How Much Does a HIPAA Security Risk Assessment Cost?

Quick answer: A HIPAA Security Risk Analysis can
cost anywhere from $0 in cash (the free HHS tool, paid for in staff
hours) to five figures for a consultant-led engagement at a large
multi-site organization. Software sits in between: Medcurity’s
self-service Small Practice SRA starts at $499 per year
for practices under 20 staff, and larger organizations are scoped to
workforce size and site count. Anyone who quotes you one number for “the
cost of an SRA” without asking how many sites, systems, and vendors you
have is guessing.

The honest way to think about SRA cost is three routes, each real,
each right for someone.

Route 1: The
free HHS tool — $0 in cash, paid in hours

HHS and ONC publish a Security Risk Assessment Tool at no cost. It is
a real tool, and for a genuinely small single-provider practice with no
software budget, it is an adequate and legitimate choice — paying for
software instead is not automatically the better decision at that
size.

What the sticker price hides is the labor: expect 20–60+ staff hours
per assessment, with no risk scoring, no remediation tracking, and no
audit trail. Someone in your practice becomes the methodology, the
documenter, and the follow-up system. If your staff time is scarce — and
in most practices it is the scarcest thing there is — “free” is the most
expensive line in the budget.

Best for: solo practitioners who can trade hours for
dollars and are comfortable defending their own documentation if OCR —
the HHS Office for Civil Rights — ever asks.

Route
2: SRA software — transparent entry, scoped from there

Purpose-built SRA software gives you the methodology, scoring,
remediation tracking, and audit trail the free tool lacks, at a fraction
of consultant cost.

Here is where we can be concrete about our own pricing, because we
publish it:

Most of the category does not publish anything. The common pattern
among HIPAA compliance vendors is quote-only pricing — a demo, a
discovery call, then a number. We are not going to invent competitor
figures here, because we do not know them and neither does anyone else
writing “pricing comparison” posts. What we can say is that a
transparent entry point exists, and you are reading it.

Best for: small practices through multi-site groups,
FQHCs, and hospitals that want a defensible, tracked, human-reviewed SRA
without a six-figure enterprise engagement.

Route 3: Consultant-led
engagements

At the top of the market, consultant-led engagements pair the
analysis with governance work: interviews, walkthroughs, formal
deliverables, sometimes a standing advisory relationship. For a large
integrated delivery network with an enterprise risk function, that model
fits, and it is priced like the professional-services engagement it is —
typically quoted per engagement, scaling with scope.

Note that this is not strictly either/or. Medcurity’s guided SRA
includes consultant-grade elements — an onsite physical safeguard
assessment under 45 CFR §164.310, a named advisor year-round, and HIPAA
expert review of every guided SRA before it is finalized — inside a
software subscription rather than a bespoke engagement.

Best for: enterprise health systems with dedicated
CISO functions and formal enterprise risk governance.

What actually drives the
number

Whatever route you take, five variables move SRA cost more than
anything else:

  1. Workforce size — more people means more systems,
    more access to review, more training exposure.
  2. Number of sites — each physical location adds
    facility-level physical safeguard review.
  3. Vendor count — every business associate with ePHI
    access belongs in the risk analysis.
  4. Onsite vs. remote — a walkthrough of your actual
    facilities costs more than a questionnaire and catches what a
    questionnaire cannot.
  5. What you already have — current policies, MFA,
    encryption, and training reduce the remediation half of the bill.

The cost of getting it wrong

The comparison that matters is not free-tool-versus-software. It is
any-of-the-above versus an inadequate SRA. Organizations with weak or
missing risk analyses have faced OCR settlements commonly running into
six figures per investigation — before remediation costs, legal fees,
and breach notification. Since OCR’s Risk Analysis Initiative launched
in late 2024, the risk analysis itself has been the center of
enforcement. An SRA that does not hold up is the most expensive kind
there is.

Where to go from here

Medcurity has served 1,000+ healthcare organizations since 2018,
rated 4.92/5, with a 100% Security Risk Analysis acceptance rate with
the HHS Office for Civil Rights.