How Much Does a HIPAA Risk Analysis Cost?
As of August 2026, the published prices for a consultant-led HIPAA security risk analysis run from about $2,000 to $25,000 and up. Patient Protect puts a light one-time engagement with a documented deliverable at $2,000 to $6,000, and a multi-week engagement with on-site days at $8,000 to $25,000 or more. Medcurity puts an external consultant at $5,000 to $25,000 or more for a medium-sized practice. Both companies sell HIPAA compliance software that competes directly with the consultant they are pricing, so read their numbers accordingly. The free option is genuinely free: the Security Risk Assessment Tool that ONC built with the HHS Office for Civil Rights costs nothing, and its current release is version 3.6.1, updated May 28, 2026.
So the honest answer to "what does it cost" is that the analysis is nearly free and the evidence is not. What follows is what the regulation actually demands, why the published range spans an order of magnitude, where the free tool stops, and what OCR's enforcement record says the finished document has to survive.
Key takeaways
- Published consultant ranges as of August 2026: $2,000 to $6,000 for a light engagement and $8,000 to $25,000 or more for a multi-week one (Patient Protect), or $5,000 to $25,000 or more for a medium practice (Medcurity). Both sources sell competing software.
- ONC and OCR's Security Risk Assessment Tool costs nothing, is at version 3.6.1 as of May 28, 2026, and is aimed at small and medium providers. It does produce a report; what it cannot produce is an independent opinion.
- The Security Rule requires an "accurate and thorough assessment" but prescribes no methodology, which is exactly why prices vary this much.
- Scope drives the number more than anything a vendor can tell you over the phone: the count of systems that create, receive, maintain, or transmit ePHI is the estimate.
- The enforcement record is the reason to spend anything at all. OCR's settlement with BST & Co. CPAs was $175,000 and was announced as the tenth enforcement action in its Risk Analysis Initiative.
What the Security Rule requires, and what it deliberately refuses to specify
The obligation is one sentence long. At 45 CFR 164.308(a)(1)(ii)(A), risk analysis is a Required implementation specification, and it reads: "Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate."
Two words in that sentence are doing all the work. Accurate. Thorough. Neither is defined in the regulation, and HHS's own Guidance on Risk Analysis says plainly that the Security Rule does not prescribe a specific risk analysis or risk management methodology. The same guidance sets the scope wide: the analysis covers the potential risks and vulnerabilities to the confidentiality, availability and integrity of all ePHI a regulated entity creates, receives, maintains, or transmits.
Notice what that combination produces. A fixed, mandatory, audited deliverable with no prescribed form. That is a market where price cannot converge, because two vendors quoting the same words are not selling the same thing.
The paired requirement matters as much. Risk management at 164.308(a)(1)(ii)(B) is also Required: "Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level." An analysis with no remediation behind it documents that you looked and did nothing, which is a worse position than not having looked.
Why the published range spans an order of magnitude
Scope. Not rigor, not seniority, not brand. Scope.
Medcurity's own breakdown by practice size makes the shape visible: first-year total HIPAA compliance spend of $5,000 to $15,000 for a small practice of one to ten providers, $15,000 to $40,000 for eleven to fifty, and $40,000 to $100,000 or more for organizations above fifty. Those are whole-program numbers rather than risk-analysis line items, and again the source sells a platform. But the slope is the useful part. Each tier is roughly triple the one below it, and headcount is the proxy for the thing that actually costs money, which is the number of systems that touch ePHI.
Build the estimate the same way an assessor will. Count your production systems that create, receive, maintain, or transmit ePHI. Count the third parties that do the same on your behalf. Count the physical locations and the exception paths, the workstation that still has a local export folder, the analytics pipeline someone stood up last spring. A single-location practice on one hosted EHR might have four things on that list. A health tech company with a customer-facing app, a data warehouse, a support tool, four subprocessors and a mobile client has thirty.
The consultant is pricing that list, whether or not they ask you for it. If you hand them the list before they quote, two things happen: the quotes become comparable, and the ones that were going to discover scope in week three stop being able to.
The free tool is real, and so is its ceiling
We are going to argue against our own line of work for a paragraph, because the SRA Tool deserves it.
It is free. It is built by ONC in collaboration with OCR, which means the questions track what the regulator actually asks. It walks the safeguard set, it produces a report, and for a small provider with a hosted EHR and a handful of workstations, it is very likely all you need. Anyone telling a two-physician practice that a compliant risk analysis requires a five-figure engagement is selling.
Now the ceiling, in ONC's own words. The tool "is neither required by nor guarantees compliance with federal, state or local laws," it "is not intended to serve as legal advice," and it targets "medium and small providers; thus, use of this tool may not be appropriate for larger organizations." Read that last clause literally. It is not a disclaimer for lawyers. It describes a design boundary.
Three things the tool cannot do, and these are what you are paying for when you pay:
- It cannot find the ePHI you forgot. It asks you about your systems. If the analytics pipeline is not on your list, it is not in your risk analysis, and the gap is invisible until someone breaches it.
- It cannot test whether a control is real. It records that you say access reviews happen. An assessor pulls last quarter's access review and reads it.
- It cannot produce an independent opinion. An enterprise customer's vendor review, and an OCR investigator, both weigh a self-completed questionnaire differently from a report with a named methodology, a scope statement and findings someone else signed.
If none of those three matter for your organization yet, use the tool and put the money somewhere else.
Working the arithmetic instead of accepting a quote
Vendor pricing pages are worth reading as arithmetic rather than as prices.
Patient Protect's software tier is $39 to $99 a month. Over three years that is $1,404 to $3,564, against the $2,000 to $6,000 they quote for a single light consultant engagement: below the consultant ceiling at both ends, and below the consultant floor at the cheap end. So the platform-versus-consultant question is not which is cheaper. It is over what period, and the arithmetic will not give you a single answer. The platform runs $468 a year at the bottom of that tier and $1,188 a year at the top, so matching the low end of one range against the low end of the other puts the crossover past year four, and matching the two high ends puts it just past year five. Pair opposite ends instead and it moves anywhere from under two years to beyond twelve. Read that spread as a reason to ask what each option actually delivers rather than as a break-even date to plan around.
Medcurity's numbers are more symmetrical than they look. Their platform tier is $1,000 to $5,000 a year; their external consultant line is $5,000 to $25,000 or more. Bottom to bottom, that is five years to break even. Top to top, also five years. When a pricing page's ratios come out that clean at both ends, you are looking at positioning rather than measurement, which does not make it wrong, but it does mean you should not treat the endpoints as observations.
Then price the part nobody invoices. Whichever route you take, someone internal assembles the system inventory, chases the subprocessor list, produces evidence of the controls, and writes the remediation plan. That work exists in all three options, it is the largest single input to the total, and it is the reason a cheap engagement can cost more than an expensive one: an assessor who does not push you to produce the inventory will happily assess the environment you described rather than the one you run.
What OCR's enforcement record says the deliverable has to survive
This is the part that turns a compliance chore into a budget line.
OCR runs a Risk Analysis Initiative, an enforcement effort that focuses selected investigations specifically on the risk analysis provision. It is not subtle about the count. The settlement with BST & Co. CPAs, LLP was $175,000, and OCR's announcement described it as the tenth enforcement action in the initiative. On April 23, 2026, OCR announced four ransomware settlements at once, totaling $1,165,000, covering breaches that affected more than 427,000 individuals, and noted that these brought the initiative to thirteen completed investigations.
Run the comparison. $175,000 is seven risk analyses at $25,000, the top of Medcurity's external-consultant range, or roughly twenty-nine at the $6,000 top of Patient Protect's light-engagement range. The four April settlements average $291,250 each. No serious version of this purchase is expensive relative to that.
But note carefully what OCR keeps citing, because it is not the absence of a document. The finding in these cases is the failure to conduct an accurate and thorough risk analysis: the analysis that existed but covered the wrong scope, or was never updated when the environment changed. A cheap analysis that produces a binder is not protective. An honest one that names your real gaps and is followed by remediation is, and the second half of that sentence is where most of the value sits.
If you want the regulatory context for where the rules are heading, our piece on the status of the proposed HIPAA Security Rule overhaul covers what is and is not enforceable today. Nothing in that proposal changes the risk analysis obligation you already have.
When you should not pay anyone for this
Three cases where we would tell you to keep your money.
You are a small provider with a hosted EHR and no custom software. Use the SRA Tool. Do it properly, take a day over it, document the decisions, and repeat it annually or after any material change. That is a compliant risk analysis. Paying $8,000 for someone to run the same questionnaire on your behalf buys a logo on the cover.
You already hold a current SOC 2 Type II covering your ePHI systems. Much of the underlying evidence is already assembled and tested. What you usually need is a mapping exercise showing how the trust services criteria you evidence line up against the Security Rule safeguards, not a second full assessment. We make this same argument in our piece on whether HIPAA certification exists, and it costs us assessment work every time.
You are pre-product with no ePHI in production. There is nothing to analyze yet. Write the data-flow map you will need later, execute your BAAs, and come back when real data lands.
The case for paying is narrower and more specific than the market implies: you have ePHI in systems you built, a customer or regulator who will read the output, or a previous analysis that you already suspect does not match the environment you run.
Where Top Floor fits
We do risk analysis, remediation planning and the ongoing program work under our HIPAA practice, the independent assessment and report work under audit and assurance, and the continuing-program version of it under Compliance as a Service. If you want to sketch the budget before talking to anyone, our budget planner will get you a range to argue with.
What we will not do is quote you a number before we have seen your system inventory, because the inventory is the estimate. Any firm that prices a HIPAA risk analysis off a headcount and a phone call is pricing a template.
How to decide this week
Open your last risk analysis and check two things: the date on it, and whether the systems it names are the systems you actually run today. If it is older than a year, or it predates your last significant architecture change, it is stale, and stale is the specific defect OCR keeps citing.
Then write the inventory yourself before you call anyone. Every system that creates, receives, maintains, or transmits ePHI, every subprocessor that does the same, every location. An afternoon of work, and it converts every quote you receive into a comparable number.
Then pick the smallest option that clears your actual constraint. No enterprise customer reading the output and no custom software means the free tool. A customer security review or an environment you built yourself means an independent assessment. Anything in between usually means a light engagement plus your own remediation work, which is the tier the market is worst at selling because it bills the least.
Frequently asked questions
Is a HIPAA risk analysis required by law?
Yes. Risk analysis is a Required implementation specification under 45 CFR 164.308(a)(1)(ii)(A), which obliges covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of the ePHI they hold. Required means there is no option to document why you skipped it, unlike the addressable specifications elsewhere in the Security Rule. The paired risk management specification at 164.308(a)(1)(ii)(B) is also Required, so an analysis with no remediation behind it does not satisfy the pair.
Can we use the free HHS Security Risk Assessment Tool instead of hiring someone?
Often, yes. The SRA Tool is free, was developed by ONC in collaboration with OCR, and is at version 3.6.1 as of May 28, 2026. ONC states that it is aimed at medium and small providers and that it may not be appropriate for larger organizations, and that it is neither required by nor guarantees compliance with any law. For a small practice on a hosted EHR it is a legitimate way to meet the requirement. Its limits are that it assesses the systems you tell it about, it records assertions rather than testing controls, and it produces a self-completed questionnaire rather than an independent report.
How often does a HIPAA risk analysis need to be updated?
The Security Rule does not name an interval, and HHS's guidance describes risk analysis as an ongoing process rather than a one-time exercise: regularly reviewing records, periodically evaluating whether security measures still work, and re-evaluating risks as things change. In practice the working rule is annually, plus immediately after any material change such as a new product, a new subprocessor, a merger, a cloud migration, or a breach. The version that gets organizations into trouble is the one that was accurate three architectures ago.
What makes OCR consider a risk analysis inadequate?
Scope and staleness, far more often than absence. OCR's Risk Analysis Initiative settlements repeatedly cite a failure to conduct an accurate and thorough assessment of the risks and vulnerabilities to all of the ePHI an organization holds, which in practice means an analysis that missed systems, missed a whole class of data, or was never refreshed after the environment changed. The settlement with BST & Co. CPAs, LLP was $175,000 and was announced as the tenth enforcement action in the initiative; by the four ransomware settlements announced on April 23, 2026, totaling $1,165,000, OCR counted thirteen completed investigations under it.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.