This site provides independent HIPAA compliance cost estimates for informational purposes only. We are not affiliated with HHS, OCR, or any compliance vendor. This is not legal or regulatory advice. Consult a qualified HIPAA compliance professional for guidance specific to your organization.

HIPAA Risk Assessment Cost in 2026

The risk analysis is the most enforced provision in OCR's published record, the first thing asked for in an investigation, and the one line no compliance platform performs for you. It is also the line with no published price anywhere, because every firm that sells it quotes per engagement.

This page prints no assessor fee. What it gives you instead is the free government tool that performs one, what the obligation actually requires, and the variables an assessor prices against.

Why there is no price here

No firm that performs HIPAA risk analyses publishes a rate card. Not one. They quote against your scope, and scope is the thing that varies most between two organisations of the same size, which is exactly why a rate card would be useless to them and a benchmark is useless to you. This page used to carry a four-by-three matrix of assessment fees, and every cell was an estimate of somebody else's quote rather than a figure anyone published. It is gone rather than relabelled, because a guess at a third party's price is not a model and calling it one puts a respectable word where a citation belongs.

The government publishes a free tool for this

ONC developed the Security Risk Assessment Tool in collaboration with the HHS Office for Civil Rights, and publishes it at no charge as a downloadable desktop application, with an Excel workbook alternative for systems it does not run on. It walks you through threat and vulnerability assessment and asset management using a wizard-based approach, and produces reports you can save and print. Your data stays local to your machine.

Two limits, both stated by ONC and both worth respecting. It says the target audience is medium and small providers, and that use of the tool may not be appropriate for larger organisations. And its disclaimer states that use of the tool is neither required by nor guarantees compliance with federal, state or local laws. That second one is not boilerplate: it is the same position HHS takes on certification generally, and it means no tool and no vendor can hand you compliance as a status.

For a small practice this genuinely sets the floor of this line at $0. The cost that remains is your own time, and the discipline to answer honestly about an environment you already know.

The ONC Security Risk Assessment Tool →

NIST also publishes SP 800-66 Rev. 2 (February 2024) free, a resource guide for implementing the Security Rule, whose Appendix D crosswalk has moved into the free NIST Cybersecurity and Privacy Reference Tool. Between them, the two things a small practice most often pays a consultant for, a method and a structure, are published by the government at no charge.

What the rule actually requires

45 CFR 164.308(a)(1)(ii)(A) requires you to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate. It is a Required implementation specification rather than an Addressable one, so there is no route to documenting why you did not do it. It applies identically to business associates.

Note the two adjectives, because they are what OCR's findings turn on. Accurate means it describes your environment rather than a generic one, which is why a template filled in for somebody else's practice fails on its own terms with every box ticked. Thorough means it covers the ePHI you actually hold, including the systems that were not on the list. The rule states no interval, but an assessment describing an environment you no longer run stops being accurate, which is what makes this recurring in practice.

What a risk analysis involves

Scope definition

Identify every system, application and data flow that creates, receives, maintains or transmits ePHI. This sets the boundary for everything else, and it is where assessments most often go wrong: the system nobody listed is the one that shows up in a breach.

Asset inventory

Document the hardware, software and network components in scope. The 2026 proposal would make this a standalone deliverable with network maps, and HHS's own view is that it is already a baseline expectation of the risk assessment you owe today.

Threat identification

Catalogue internal threats, including negligent and malicious workforce members, and external ones, including ransomware, phishing and physical intrusion. The four ransomware resolutions OCR announced in April 2026 are a reasonable place to calibrate what external looks like now.

Vulnerability assessment

Technical scanning of networks, endpoints and applications, plus administrative review of policies, procedures and training gaps. Both halves count: a policy that exists and is not followed is a vulnerability.

Risk scoring

Rate each threat and vulnerability pair by likelihood and impact, and output a prioritised risk register. This is the artefact that drives your remediation budget, and the one an investigator reads most closely.

Remediation planning

Specific actions, named owners, timelines. This is the bridge between the assessment and the rest of your budget, and an assessment without it is an observation rather than a plan.

Documentation

Retained six years under 45 CFR 164.316(b)(2)(i). In practice this is the deliverable: if you cannot produce it, the work did not happen as far as an investigation is concerned.

What an assessor actually prices against

Since there is no rate card to read, the useful thing is knowing the variables a quote is built from. Brief against these and you will get comparable quotes from different firms, which is more valuable than any benchmark this page could print.

Systems in scope

The dominant driver, and it is not headcount. One cloud EHR is a far smaller assessment than an EHR plus a legacy archive plus three specialty systems. Two organisations of identical size can differ by a multiple on this alone.

Sites

Each physical location adds network and physical safeguards to evaluate, and typically a separate walk-through.

Deployment model

A cloud-hosted estate under a vendor BAA is a different assessment from on-premises infrastructure you own end to end. Neither is automatically cheaper; they are different work.

Programme maturity

A first assessment from nothing and a refresh of a maintained programme are different engagements. Conflating them is how published cost ranges get their implausible width.

Whether a pen test is in scope

Frequently bundled into an assessment quote and frequently not. It is a separate discipline with separate specialists, and it is the line most likely to move a quote sharply.

Who does the internal work

Someone on your side has to answer the questions, find the documentation and walk the assessor round. That time never appears on the invoice and is often the largest real cost.

Why this line matters more than the others

OCR runs a Risk Analysis Initiative, focusing selected investigations on this specific provision, which it describes as the foundation for effective cybersecurity and the protection of ePHI. That is the regulator telling you in advance where it will look, which is unusual and worth acting on.

The published record bears it out. Reading OCR's resolution agreements, a missing, stale or generic risk analysis is the common thread through nearly all of them, at every scale. In OCR's May 2025 settlement with BayCare Health System at $800,000, the findings included no role-based access limits, no routine log review and no risk analysis. None of those three is a purchasing gap. Each is something the organisation already had the tools to do and did not do, which is the pattern: the expensive HIPAA failures are process failures rather than spending failures, and more tooling does not fix them.

It is also the line no platform discharges. A platform gives you the workflow and the evidence store; it does not know what is in your server room. See penalties and enforcement for the full published record and the tools comparison for what the platforms do and do not include.

What the 2026 proposal would add

A technology asset inventory with network maps as a standalone requirement, vulnerability scanning every six months, and annual penetration testing. This page prints no cost impact for those, because HHS published none: it placed the asset inventory in its unquantifiable bucket with no dollar figure attached, calling it a baseline expectation for the existing requirement of conducting a risk assessment, and there is no vulnerability-scanning cost line anywhere in its analysis. Penetration testing it did price, at a $656M national first-year total with a published sensitivity range from $437M to $2,186M. The rule remains a proposal with no final text and no compliance date. Source: 90 FR 898, 6 January 2025, the proposed rule on the Federal Register. See the 2026 rule changes.

How to spend less on this

Maintain an asset inventory year-round

An assessor who starts with an accurate inventory is not billing you to build one. The mechanism is obvious, no firm publishes what it is worth, and this page therefore puts no percentage on it. HHS's own framing is that the inventory is a baseline expectation of the assessment you already owe, so this is work you are not avoiding by deferring.

Use the free tools first

The ONC and OCR Security Risk Assessment Tool and NIST SP 800-66 Rev. 2 are published free. Even if you ultimately hire an assessor, arriving with a completed structured self-assessment narrows what you are paying them to do, from discovery to challenge.

Brief against the drivers, not the price

Give every firm the same scope: systems, sites, deployment model, whether a pen test is included. Quotes that are not built on the same scope are not comparable, and scope is where the difference lives.

Ask about bundling

Combining the assessment with an audit or another framework's fieldwork does cost less than running them apart, through shared control testing, one evidence-collection pass and a single mobilisation. No assessment firm publishes an engagement fee, bundled or separate, so this page prints no saving figure. Ask each firm to quote both ways and compare their own numbers.

Frequently Asked Questions

How much does a HIPAA risk assessment cost?
Nobody publishes a price, and this page no longer prints one. Every firm that performs risk analyses quotes per engagement against your scope, and not one publishes a rate card, so any range you are shown, including the assessment-fee range this page used to carry, is somebody's estimate of other companies' quotes. What is genuinely free is the government's own tool: ONC, working with OCR, publishes a Security Risk Assessment Tool at no charge as a downloadable desktop application, aimed at small and medium providers. So the floor of this line is $0 for a practice small enough to use it, and the ceiling is whatever an assessor quotes you for a scope only you can describe. The useful move is not to find a benchmark but to understand what drives the quote, which is what the rest of this page is about.
Is there a free HIPAA risk assessment tool?
Yes, from the government. ONC developed the Security Risk Assessment Tool in collaboration with the HHS Office for Civil Rights, and it is available at no charge as a downloadable desktop application, with an Excel workbook alternative for non-Windows systems. It uses a wizard-based approach through threat and vulnerability assessment and asset management, and produces reports you can save and print. Data stays local to your machine. Two limits stated on the tool itself and worth taking seriously: ONC says the target audience is medium and small providers and that use of the tool may not be appropriate for larger organisations; and the disclaimer states that use of the tool is neither required by nor guarantees compliance with federal, state or local laws. It is a structured way to do the work and produce documentation, not a compliance certificate. Nothing is.
How often do you need a HIPAA risk analysis?
45 CFR 164.308(a)(1)(ii)(A) requires an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of the ePHI you hold. It does not state an interval. What makes it a recurring obligation in practice is 164.308(a)(8), which requires periodic evaluation, and the plain fact that an assessment describing an environment you no longer run is not accurate and thorough. So the trigger is material change rather than the calendar: a new EHR, a cloud migration, a merger or acquisition, a significant security incident, a new site. Most organisations settle on an annual cadence with re-assessment on those events, which is a defensible reading rather than a rule. A re-assessment is a smaller engagement than the first one, and how much smaller depends on how well you maintained the documentation in between.
Can I do the risk analysis myself?
For a small practice, often yes, and the government publishes the tool to do it with. The honest trade-off is not about defensibility on paper: OCR has never said a self-assessment is worth less than a consultant's, and its published findings turn on whether an assessment was done, was current and covered the real environment, rather than on who signed it. The trade-off is about whether you will actually do it properly. A structured questionnaire completed by someone who knows the environment and has time to be honest about it beats an expensive report describing a generic practice. What a consultant genuinely brings is scope challenge: they ask about the systems you forgot, which is precisely where OCR's findings live. This site publishes no consultant rate, because no consultant publishes one.
Does a compliance platform do the risk analysis for me?
No, and this is the most common misreading of what a platform is. Compliancy Group and Accountable HQ both publish full rate cards and both give you workflow, templates, tracking and an evidence store. What none of them does is assess your actual environment: the platform does not know what servers you have, which laptop the practice manager takes home, or that a legacy archive still holds records from a clinic you closed. It gives you somewhere to record the answer and it does not know the answer. That gap is why the risk analysis stays the most enforced provision in OCR's record even at organisations that bought a platform, and it is why a platform subscription is not a HIPAA programme.
What does the 2026 proposal change for risk assessments?
The proposal would add a technology asset inventory with network maps as a standalone requirement, vulnerability scanning on a six-month cadence and annual penetration testing. This page prints no cost impact for any of that, because HHS did not. In its own regulatory impact analysis at 90 FR 898, 6 January 2025, HHS placed the asset inventory in its unquantifiable bucket with no dollar figure, on the reasoning that it is a baseline expectation for the existing requirement of conducting a risk assessment; and there is no vulnerability-scanning cost line anywhere in the analysis. Penetration testing is priced, at a $656M national first-year total across all regulated entities, and it carries the only published sensitivity range in the document, from $437M to $2,186M, which is a five-fold spread. The rule is still a proposal with no final text and no compliance date.
What is actually in a risk analysis?
Scope definition, identifying every system and data flow that creates, receives, maintains or transmits ePHI. An asset inventory of the hardware, software and network components in that scope. Threat identification across internal threats such as negligent or malicious workforce members and external ones such as ransomware and phishing. Vulnerability assessment, technical and administrative. Risk scoring of each threat and vulnerability pair by likelihood and impact, producing a prioritised register. Remediation planning with owners and timelines. And documentation, which is what you will actually be asked to produce. OCR's guidance is that the analysis must be accurate and thorough and cover the ePHI you actually hold, which is why a generic template filled in for a practice that is not yours fails on its own terms even when every box is ticked.

Updated 2026-07-17