and change-after-assessment boundary. Material changes may require an update or new assessment.
07Can Ayliea receive PHI?+
Ayliea's published posture is no PHI by design. Do not send patient records, PHI, credentials, questionnaires, or assessment evidence through the booking page or initial email. Engagement-specific transfer arrangements are established in writing.
08What does independent mean?+
Ayliea is an external, paid assessor rather than the organization being assessed or its regulator. Independence does not imply governmental authority. Potential conflicts are addressed during scoping, and commercial outcomes are not guaranteed.
09How are corrections handled?+
Factual errors and evidence references can be corrected through a documented review process. A request to change a commercial outcome does not require the assessor to change a supported professional conclusion.
10How long does an engagement take?+
Once your evidence is ready, a Focused Assessment typically runs about 3–4 weeks and a Comprehensive Assessment about 5–6 weeks. Timing still depends on scope, system count, entities, procedures, and how quickly evidence and stakeholders are available, so the scoping call sets a realistic plan for your engagement.
11How much does an engagement cost?+
Focused Assessments start at $6,500. Comprehensive Assessments start at $15,000. Enterprise Programs use a custom scope.
12Do you certify HIPAA compliance?+
No. Ayliea does not provide a government-backed HIPAA certification, certify that an organization is HIPAA compliant, or guarantee compliance. Relevant findings may be mapped to applicable HIPAA Security Rule safeguards.
13What security frameworks do you assess against?+
Ayliea maps and aligns relevant findings to established AI security frameworks: NIST AI RMF 1.0, ISO/IEC 42001:2023, HIPAA Security Rule, OWASP LLM Top 10, MITRE ATLAS. These references frame the findings so a receiving reviewer can place them in a familiar context. Mapping and alignment are not certification or endorsement—Ayliea is not a certification body—and professional judgments and evidence-quality decisions remain explained and attributable to the assessor.
Next step
Have a healthcare security review coming up?
Use a 20-minute scoping call to clarify what the reviewer is asking for, what belongs in scope, and whether an independent Ayliea assessment is a fit.
- Clarify the review request
- Identify systems and evidence
- Define a defensible scope