HIPAA Compliance Cost in 2026: What Is Published, and What Is Not
A HIPAA budget is part licence and part engagement. The licence half has published prices, and this site reads them off the vendors' own cards with the unit and the date. The engagement half has none, because every firm selling it quotes per scope. Most HIPAA cost guides paper over that seam with an estimate. This one shows you where it is.
There is no headline number on this page. Nobody publishes a HIPAA programme total by organisation size, so a total here would be our guess at other companies' quotes wearing a dollar sign.
The two halves of a HIPAA budget
This split is the single most useful thing to understand before you brief anybody for a quote. It is also why cost ranges published elsewhere are so implausibly wide: they are averaging the half nobody publishes.
Priced from a published card
Read off the vendor's own pricing page or its AWS Marketplace listing, attributed and dated.
- Compliance platform subscriptions
- Per-employee platform fees
- Identity, MFA and endpoint tooling
- Cloud security services
- Ambulatory EHR, for the three vendors that publish
Quoted per engagement, published by nobody
Usually the larger half of a first-year programme. This site prints no figure for any of it.
- The risk analysis, which OCR investigates more than any other provision
- Policy and procedure development
- Penetration testing and vulnerability scanning
- Compliance consulting and healthcare counsel
- Gap assessments, mock audits and assessor fees
- Epic, Oracle Health and MEDITECH, none of which publishes a price anywhere
Cost worksheet
Bring your own quotes. This does the arithmetic.
This worksheet holds no prices of its own, because a HIPAA programme is part licence and part engagement, and only the licence half is published. Set your scope on the left and it works out the quantities. Enter a rate on a line, from a quote you hold or the published example beside it, and the line fills in. Leave a line blank and it stays open, because a total that quietly assumes a number you never gave it is exactly what this site exists to avoid.
Quick presets (set scope, not rates)
Your scope
A business associate has no patient-facing Privacy Rule surface, so its policy work is usually narrower. It does not change any published rate on this worksheet.
Meters the per-employee, identity and training lines.
Meters the endpoint protection line.
Your first-year total, from the rates you entered
$0
0 of 8 applicable lines priced. 8 still need a quote and count as zero, so this is a floor, not a budget.
| Line | Your rate | Qty | Line total |
|---|---|---|---|
| Compliance platform subscriptionper yearPublished examples: Compliancy Group plans from $99/mo billed annually; Accountable HQ from $169/mo billed annually ($2,028/yr). Enter the plan you would buy. | $ | ×1 | Need a quote |
| Per-employee platform fee (annual)per workforce member / yearPublished example: Compliancy Group adds a per-employee fee from $8/mo, which is $96 per person per year. Some platforms include this in the plan. | $ | ×10 | Need a quote |
| Identity and MFA licences (annual)per user / yearPublished examples: Cisco Duo Essentials $3/user/mo ($36/yr); Microsoft Entra ID Free includes MFA at $0, so this is frequently a zero line on Microsoft 365. | $ | ×10 | Need a quote |
| Endpoint protection, EDR (annual)per device / yearPublished example: CrowdStrike Falcon Go $59.99 per device per year, capped at 100 devices. Enter the per-device rate you would pay. | $ | ×12 | Need a quote |
| Workforce trainingper person / yearFloor is $0: OCR publishes HIPAA training materials free. Published per-course examples run about $29 per person. Enter what you would spend, or $0 to use the free materials. | $ | ×10 | Need a quote |
| Risk analysisper engagement · quoted per engagement, published by nobodyFloor is $0 for a practice small enough to use the free ONC and OCR Security Risk Assessment Tool. No firm that performs risk analyses publishes an assessor fee, so enter your own quote or leave the line open. | $ | ×1 | Need a quote |
| Policy and procedure developmentper engagement · quoted per engagement, published by nobodyQuoted per engagement against your scope; no firm publishes a rate. A platform's templates can bring this toward $0. Enter your quote or leave it open. | $ | ×1 | Need a quote |
| External audit or gap assessmentper engagement · quoted per engagement, published by nobodyQuoted per engagement; no assessment firm publishes a fee. Brief two or three firms on one written scope and enter the quote you get. | $ | ×1 | Need a quote |
| Total (first year) | $0 |
Your arithmetic, not our estimate
Every figure above is a rate you entered multiplied by a quantity shown next to it. This worksheet supplies no rates and no estimates of its own, because nobody publishes HIPAA programme cost by organisation size: the licence lines have published examples you can adopt, and the engagement lines are quoted per scope and published by nobody, which is why they read “need a quote” until you enter one. Where a line stays open the total is a floor rather than a budget. The published examples beside each line are attributed and dated on the tools comparison and the vendor pages. The 2026 Security Rule proposals would add cost, and HHS declines to quantify several provisions, so this worksheet applies no uplift for them.
The layer you can actually price
Every figure below is attributed to the surface that published it and carries the date it was checked. Note the units: per user, per device and per endpoint are three different meters, and this site states the vendor's own rather than normalising them into a comparison the vendors do not publish.
Compliance platforms
Compliancy Group publishes plans from $99/mo billed annually plus a separate per-employee fee from $8/mo. Accountable HQ publishes Basic $199/mo, or $169 billed annually. Both read off their own pricing pages, checked July 2026.
All published platform rates →Security tooling
Cisco Duo Essentials $3 per user/month. Microsoft Entra ID P1 $7.00 user/month paid yearly. CrowdStrike Falcon Go $7.99 per device monthly or $59.99 annually, published independently. Each vendor's own unit, never normalised.
Units and bands in full →Cloud services
None of AWS, Azure or Google charges a HIPAA surcharge or a BAA fee. What you pay for is the security services you run: AWS KMS $1 per key/month, Azure Sentinel $4.30/GB, GCP Security Command Center Premium at 5% of run rate with a $15,000 annual minimum.
AWS, Azure and GCP rates →HITRUST
HITRUST's own guidance says MyCSF subscriptions typically cost from $18,100 and a readiness assessment report begins at $3,625. It also states each external assessor sets its own fees, so the largest line has no published figure.
HIPAA alongside other frameworks →There is no HIPAA certification
HHS says so in its own FAQ, published in 2003 and never withdrawn: there is no standard or implementation specification requiring a covered entity to certify compliance, HHS does not endorse or otherwise recognize private organizations' certifications regarding the Security Rule, and an external certification does not preclude HHS from later finding a violation. What 45 CFR 164.308(a)(8) requires is a periodic evaluation, internal or external. Worth knowing before you buy anything sold as certification, because the word is doing marketing work rather than regulatory work.
How HIPAA sits alongside SOC 2, ISO 27001 and HITRUST →The 2026 Security Rule proposal, as HHS priced it
HHS priced its own rule in the proposal's regulatory impact analysis. These are its figures, not ours.
HHS first-year total
$9 billion
National, all regulated entities
Ongoing, years 2-5
$6 billion
Per year, national
HHS denominator
1,822,600
Regulated entities
The only per-entity figure
$1,235
Annualized, per establishment
That $1,235 is flat. It carries no breakdown by clinical segment and no differentiation by organisation size, and HHS notes that per-entity costs represent costs per establishment. The impact analysis contains no figure for a dental practice, a clinical laboratory, a home health agency or a pharmacy: the word “dental” does not appear in it once. HHS also put two of the most-discussed provisions in its unquantifiable bucket and attached no dollar figure to either, namely the technology asset inventory and deploying encryption in a more concerted manner. If you have read that the rule adds a fixed percentage to your budget, that percentage is not from HHS.
Status: still a proposal. The comment period closed on 7 March 2025 and no final rule had been published as at July 2026. HHS's Unified Agenda moved the rule to Long-Term Actions and now projects final action in July 2027, having previously projected May 2026. Source: 90 FR 898, 6 January 2025, the proposed rule on the Federal Register.
The proposals, provision by provisionWhat non-compliance costs, as published
OCR publishes every resolution agreement and civil money penalty it concludes. The amounts span orders of magnitude, so this site quotes them individually rather than averaging them into a number that would describe no real organisation.
| Published action | Amount | Type | Date |
|---|---|---|---|
| Montefiore Medical Center | $4,750,000 | Settlement | Feb 2024 |
| Heritage Valley Health System | $950,000 | Settlement | Jul 2024 |
| BayCare Health System | $800,000 | Settlement | May 2025 |
| Assured Imaging | $375,000 | Settlement | Apr 2026 |
| Oregon Health & Science University | $200,000 | Civil money penalty | Dec 2024 |
| MMG Fusion | $10,000 | Settlement | Mar 2026 |
A settlement is not a civil money penalty, and the distinction matters. A resolution agreement is a negotiated settlement with a corrective action plan and no admission of liability, and it is how nearly all OCR enforcement concludes. A civil money penalty is imposed under the statutory tier structure and can be contested before an administrative law judge. Note the range: MMG Fusion settled at $10,000 in March 2026 despite a breach affecting 15 million individuals, which is why an average of these would tell you nothing. A missing or inadequate security risk analysis is the common thread through nearly all of them.
The four-tier penalty structure and the full published record →