Methodology
How HIPAAComplianceCost.com sources its numbers, what is in scope and what is out of scope, the refresh cadence, and the corrections process. Every figure on the site is one of three things, and the site tells you which: published and cited to the surface that published it, our own labelled arithmetic over inputs you can see and redo, or deliberately absent with the reason stated. It is not the case that every number here is a published external fact, and the site does not claim it is.
01. Primary and named sources
The site relies on a small set of primary regulatory sources, industry cost reports, and named vendor pricing pages. Where two sources disagree, the primary source (HHS / OCR / NIST / Federal Register) takes precedence and the secondary source is shown for context.
| Source | Cadence | What we take |
|---|---|---|
| HHS HIPAA Rules | On rule change | Canonical text of the Privacy, Security, and Breach Notification Rules. Used for the requirements checklist on /requirements, the rule-by-rule framing on cost-component pages, and the addressable-vs-required distinction discussed on /2026-rule-changes. |
| OCR Compliance and Enforcement | Quarterly | Resolution Agreements, civil monetary penalties, and the published list of recent settlements. Used for the four-tier penalty structure, average-settlement figures, and enforcement examples cited on /penalties. |
| OCR Civil Monetary Penalty inflation notice | Annual | Annual inflation-adjusted penalty amounts published in the Federal Register. Used for the per-violation minimums and the annual cap by tier shown on /penalties. The 2026 figures cited are the most recent OCR inflation-adjusted notice. |
| NIST SP 800-66 Rev. 2 | On revision | Implementing the HIPAA Security Rule. The canonical risk-assessment methodology reference. Used for the assessment-phase framing on /risk-assessment-cost (scope definition, asset inventory, threat ID, vulnerability assessment, risk scoring, remediation planning). |
| Federal Register HIPAA Security Rule NPRM 2024-30983 | On NPRM update / final rule | Proposed text of the 2026 Security Rule update, and its regulatory impact analysis at Section V. Used for the changes listed on /2026-rule-changes and for HHS's own cost estimates: roughly $9 billion in first-year costs across 1,822,600 regulated entities, and approximately $1,235 in annualized cost per regulated entity. That per-entity figure is flat: the RIA contains no breakdown by clinical segment and no dollar figure for the asset-inventory or encryption provisions. Tracked against the comment-period and final-rule publication timeline. |
| IBM Cost of a Data Breach Report 2026 (healthcare segment) | Annual | Average healthcare data breach cost ($6.64M in the 2026 report, down 10.5% from $7.42M in 2025, still the highest of any industry for the thirteenth year running) and the cost-of-non-compliance framing on the homepage and /penalties. This is the one industry report this site cites, and it is cited for one figure that IBM measures directly, not as a general-purpose benchmark. |
| Cloud provider pricing pages and the Azure Retail Prices API | Quarterly | Per-service list prices for the security services a HIPAA workload runs: AWS KMS, CloudTrail, Config and GuardDuty; Google Security Command Center, Cloud KMS and Cloud Logging; Microsoft Defender for Cloud, Sentinel, Key Vault and Log Analytics. Azure figures come from Microsoft's own Retail Prices API rather than its pricing pages, which render their figures client-side and serve placeholders. These are separate published dimensions and are never summed into a headline. |
| Compliance-platform vendor pricing pages | Monthly | Named vendor pricing for Accountable, Compliancy Group, Sprinto, Secureframe, Vanta, and Medcurity, taken from each vendor's own published pricing page. Used for the platform pricing rows on /tools and the ongoing-monitoring cost-component row. |
| HHS Security Risk Assessment Tool | On HHS revision | HHS-published risk assessment tool for small and mid-size practices. Used for the self-assessment vs consultant-led framing on /risk-assessment-cost and as the lowest-cost option in the small-practice budget on /small-practice. |
02. In scope and out of scope
In scope
- Published vendor list prices for the licence half of a HIPAA budget: compliance platforms, identity and endpoint tooling, cloud security services and the three EHR vendors that publish, each attributed to the surface that published it and dated.
- The homepage worksheet, which supplies no rate of its own and totals only the rates the reader enters against quantities it derives from the scope and shows on screen.
- OCR-published settlement amounts and the four-tier civil monetary penalty structure with annual inflation adjustments.
- NIST SP 800-66 Rev. 2 derived risk-assessment scope (asset inventory, threat ID, vulnerability assessment, risk scoring, remediation planning).
- Per-employee HIPAA training cost ranges by delivery format (self-paced, interactive, instructor-led) with named LMS pricing.
- Compliance platform pricing taken from each vendor's own published pricing page.
- Proposed 2026 Security Rule cost impact, tracked against the Federal Register NPRM and updated on rule revisions.
Out of scope
- Enterprise-negotiated audit pricing and sales-led consultancy contracts that are not published on a public page.
- Internal salary-loaded rate estimates that depend on org-specific overhead, benefits, and benefit loading rules.
- Legal advice on specific HIPAA enforcement scenarios, breach notification timing, or BAA contract terms.
- Vendor-specific BAA contractual provisions, indemnity caps, and liability allocation clauses.
- State-law overlays (CMIA, Texas HB 300, NY SHIELD Act) that strengthen HIPAA in specific jurisdictions; brief mentions are flagged but not exhaustively priced.
- Foreign-jurisdiction healthcare privacy laws (GDPR, PIPEDA, DPA 2018) where they exceed HIPAA scope.
03. Calculation framework
Not every figure on the site is a published external fact, and the site does not claim it is. A published price is cited to its surface and dated. Our own arithmetic, the homepage worksheet and the worked examples, is labelled as ours and built only from inputs the reader can see and redo. Where a price is quoted per engagement and published by nobody, the site prints no figure and says so. The cards below show how each cluster is handled.
The calculator holds no rate of its own. The reader enters a rate on each line, from a quote they hold or a published example shown beside it, and the tool multiplies it by a quantity it derives from the scope and shows on screen. The total is therefore the reader's own arithmetic over visible inputs, which anyone can redo. The engagement lines nobody publishes, the risk analysis, policy work, external audit and penetration test, stay open and count as zero until a quote is entered, so an incomplete total reads honestly as a floor. There is no site-supplied first-year total anywhere in it.
Every vendor figure names where it was published and when we read it. AWS Marketplace listings for Drata, Vanta, Secureframe and Sprinto; vendors' own pricing pages for Accountable HQ and Compliancy Group; HITRUST's own guidance for MyCSF and readiness; eClinicalWorks, AdvancedMD and Practice Fusion for EHR. Where a vendor publishes a platform fee and a framework fee as separate lines and no combined total, we report the lines and leave the arithmetic to you. Where a figure is worded "starting at", it is reported as a floor.
The cloud pages and the tools page carry worked examples: a published per-unit rate times a quantity stated on screen, under an "Our arithmetic, not a vendor price" banner. Every input carries its surface and date, and the reader can redo the sum. Nothing in a worked example is adjusted, discounted or inflated by us, and no figure enters one unless the vendor published it.
No assessment firm publishes an audit or engagement fee, and this site prints none, on /audit-cost or anywhere else. No HIPAA consultant publishes an hourly rate. Epic, Oracle Health and MEDITECH publish no EHR price and no federal rule compels one. Medcurity directs buyers to a quote. Security Command Center Enterprise is contact-sales. In every case this site prints no figure and explains what drives the quote instead, which is the part you can act on.
The /2026-rule-changes page reports what HHS put against each provision in its own regulatory impact analysis and nothing more. It prints no percentage uplift and no per-size band, because HHS published neither: its impact analysis gives one flat per-entity figure with no size or segment breakdown and declines to quantify the asset-inventory and encryption provisions entirely. Every NPRM figure on the site is imported from a single source file so the pages cannot drift.
The /cross-framework page publishes no control-overlap percentage between HIPAA and SOC 2, ISO 27001 or PCI DSS, because no authority publishes one: OCR, NIST, AICPA, HITRUST and the PCI SSC publish relationships rather than ratios. It gives the published crosswalks (the 2016 OCR crosswalk, NIST SP 800-66 Rev. 2) and the mechanism by which a combined engagement costs less, and puts no number on that saving, because no assessment firm publishes a fee.
04. Refresh cadence
A full source pass runs on the first business week of each calendar month. The last full pass was July 2026. The verification date is held in a single constant (LAST_VERIFIED_DATE) imported by every page; footer text, schema dateModified, and visible headings all read from that one source, so a cosmetic date refresh is not possible without re-running the source pass.
Out-of-cycle refreshes are triggered by any of the following:
- OCR publishes a new inflation-adjusted civil monetary penalty notice in the Federal Register (annual, usually Q4).
- OCR publishes a new Resolution Agreement that materially changes the published average-settlement figure.
- HHS publishes a revision to or final-rule version of the 2026 Security Rule NPRM.
- A named vendor on /tools changes its pricing page (entry-tier or platform-tier price moves more than 10 percent).
- IBM publishes a new Cost of a Data Breach Report with an updated healthcare-segment figure.
- AWS, Microsoft or Google changes a published rate for one of the security services on the cloud pages.
- NIST publishes a revision to SP 800-66 or a new related healthcare-sector publication.
05. Limitations
Cost ranges on this site are budgeting and planning anchors, not quotes. A specific engagement quote depends on organisation specifics (number of locations, EHR systems, prior compliance posture, cloud footprint, existing SOC 2 or ISO 27001 evidence base) that cannot be captured in a published range.
This site publishes no average OCR settlement, on the home page or on /penalties. OCR does not publish one, and the resolutions it does publish run from $10,000 to eight figures across entities and failure modes with nothing in common, so an average of them would describe no real organisation. What OCR does publish is every resolution agreement and civil money penalty individually, which makes enforcement one of the few areas of HIPAA cost with a genuine public record. We quote the cases, name the entity and the date, keep resolution agreements distinct from imposed civil money penalties, and suggest you read the ones that match your size and failure mode.
The 2026 Security Rule cited on /2026-rule-changes is still in proposed status. The final rule, when published, may differ in scope (specific safeguards) or timing (compliance deadline) from the NPRM. The site flags this uncertainty on the page itself and is updated when HHS publishes a substantive revision or the final rule.
06. Corrections process
Spotted a stale number, a missing tier, an OCR settlement we have not caught yet, a NIST publication revision, or a 2026 Security Rule change after final publication? Email [email protected] with the page URL, the source you would like cited, and a brief note on what should change. Substantive corrections are typically actioned within five business days, with a note in the page footer on substantive amendments.
For broader site-level questions or editorial position, see the about page.