HIPAA Risk Assessment Cost in 2026
The risk analysis is the most enforced provision in OCR's published record, the first thing asked for in an investigation, and the one line no compliance platform performs for you. It is also the line with no published price anywhere, because every firm that sells it quotes per engagement.
This page prints no assessor fee. What it gives you instead is the free government tool that performs one, what the obligation actually requires, and the variables an assessor prices against.
Why there is no price here
No firm that performs HIPAA risk analyses publishes a rate card. Not one. They quote against your scope, and scope is the thing that varies most between two organisations of the same size, which is exactly why a rate card would be useless to them and a benchmark is useless to you. This page used to carry a four-by-three matrix of assessment fees, and every cell was an estimate of somebody else's quote rather than a figure anyone published. It is gone rather than relabelled, because a guess at a third party's price is not a model and calling it one puts a respectable word where a citation belongs.
The government publishes a free tool for this
ONC developed the Security Risk Assessment Tool in collaboration with the HHS Office for Civil Rights, and publishes it at no charge as a downloadable desktop application, with an Excel workbook alternative for systems it does not run on. It walks you through threat and vulnerability assessment and asset management using a wizard-based approach, and produces reports you can save and print. Your data stays local to your machine.
Two limits, both stated by ONC and both worth respecting. It says the target audience is medium and small providers, and that use of the tool may not be appropriate for larger organisations. And its disclaimer states that use of the tool is neither required by nor guarantees compliance with federal, state or local laws. That second one is not boilerplate: it is the same position HHS takes on certification generally, and it means no tool and no vendor can hand you compliance as a status.
For a small practice this genuinely sets the floor of this line at $0. The cost that remains is your own time, and the discipline to answer honestly about an environment you already know.
NIST also publishes SP 800-66 Rev. 2 (February 2024) free, a resource guide for implementing the Security Rule, whose Appendix D crosswalk has moved into the free NIST Cybersecurity and Privacy Reference Tool. Between them, the two things a small practice most often pays a consultant for, a method and a structure, are published by the government at no charge.
What the rule actually requires
45 CFR 164.308(a)(1)(ii)(A) requires you to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate. It is a Required implementation specification rather than an Addressable one, so there is no route to documenting why you did not do it. It applies identically to business associates.
Note the two adjectives, because they are what OCR's findings turn on. Accurate means it describes your environment rather than a generic one, which is why a template filled in for somebody else's practice fails on its own terms with every box ticked. Thorough means it covers the ePHI you actually hold, including the systems that were not on the list. The rule states no interval, but an assessment describing an environment you no longer run stops being accurate, which is what makes this recurring in practice.
What a risk analysis involves
Scope definition
Identify every system, application and data flow that creates, receives, maintains or transmits ePHI. This sets the boundary for everything else, and it is where assessments most often go wrong: the system nobody listed is the one that shows up in a breach.
Asset inventory
Document the hardware, software and network components in scope. The 2026 proposal would make this a standalone deliverable with network maps, and HHS's own view is that it is already a baseline expectation of the risk assessment you owe today.
Threat identification
Catalogue internal threats, including negligent and malicious workforce members, and external ones, including ransomware, phishing and physical intrusion. The four ransomware resolutions OCR announced in April 2026 are a reasonable place to calibrate what external looks like now.
Vulnerability assessment
Technical scanning of networks, endpoints and applications, plus administrative review of policies, procedures and training gaps. Both halves count: a policy that exists and is not followed is a vulnerability.
Risk scoring
Rate each threat and vulnerability pair by likelihood and impact, and output a prioritised risk register. This is the artefact that drives your remediation budget, and the one an investigator reads most closely.
Remediation planning
Specific actions, named owners, timelines. This is the bridge between the assessment and the rest of your budget, and an assessment without it is an observation rather than a plan.
Documentation
Retained six years under 45 CFR 164.316(b)(2)(i). In practice this is the deliverable: if you cannot produce it, the work did not happen as far as an investigation is concerned.
What an assessor actually prices against
Since there is no rate card to read, the useful thing is knowing the variables a quote is built from. Brief against these and you will get comparable quotes from different firms, which is more valuable than any benchmark this page could print.
Systems in scope
The dominant driver, and it is not headcount. One cloud EHR is a far smaller assessment than an EHR plus a legacy archive plus three specialty systems. Two organisations of identical size can differ by a multiple on this alone.
Sites
Each physical location adds network and physical safeguards to evaluate, and typically a separate walk-through.
Deployment model
A cloud-hosted estate under a vendor BAA is a different assessment from on-premises infrastructure you own end to end. Neither is automatically cheaper; they are different work.
Programme maturity
A first assessment from nothing and a refresh of a maintained programme are different engagements. Conflating them is how published cost ranges get their implausible width.
Whether a pen test is in scope
Frequently bundled into an assessment quote and frequently not. It is a separate discipline with separate specialists, and it is the line most likely to move a quote sharply.
Who does the internal work
Someone on your side has to answer the questions, find the documentation and walk the assessor round. That time never appears on the invoice and is often the largest real cost.
Why this line matters more than the others
OCR runs a Risk Analysis Initiative, focusing selected investigations on this specific provision, which it describes as the foundation for effective cybersecurity and the protection of ePHI. That is the regulator telling you in advance where it will look, which is unusual and worth acting on.
The published record bears it out. Reading OCR's resolution agreements, a missing, stale or generic risk analysis is the common thread through nearly all of them, at every scale. In OCR's May 2025 settlement with BayCare Health System at $800,000, the findings included no role-based access limits, no routine log review and no risk analysis. None of those three is a purchasing gap. Each is something the organisation already had the tools to do and did not do, which is the pattern: the expensive HIPAA failures are process failures rather than spending failures, and more tooling does not fix them.
It is also the line no platform discharges. A platform gives you the workflow and the evidence store; it does not know what is in your server room. See penalties and enforcement for the full published record and the tools comparison for what the platforms do and do not include.
What the 2026 proposal would add
A technology asset inventory with network maps as a standalone requirement, vulnerability scanning every six months, and annual penetration testing. This page prints no cost impact for those, because HHS published none: it placed the asset inventory in its unquantifiable bucket with no dollar figure attached, calling it a baseline expectation for the existing requirement of conducting a risk assessment, and there is no vulnerability-scanning cost line anywhere in its analysis. Penetration testing it did price, at a $656M national first-year total with a published sensitivity range from $437M to $2,186M. The rule remains a proposal with no final text and no compliance date. Source: 90 FR 898, 6 January 2025, the proposed rule on the Federal Register. See the 2026 rule changes.
How to spend less on this
Maintain an asset inventory year-round
An assessor who starts with an accurate inventory is not billing you to build one. The mechanism is obvious, no firm publishes what it is worth, and this page therefore puts no percentage on it. HHS's own framing is that the inventory is a baseline expectation of the assessment you already owe, so this is work you are not avoiding by deferring.
Use the free tools first
The ONC and OCR Security Risk Assessment Tool and NIST SP 800-66 Rev. 2 are published free. Even if you ultimately hire an assessor, arriving with a completed structured self-assessment narrows what you are paying them to do, from discovery to challenge.
Brief against the drivers, not the price
Give every firm the same scope: systems, sites, deployment model, whether a pen test is included. Quotes that are not built on the same scope are not comparable, and scope is where the difference lives.
Ask about bundling
Combining the assessment with an audit or another framework's fieldwork does cost less than running them apart, through shared control testing, one evidence-collection pass and a single mobilisation. No assessment firm publishes an engagement fee, bundled or separate, so this page prints no saving figure. Ask each firm to quote both ways and compare their own numbers.