Skip the reading? Connect your stack and get a readiness score today. Plans from $79 a month, prices published.
The best HIPAA risk assessment tool for most small practices is the free one HHS already publishes, and the best one for a healthtech company is whichever platform keeps the analysis current after the first pass. That is the whole decision. The ONC and OCR Security Risk Assessment Tool costs nothing, follows the guidance closely, and is genuinely sufficient for a single-location provider with a simple environment. Organizations outgrow it for one reason, and it is not the quality of the questions: it produces an assessment and then stops, so remediation, evidence and the annual refresh all fall back on somebody remembering.
Most roundups in this category skip the free tool entirely, which is a strange omission given HHS maintains it and half the buyers reading those pages do not need to spend anything. Here is the field with the free option in it.
HIPAA risk assessment tools compared
Everything below was read off each vendor's own pages in September 2026. Where a vendor publishes no figures, the table says so instead of repeating a directory estimate as though it were a list price.
| Tool | Best for | Tracks remediation after the assessment | Published pricing |
|---|---|---|---|
| HHS SRA Tool | Small and medium providers with one location and a simple stack | No, it produces a report | Free |
| Complies | Healthtech teams of 5 to 200 that need HIPAA and SOC 2 on one control set | Yes, as owned obligations with due dates | Published: $79, $199 and $499 a month |
| Accountable HQ | Practices and business associates wanting the whole HIPAA program self-serve | Yes, alongside training and BAA tracking | Published: $199 to $799 a month, or $169 to $679 billed annually |
| Medcurity | Practices that want a named advisor rather than software alone | Yes, with expert review of the finished analysis | Starts at $499 a year for the small practice analysis |
| Compliancy Group | Teams that want guided onboarding and a coach checking their work | Yes, as part of the guided program | No figures published |
| Vanta, Drata, Secureframe, Sprinto | Healthtech whose immediate driver is customer security review, not OCR | Yes, though HIPAA is one framework among dozens | Quote-only and annual-first |
| A consultant engagement | Complex environments, an active investigation, or a need for privilege | Depends entirely on the scope you buy | Quoted per engagement |
We build one of those, so read the Complies row as an interested party's claim and check it against the rest. The rest of this piece matters more than the table anyway, because in this category the tool is a smaller variable than whether anyone maintains the thing after week one.
Start with the free HHS tool, and know when you have outgrown it
The Security Risk Assessment Tool is built by the Office of the National Coordinator with OCR. Version 3.6.1 landed on May 28, 2026, and it ships as a Windows application and as an Excel workbook for everyone else. It walks through the administrative, physical and technical safeguards and produces a report at the end.
HHS is unusually direct about its limits. The documentation states the tool is designed for small and medium providers and that using it may not be appropriate for larger organizations. Take that at face value. If you are a two-location practice with an EHR and a billing vendor, working through it carefully and saving each year's file is a real risk analysis, and nobody is going to fault you for not buying software.
The signals that you have outgrown it are practical rather than regulatory. You have more systems than one person can hold in their head. Risks get identified and then nothing visibly happens to them. The environment changes several times a year, so a file from last January describes a company that no longer exists. Or you are also being asked for SOC 2 by customers, and you have started maintaining two separate control lists that say the same thing.
What actually separates the paid tools
Feature lists in this category are close to identical, and none of them addresses the thing that decides whether the analysis holds up. Three questions cut through it.
Does a risk connect to the control that treats it? A rated risk sitting on its own is an unanswered question. In a tool worth paying for, the risk links to the safeguard meant to reduce it and to evidence that the safeguard operates, so the analysis and the control library stay one artifact instead of two documents drifting apart.
Does remediation have a name and a date? The risk analysis at 164.308(a)(1)(ii)(A) is immediately followed by risk management at 164.308(a)(1)(ii)(B), and the second one is what enforcement turns on. Every rated risk needs a decision: reduce it, accept it in writing, or transfer it, each with an owner.
Does it help you find the ePHI in the first place? Scoping is where analyses quietly fail, because PHI does not stay where the architecture diagram says it does. It ends up in support tickets, exported spreadsheets, shared drives and chat threads. Being able to search across every system your staff actually use surfaces more in-scope data than any questionnaire, and the systems nobody lists are consistently the ones investigations find.
Who can perform a HIPAA risk assessment?
Anyone competent to do it, including your own staff. HIPAA does not require an external assessor, a credential or a certification, which is a genuine difference from a SOC 2 audit or a PCI Report on Compliance. What the rule asks for is an accurate and thorough analysis that is documented. Organizations hire consultants for expertise, for capacity, or to get legal privilege over uncomfortable findings, not because the regulation demands an outside name on the cover.
How often should a HIPAA risk assessment be done?
The Security Rule does not name an interval. It requires review and update as needed, and OCR's guidance frames that as periodic review. Annual is the working norm and what auditors, health system procurement teams and cyber insurers expect to see. The more useful trigger is change: a new system, a new vendor holding PHI, a merger, a significant architecture shift or a security incident should each prompt an update rather than waiting for the anniversary of the last one.
Is a HIPAA risk assessment mandatory?
Yes, and it is a required implementation specification rather than an addressable one, so there is no route where you document why you chose not to do it. It applies to every covered entity and every business associate handling electronic PHI, whatever the size. Business associates own this in their own right, too. Your customer's analysis does not cover you, and signing their business associate agreement does not discharge it.
Does a HIPAA risk assessment template work?
A template is a reasonable structure and a poor finished product. The failure is predictable: the generic threat list survives, the organization's actual architecture never appears, and every row ends up rated medium, which makes the ratings useless for deciding what to fix first. If a reviewer cannot tell from the document which systems you run, the template has not been filled in so much as submitted.
What the OCR settlements actually turn on
This is the most heavily enforced corner of HIPAA at the moment. OCR runs a Risk Analysis Initiative aimed specifically at entities that never conducted an accurate and thorough analysis. By April 23, 2026 it had completed thirteen investigations under it, announcing four settlements that day covering more than 427,000 individuals, over $1 million in payments, and two-year corrective action plans for each entity.
The pattern in those cases is consistent and worth internalizing: a breach gets reported, OCR investigates, and the investigation finds there was no adequate risk analysis behind it. The absence turns an incident into a documented compliance failure. Nobody is fined for the analysis being imperfect. They are penalized for it not existing.
Worth watching alongside that: OCR proposed a full Security Rule overhaul on January 6, 2025 that would remove the required and addressable distinction and make a written asset inventory, a network map and annual risk analysis explicit mandates. The comment period closed on March 7, 2025 with roughly 4,745 comments, and the target for a final rule has since slipped from May 2026 to July 2027. It is not law. Build against the current rule, but build on a real asset list so that if it is adopted the change is a formatting exercise rather than a restart.
So which one should you buy?
If you are a small provider with a simple environment, start with the HHS tool this month rather than budgeting for software next quarter. If you are a healthtech company holding PHI under BAAs and also facing customer security reviews, buy something that cross-maps HIPAA with SOC 2 so you are not evidencing access control twice, and check the published price before the demo. If you are mid-investigation or your environment is genuinely complicated, hire a consultant and use software to hold what they hand you.
The common thread is unglamorous. A rough analysis covering all nine elements, done now and revisited when things change, beats a polished one that describes the company you were two years ago. Our own take on that is set out in more depth on HIPAA risk assessment software, and the step-by-step mechanics of running one are in the guide to the HIPAA security risk assessment. If you are weighing the wider category rather than the assessment alone, the roundup of healthcare compliance software covers the platforms that also handle training and exclusion screening, and HIPAA compliance software covers the safeguards either side of the risk analysis.
RUN IT, NOT JUST READ IT
Turn this into tracked rows with owners
Everything in this guide becomes obligations, controls, and evidence with owners and due dates inside Complies, with a live readiness score on top. Plans from $79 a month, prices published.