This site provides independent HIPAA compliance cost estimates for informational purposes only. We are not affiliated with HHS, OCR, or any compliance vendor. This is not legal or regulatory advice. Consult a qualified HIPAA compliance professional for guidance specific to your organization.

HIPAA Compliance Cost in 2026: What Is Published, and What Is Not

A HIPAA budget is part licence and part engagement. The licence half has published prices, and this site reads them off the vendors' own cards with the unit and the date. The engagement half has none, because every firm selling it quotes per scope. Most HIPAA cost guides paper over that seam with an estimate. This one shows you where it is.

There is no headline number on this page. Nobody publishes a HIPAA programme total by organisation size, so a total here would be our guess at other companies' quotes wearing a dollar sign.

The two halves of a HIPAA budget

This split is the single most useful thing to understand before you brief anybody for a quote. It is also why cost ranges published elsewhere are so implausibly wide: they are averaging the half nobody publishes.

Priced from a published card

Read off the vendor's own pricing page or its AWS Marketplace listing, attributed and dated.

  • Compliance platform subscriptions
  • Per-employee platform fees
  • Identity, MFA and endpoint tooling
  • Cloud security services
  • Ambulatory EHR, for the three vendors that publish

Quoted per engagement, published by nobody

Usually the larger half of a first-year programme. This site prints no figure for any of it.

  • The risk analysis, which OCR investigates more than any other provision
  • Policy and procedure development
  • Penetration testing and vulnerability scanning
  • Compliance consulting and healthcare counsel
  • Gap assessments, mock audits and assessor fees
  • Epic, Oracle Health and MEDITECH, none of which publishes a price anywhere

Cost worksheet

Bring your own quotes. This does the arithmetic.

This worksheet holds no prices of its own, because a HIPAA programme is part licence and part engagement, and only the licence half is published. Set your scope on the left and it works out the quantities. Enter a rate on a line, from a quote you hold or the published example beside it, and the line fills in. Leave a line blank and it stays open, because a total that quietly assumes a number you never gave it is exactly what this site exists to avoid.

Quick presets (set scope, not rates)

Your scope

A business associate has no patient-facing Privacy Rule surface, so its policy work is usually narrower. It does not change any published rate on this worksheet.

Meters the per-employee, identity and training lines.

Meters the endpoint protection line.

Your first-year total, from the rates you entered

$0

0 of 8 applicable lines priced. 8 still need a quote and count as zero, so this is a floor, not a budget.

LineYour rateQtyLine total
Compliance platform subscriptionper yearPublished examples: Compliancy Group plans from $99/mo billed annually; Accountable HQ from $169/mo billed annually ($2,028/yr). Enter the plan you would buy.
$
×1Need a quote
Per-employee platform fee (annual)per workforce member / yearPublished example: Compliancy Group adds a per-employee fee from $8/mo, which is $96 per person per year. Some platforms include this in the plan.
$
×10Need a quote
Identity and MFA licences (annual)per user / yearPublished examples: Cisco Duo Essentials $3/user/mo ($36/yr); Microsoft Entra ID Free includes MFA at $0, so this is frequently a zero line on Microsoft 365.
$
×10Need a quote
Endpoint protection, EDR (annual)per device / yearPublished example: CrowdStrike Falcon Go $59.99 per device per year, capped at 100 devices. Enter the per-device rate you would pay.
$
×12Need a quote
Workforce trainingper person / yearFloor is $0: OCR publishes HIPAA training materials free. Published per-course examples run about $29 per person. Enter what you would spend, or $0 to use the free materials.
$
×10Need a quote
Risk analysisper engagement · quoted per engagement, published by nobodyFloor is $0 for a practice small enough to use the free ONC and OCR Security Risk Assessment Tool. No firm that performs risk analyses publishes an assessor fee, so enter your own quote or leave the line open.
$
×1Need a quote
Policy and procedure developmentper engagement · quoted per engagement, published by nobodyQuoted per engagement against your scope; no firm publishes a rate. A platform's templates can bring this toward $0. Enter your quote or leave it open.
$
×1Need a quote
External audit or gap assessmentper engagement · quoted per engagement, published by nobodyQuoted per engagement; no assessment firm publishes a fee. Brief two or three firms on one written scope and enter the quote you get.
$
×1Need a quote
Total (first year)$0

Your arithmetic, not our estimate

Every figure above is a rate you entered multiplied by a quantity shown next to it. This worksheet supplies no rates and no estimates of its own, because nobody publishes HIPAA programme cost by organisation size: the licence lines have published examples you can adopt, and the engagement lines are quoted per scope and published by nobody, which is why they read “need a quote” until you enter one. Where a line stays open the total is a floor rather than a budget. The published examples beside each line are attributed and dated on the tools comparison and the vendor pages. The 2026 Security Rule proposals would add cost, and HHS declines to quantify several provisions, so this worksheet applies no uplift for them.

The layer you can actually price

Every figure below is attributed to the surface that published it and carries the date it was checked. Note the units: per user, per device and per endpoint are three different meters, and this site states the vendor's own rather than normalising them into a comparison the vendors do not publish.

Compliance platforms

Compliancy Group publishes plans from $99/mo billed annually plus a separate per-employee fee from $8/mo. Accountable HQ publishes Basic $199/mo, or $169 billed annually. Both read off their own pricing pages, checked July 2026.

All published platform rates

Security tooling

Cisco Duo Essentials $3 per user/month. Microsoft Entra ID P1 $7.00 user/month paid yearly. CrowdStrike Falcon Go $7.99 per device monthly or $59.99 annually, published independently. Each vendor's own unit, never normalised.

Units and bands in full

Cloud services

None of AWS, Azure or Google charges a HIPAA surcharge or a BAA fee. What you pay for is the security services you run: AWS KMS $1 per key/month, Azure Sentinel $4.30/GB, GCP Security Command Center Premium at 5% of run rate with a $15,000 annual minimum.

AWS, Azure and GCP rates

HITRUST

HITRUST's own guidance says MyCSF subscriptions typically cost from $18,100 and a readiness assessment report begins at $3,625. It also states each external assessor sets its own fees, so the largest line has no published figure.

HIPAA alongside other frameworks

There is no HIPAA certification

HHS says so in its own FAQ, published in 2003 and never withdrawn: there is no standard or implementation specification requiring a covered entity to certify compliance, HHS does not endorse or otherwise recognize private organizations' certifications regarding the Security Rule, and an external certification does not preclude HHS from later finding a violation. What 45 CFR 164.308(a)(8) requires is a periodic evaluation, internal or external. Worth knowing before you buy anything sold as certification, because the word is doing marketing work rather than regulatory work.

How HIPAA sits alongside SOC 2, ISO 27001 and HITRUST →

The 2026 Security Rule proposal, as HHS priced it

HHS priced its own rule in the proposal's regulatory impact analysis. These are its figures, not ours.

HHS first-year total

$9 billion

National, all regulated entities

Ongoing, years 2-5

$6 billion

Per year, national

HHS denominator

1,822,600

Regulated entities

The only per-entity figure

$1,235

Annualized, per establishment

That $1,235 is flat. It carries no breakdown by clinical segment and no differentiation by organisation size, and HHS notes that per-entity costs represent costs per establishment. The impact analysis contains no figure for a dental practice, a clinical laboratory, a home health agency or a pharmacy: the word “dental” does not appear in it once. HHS also put two of the most-discussed provisions in its unquantifiable bucket and attached no dollar figure to either, namely the technology asset inventory and deploying encryption in a more concerted manner. If you have read that the rule adds a fixed percentage to your budget, that percentage is not from HHS.

Status: still a proposal. The comment period closed on 7 March 2025 and no final rule had been published as at July 2026. HHS's Unified Agenda moved the rule to Long-Term Actions and now projects final action in July 2027, having previously projected May 2026. Source: 90 FR 898, 6 January 2025, the proposed rule on the Federal Register.

The proposals, provision by provision

What non-compliance costs, as published

OCR publishes every resolution agreement and civil money penalty it concludes. The amounts span orders of magnitude, so this site quotes them individually rather than averaging them into a number that would describe no real organisation.

Published actionAmountTypeDate
Montefiore Medical Center$4,750,000SettlementFeb 2024
Heritage Valley Health System$950,000SettlementJul 2024
BayCare Health System$800,000SettlementMay 2025
Assured Imaging$375,000SettlementApr 2026
Oregon Health & Science University$200,000Civil money penaltyDec 2024
MMG Fusion$10,000SettlementMar 2026

A settlement is not a civil money penalty, and the distinction matters. A resolution agreement is a negotiated settlement with a corrective action plan and no admission of liability, and it is how nearly all OCR enforcement concludes. A civil money penalty is imposed under the statutory tier structure and can be contested before an administrative law judge. Note the range: MMG Fusion settled at $10,000 in March 2026 despite a breach affecting 15 million individuals, which is why an average of these would tell you nothing. A missing or inadequate security risk analysis is the common thread through nearly all of them.

The four-tier penalty structure and the full published record →

Frequently Asked Questions

How much does HIPAA compliance cost?
There is no honest single number, and this site does not print one. The reason is structural rather than coy: a HIPAA programme is part licence and part engagement, and only the licence half has published prices. You can price the compliance platform, the identity and endpoint tooling, and the cloud services from the vendors' own rate cards, because those vendors publish. You cannot price the risk analysis, the policy work, the penetration test or the counsel time, because every firm that sells those quotes them per engagement against your scope and none publishes a rate card. That unpriced half is usually the larger one. Any all-in figure you are shown, on this site or any other, is somebody's estimate of those quotes rather than a market rate, and this site removed its own rather than keep it behind a label.
Is there a HIPAA certification I can buy?
No. HHS is explicit about this in its own FAQ: there is no standard or implementation specification requiring a covered entity to certify compliance, HHS does not endorse or otherwise recognize private organizations' certifications regarding the Security Rule, and obtaining an external certification does not preclude HHS from later finding a violation. What 45 CFR 164.308(a)(8) actually requires is a periodic evaluation, which may be internal or external. This matters commercially, because certification is what a good deal of HIPAA marketing implicitly sells. A vendor may audit you against HIPAA and issue you a document, and that document is the vendor's opinion rather than a status HHS recognises.
What does HHS itself say the 2026 Security Rule proposal would cost?
HHS priced its own rule, and the figures are in the proposal's regulatory impact analysis at 90 FR 898. It estimates approximately $9 billion in first-year costs and roughly $6 billion annually in years two through five, against a denominator of 1,822,600 regulated entities. The only per-entity figure it publishes is approximately $1,235 in annualized cost per regulated entity, and HHS notes that per-entity costs represent costs per establishment. That $1,235 is flat: it carries no breakdown by clinical segment and no differentiation by organisation size. The RIA's real dimension is by provision, nationally, and HHS explicitly declined to quantify two of the most-discussed provisions, attaching no dollar figure to either the technology asset inventory or to encryption. Any claim that the rule adds a specific percentage to your budget is not from HHS, because HHS published no such percentage.
What do OCR enforcement actions actually cost?
OCR publishes every resolution agreement and civil money penalty it concludes, which makes this one of the few areas of HIPAA cost with a genuine public record. The published amounts span orders of magnitude, so this site quotes them individually rather than averaging them. Recent examples: four ransomware resolutions announced on 24 April 2026 totalling $1,165,000, the largest of them Assured Imaging at $375,000; MMG Fusion at $10,000 in March 2026 despite a breach affecting 15 million individuals. Larger historical actions include Montefiore Medical Center at $4,750,000 and Heritage Valley Health System at $950,000. A settlement is not a civil money penalty: a resolution agreement is a negotiated settlement with a corrective action plan and no admission of liability, and it is how nearly all OCR enforcement concludes.
What actually drives the size of the bill?
Workforce headcount rather than clinician count, because training licences, identity governance and the per-employee fees platforms charge all meter on workforce. Then: the number of systems in scope, which drives the risk analysis more than headcount does; the number of physical sites; how many vendors touch PHI, which sets your BAA count; whether you are a covered entity or a business associate, which changes which Privacy Rule obligations apply at all; and whether your privacy and security officer roles are dual-hat or dedicated, which is usually the single largest swing because it is a headcount decision rather than a licence. Programme maturity matters too: a first-year build and an annual refresh are different engagements, and conflating them is how published cost ranges get their implausible width.
What is the most common HIPAA failure?
The risk analysis, and OCR has made this explicit rather than leaving it to inference. Its Risk Analysis Initiative focuses selected investigations on the Security Rule risk analysis provision, which OCR describes as the foundation for effective cybersecurity and the protection of ePHI. Reading the published resolution agreements, the same gaps recur: a risk analysis that is missing, stale or a generic template rather than an assessment of the actual environment; BAAs missing or expired for vendors that handle PHI; and audit logs the system captures faithfully and nobody ever reviews. All three are process failures rather than spending failures, which is why more tooling does not fix them.
Does an existing SOC 2 reduce HIPAA cost?
It helps, and this site does not put a percentage on it because no authority publishes one. OCR, NIST, AICPA, HITRUST and the PCI Security Standards Council are the bodies that did the mapping work, and every one publishes relationships rather than ratios. The mechanism is real and explainable without a number: shared control testing, a single evidence-collection pass, one fieldwork mobilisation, aligned observation windows and common readiness work. The limits are equally real. The Privacy Rule, the Notice of Privacy Practices, the minimum necessary standard and patient rights are HIPAA-specific and have no SOC 2 counterpart, so that work is still discrete whatever your existing posture.
Can a small practice do this without a consultant?
Often, yes, and the platform layer is the part with published prices. Compliancy Group and Accountable HQ both publish full rate cards and provide guided workflows, policy templates and training modules. OCR also publishes its own training materials free of charge, and states that it does not certify any materials or services provided by private sector entities as HIPAA compliant. What a platform does not do is perform your risk analysis: it gives you the workflow and the evidence store, and the assessment of your actual environment is still work someone has to do. That is the line where practices most often decide to bring in help, and it is also the line OCR investigates most.

Updated 2026-07-17