Complies

RISK ANALYSIS · 164.308(a)(1)(ii)(A) · EVIDENCE

HIPAA risk assessment software: a HIPAA security risk assessment tool, SRA tool alternative and Security Rule risk analysis platform

The risk analysis is the one HIPAA requirement OCR cites more than any other, and it fails for a boring reason: it gets done once, saved as a PDF, and never touched again.

See pricing

From $79/mo · Prices published · No sales call · Monthly billing

SOC 2 · TRUST SERVICES CRITERIA

Audit readiness

0 %

Your auditor makes the final call

Built for teams of 5 to 200

AWS GitHub Google Workspace Slack Jira Azure Okta
SRA

What HIPAA risk assessment software does, and the nine elements it has to cover

HIPAA risk assessment software helps a covered entity or business associate run and maintain the risk analysis that 45 CFR 164.308(a)(1)(ii)(A) requires: identify everywhere electronic protected health information lives, pair each asset with the threats and vulnerabilities that apply to it, judge likelihood and impact, assign a risk level, and track the remediation that follows. OCR published guidance setting out nine elements a compliant risk analysis contains, and they are the specification any tool in this category is really being measured against: scope, data collection, threats and vulnerabilities, current security measures, likelihood, impact, risk level, documentation, and periodic review. The last element is where most programs actually fail. A risk analysis is not an annual event that produces a report; it is a record that has to be updated when the environment changes, and OCR expects to see that history. Three facts should shape which tool you buy. First, HHS publishes a genuinely useful free option: the ONC and OCR Security Risk Assessment Tool, version 3.6.1 as of May 28, 2026, available as a Windows application and an Excel workbook. HHS states in its own documentation that it is built for small and medium providers and may not be appropriate for larger organizations, which is the honest dividing line between the free tool and a paid platform. Second, this is the most heavily enforced corner of HIPAA right now. OCR runs a Risk Analysis Initiative aimed squarely at entities that never conducted an accurate and thorough analysis, and it had completed thirteen investigations under it by April 23, 2026, when it announced four more settlements covering over 427,000 individuals, more than $1 million in payments, and two-year corrective action plans. Third, the rules are about to move but have not moved yet. OCR proposed a full Security Rule overhaul on January 6, 2025 that would remove the addressable and required distinction and make an asset inventory, a network map and annual risk analysis explicit mandates. The comment period closed March 7, 2025 with roughly 4,745 comments, and the target for a final rule has slipped from May 2026 to July 2027 on the federal agenda. Nothing is adopted, so build against today's rule and design so the proposed additions are not a rewrite. Complies covers the software half of that work for healthtech and digital health teams of 5 to 200 at published prices of $79 to $499 a month: a risk register where each threat and vulnerability pair carries a rating and an owner, controls mapped to the safeguards that treat it, evidence pulled on a schedule from AWS, Okta and Google Workspace, and a dated history of every review. It does not scan your network, it does not store PHI, and it does not sign anything on your behalf, and the tables below say where those lines fall rather than blurring them.

Complies assists with compliance workflows. It is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready.

Last updated September 2026

SCOPE · RATE · TREAT

The three phases of a Security Rule risk analysis, and where each one breaks

01

Scope every place ePHI actually lives

The analysis has to cover all electronic PHI the organization creates, receives, maintains or transmits, which in practice means production databases, backups, logs, analytics pipelines, support tickets, laptops and every vendor holding data under a BAA. Scoping to the main application and forgetting the ticketing system is the most common finding in an OCR investigation, because that is exactly where PHI ends up pasted into a message.

obligation tracking software
02

Rate likelihood and impact honestly

Each asset gets paired with the threats and vulnerabilities that realistically apply, and each pair gets a likelihood, an impact and a resulting risk level. The trap is a spreadsheet where everything is rated medium, which tells a reviewer nothing and cannot justify why one gap was fixed this quarter and another was deferred. The rating exists to defend your remediation order.

risk register software
03

Treat the risk and keep the record alive

Risk analysis under 164.308(a)(1)(ii)(A) is followed immediately by risk management under 164.308(a)(1)(ii)(B), and the second one is what OCR checks. Every rated risk needs a decision: reduce it, accept it in writing, or transfer it, each with an owner and a date. Complies holds those as tracked obligations, so the analysis carries a remediation history rather than ending at a report.

control mapping software
COMPARE

The nine elements OCR expects in a risk analysis, and where each one usually fails

OCR's guidance on risk analysis under the Security Rule sets out nine elements a compliant analysis contains. Almost every vendor page in this category mentions that the guidance exists without ever listing what it asks for, which makes it impossible to check a tool against it. Here is the full set, what a reviewer is actually looking for in each, the failure that shows up repeatedly in enforcement, and where Complies holds it. Use this as a specification when you evaluate any tool on this page, ours included.

Required element What a reviewer looks for Where it usually fails Where Complies holds it
Scope of the analysis Coverage of all ePHI the organization creates, receives, maintains or transmits, across every system, media and location, including remote work and vendors. Scope quietly limited to the main clinical or product system, leaving out backups, logs, support tickets and analytics. A scoped asset list you build once and revise, with each system carrying the systems it feeds and the vendor behind it.
Data collection Documented evidence of where ePHI is stored, received, maintained and transmitted, gathered rather than assumed. The data flow lives in one person's head, so nobody can reproduce how the conclusion was reached. Asset and integration records with the source of each fact attached, so the collection step is itself documented.
Threats and vulnerabilities A realistic list of potential threats and technical and non-technical vulnerabilities for each asset in scope. A generic threat list copied from a template that never mentions the organization's actual architecture. Threat and vulnerability pairs attached to named assets in the risk register, not to an abstract category.
Current security measures What is already in place for each risk, whether it is configured correctly, and whether it actually operates. Controls listed as implemented with nothing showing they were ever checked after go-live. Each safeguard mapped to a control with scheduled evidence pulled from AWS, Okta and Google Workspace.
Likelihood of occurrence A documented likelihood rating for each threat and vulnerability pair, with the reasoning behind it. Every row rated medium, which makes the whole rating exercise unusable for prioritization. A required likelihood field per risk with the justification stored beside it.
Potential impact The impact on confidentiality, integrity and availability of ePHI if the pair were realized, including record counts. Impact estimated without reference to how much PHI the system actually holds. An impact rating recorded against the asset, so the record count informs the score.
Level of risk A risk level derived from likelihood and impact, with a corrective action list flowing from it. A risk level assigned but never used, so remediation order has no documented rationale. Calculated risk levels that drive the remediation queue and its ordering.
Finalize documentation The analysis written down in a form a reviewer can follow, retained for six years under 164.316(b)(2). A PDF saved to a shared drive with no version history, so no one can prove what was known when. A dated record with revision history, exportable as a pack rather than reassembled by hand.
Periodic review and updates Evidence the analysis is reviewed and updated as the environment changes, not just once a year. The single biggest failure in this list. The analysis is done once, then nothing happens for three years. A recurring obligation with a named owner, plus a trigger to revisit when a new system or vendor is added.

One clarification worth making because it causes real confusion: the risk analysis in this table is not the same thing as the four-factor breach risk assessment under 164.402. That one is performed after a specific incident to decide whether an impermissible use or disclosure is a notifiable breach, weighing the nature of the PHI, who received it, whether it was actually acquired or viewed, and how far the risk was mitigated. Both are called risk assessments and they answer completely different questions. The Security Rule analysis in this table is the ongoing, organization-wide one, and it is the one OCR keeps citing. Compare the multi-framework platforms in this space in detail on Vanta alternatives, Drata alternatives and Secureframe alternatives.

FREE TOOL, PLATFORM OR CONSULTANT

HIPAA risk assessment tools compared, including the free HHS option most pages leave out

Roundups in this category tend to list paid platforms and skip the fact that HHS gives away a workable tool. That omission is the single most useful thing a buyer can know, because for a small practice the free tool may genuinely be enough, and for a larger organization HHS itself says it is not. Below is what each option actually is and what it publishes, read off each vendor's own pages in September 2026. Where a vendor does not publish figures we say so instead of repeating a third-party estimate as if it were a list price.

Tool What it actually is Who it fits Published pricing (September 2026)
HHS SRA Tool A free desktop application and Excel workbook from ONC and OCR, version 3.6.1 released May 28, 2026, that walks you through the safeguard questions and produces a report. Small and medium providers. HHS states in its own documentation that the tool may not be appropriate for larger organizations. Free.
Complies A risk register where threats and vulnerabilities attach to named assets and link to the controls that treat them, with evidence collected on a schedule and a dated review history. Healthtech and digital health teams of 5 to 200 that need the analysis to stay current between reviews, usually alongside SOC 2. Published: $79, $199 and $499 a month at the yearly rate.
Accountable HQ A HIPAA compliance platform covering risk assessment, policies, workforce training and business associate agreement tracking on one subscription. Small practices and business associates wanting the whole HIPAA program self-serve, including the training we do not ship. Published: $199, $299 and $799 a month, or $169, $254 and $679 a month billed annually.
Medcurity A guided Security Risk Analysis with a named advisor and expert review of the finished assessment, plus remediation tracking. Practices that want a person involved rather than software alone, and would not complete an assessment unaided. Starts at $499 a year for the small practice analysis; larger scopes are quoted.
Compliancy Group A HIPAA-specific platform sold alongside a coaching model, covering risk assessment, policies, training and vendor management. Practices and business associates that want guided onboarding and a human checking their work. No figures published on its pricing pages, checked September 2026.
Vanta, Drata, Secureframe, Sprinto Security compliance automation where HIPAA is one framework among dozens, mapped over a SOC 2 style control set. Healthtech companies whose main driver is passing customer security review, with HIPAA folded into the same contract. Quote-only and annual-first; none publishes a rate card.
A consultant or law firm engagement A one-off assessment producing a written risk analysis report, sometimes with a remediation roadmap and, through counsel, a claim of privilege. Complex environments, an active OCR investigation, or a genuine need for legal privilege over the findings. Quoted per engagement; nobody publishes a rate card.
A spreadsheet you maintain yourself Whatever structure you impose on it. Legitimately compliant if it covers all nine elements and is genuinely reviewed and versioned. Very small covered entities with a simple environment and one person who reliably owns it. Free, until an investigation asks for six years of dated versions.

Two honest notes. The HHS SRA Tool is not a consolation prize: it is maintained, it follows the guidance closely, and a single-location practice that works through it carefully and saves each year's output has done a real risk analysis. What it will not do is track remediation to closure, pull evidence automatically, or keep itself current when you add a system in March, and those are the reasons organizations outgrow it rather than any deficiency in the questions it asks. The second note is about all of us: no tool on this list, ours included, makes you compliant. OCR settlements under the Risk Analysis Initiative are about organizations that did not identify their risks and did not fix them. Software makes that work legible and repeatable. It does not do it for you.

CAPABILITIES

What Complies covers when the risk analysis has to survive scrutiny

A record that stays current between reviews

The periodic review element is where most programs fail, and it fails through neglect rather than intent. Complies holds the review as a recurring obligation with a named owner, and flags a revisit when a new system or vendor enters scope, so the analysis reflects the environment rather than last year's architecture.

Risks linked to the controls that treat them

A rated risk sitting next to nothing is an unanswered question. Each threat and vulnerability pair links to the safeguard meant to reduce it and to the evidence that the safeguard operates, so the analysis and the control library are one artifact instead of two documents that drift apart.

The asset inventory the proposed rule would require

OCR's January 2025 proposal would make a written asset inventory and network map explicit requirements rather than implied ones. Building the analysis on a real asset list now means that change is a formatting exercise if the rule is finalized, not a restart.

Remediation with a name and a date

Risk analysis is followed by risk management under 164.308(a)(1)(ii)(B), and that is the requirement enforcement actions actually turn on. Every rated risk gets a decision, an owner and a due date, and accepted risks get written acceptance rather than silence.

One control library across HIPAA, SOC 2 and ISO 27001

Access control, audit logging, encryption and vendor management are asked for by all three. Map a control once and it counts in each, so a healthtech company chasing SOC 2 for customers is not running a second evidence collection for HIPAA.

A price you can read before a sales call

Starter is $79 a month, Growth $199, Scale $499, published. Several platforms in this category will not quote until after a demo, which for a small healthtech team is a procurement cycle before you can even scope the work.

HOW TO START

Running a defensible risk analysis without a consultant

01

List every place ePHI actually lives

Start with production, then follow the data: backups, logs, analytics, support tooling, laptops, and every vendor holding PHI under a BAA. The systems people forget are the ones where PHI arrives by accident, like a screenshot pasted into a ticket, and those are exactly what investigations surface.

02

Pair each asset with realistic threats and vulnerabilities

Skip the generic threat catalog. For each system ask what would actually go wrong given how it is built and who can reach it, then record the pair against the named asset with a likelihood, an impact and the reasoning behind both.

03

Connect identity, code and cloud for the safeguard evidence

Point Complies at Okta or Google Workspace, GitHub and AWS. It reads configuration and access rather than your data, and the current security measures element stops being a claim and becomes a scheduled observation.

04

Treat the risks, then keep the record breathing

Turn each rated risk into an obligation: reduce, accept in writing, or transfer, with an owner and a date. Set the review cadence and the triggers that force an update. When anyone asks for the analysis, export the dated pack rather than reconstructing it.

FIT

Who this is for, and who it is not

A GOOD FIT WHEN

  • You are a healthtech or digital health company that signed a BAA and now owes a real risk analysis.
  • You have a risk analysis PDF from a consultant that is two years old and has not been touched since.
  • You have outgrown the HHS SRA Tool and need remediation tracked to closure rather than a report.
  • You are chasing SOC 2 for customers and refuse to run a separate evidence collection for HIPAA.
  • You want the analysis, the controls and the evidence in one record at a published price.

LOOK ELSEWHERE WHEN

  • You need a network vulnerability scan or a penetration test; those are separate services and this is not one.
  • You want a consultant to perform, write and sign the assessment for you, or you need legal privilege over the findings.
  • You want PHI itself to live in the platform; Complies holds compliance records, not patient data.
  • You are a hospital system needing enterprise integrated risk management across thousands of assets.
  • You need workforce HIPAA training or OIG exclusion screening, neither of which Complies ships.
QUESTIONS

HIPAA risk assessment questions buyers actually ask

A HIPAA risk assessment, more precisely a risk analysis, is the documented process required by 45 CFR 164.308(a)(1)(ii)(A) of identifying risks to the confidentiality, integrity and availability of electronic protected health information. You determine where ePHI lives, what threats and vulnerabilities apply to each place, how likely each is and how bad it would be, and what your current safeguards do about it. OCR's guidance lists nine elements a compliant analysis contains.

Yes. The risk analysis is a required implementation specification under the Security Rule, not an addressable one, which means there is no option to document why you skipped it. It applies to every covered entity and every business associate handling electronic PHI, regardless of size. A solo practice and a health system owe the same requirement; only the scope and effort differ.

The Security Rule does not name an interval. It requires review and update as needed, which OCR interprets through the periodic review element of its guidance. Annual is the working norm and what most auditors and cyber insurers expect, but the real trigger is change: a new system, a new vendor with PHI, a merger, a significant architecture shift or a security incident should each prompt an update rather than waiting for the anniversary.

Anyone competent to do it, including your own staff. HIPAA does not require an external assessor, a certification or a credential, which is a real difference from a SOC 2 audit or a PCI Report on Compliance. What matters is whether the analysis is accurate and thorough and whether it is documented. Organizations hire consultants for expertise, capacity or legal privilege, not because the rule demands it.

In the regulation the operative term is risk analysis, and in everyday use the two words are interchangeable for the same Security Rule exercise. The distinction that genuinely matters is a different one: the Security Rule risk analysis is the ongoing, organization-wide look at risks to ePHI, while the four-factor breach risk assessment under 164.402 is performed after a specific incident to decide whether it must be reported. Different triggers, different scope, same two words.

The Security Risk Assessment Tool is a free application built by ONC with OCR, currently version 3.6.1 released May 28, 2026, available as a Windows program and an Excel workbook. It is genuinely useful and it follows the guidance closely. HHS states it is designed for small and medium providers and may not be appropriate for larger organizations. It also stops at the assessment: it will not track remediation to closure, collect evidence, or keep itself current as your environment changes.

It spans a wide range because the products are not the same shape. The HHS SRA Tool is free. Medcurity publishes a starting figure of $499 a year for a small practice analysis. Complies publishes $79, $199 and $499 a month. Accountable HQ publishes $199 to $799 a month, or $169 to $679 billed annually. Compliancy Group and the multi-framework platforms like Vanta and Drata do not publish figures at all. Consultant engagements are quoted individually.

A template is a reasonable starting structure and a poor finished product. The failure mode is predictable: the template's generic threat list gets kept, the organization's actual architecture never appears, and every row ends up rated medium. OCR's standard is an accurate and thorough analysis of your environment. If a reviewer cannot tell from the document which systems you run, the template has not been filled in, it has been submitted.

It is an OCR enforcement program focused specifically on entities that failed to conduct an accurate and thorough risk analysis, which is the most frequently cited Security Rule failure. By April 23, 2026 OCR had completed thirteen investigations under it, announcing four settlements that day covering more than 427,000 individuals and over $1 million in payments, each with a two-year corrective action plan. The pattern is consistent: a breach is reported, and the investigation finds no adequate risk analysis behind it.

It would, if adopted, and it has not been. OCR proposed the overhaul on January 6, 2025. It would remove the distinction between required and addressable implementation specifications, and make a written asset inventory, a network map, annual risk analysis, multi-factor authentication and encryption explicit requirements. The comment period closed March 7, 2025 with roughly 4,745 comments, and the target for a final rule has moved from May 2026 to July 2027. Plan against the current rule.

Yes. Since the 2013 Omnibus Rule, business associates are directly liable for Security Rule compliance, and the risk analysis obligation applies to them in their own right. Your client's analysis does not cover you, and signing their BAA does not discharge it. For a software vendor holding PHI this is usually the first HIPAA artifact a healthcare customer asks to see during procurement.

Yes, and it is the cheaper path when both are on the roadmap. The overlap is substantial: access control, audit logging, encryption, vendor management and incident response are asked for by both, so a shared control satisfies each once. What stays HIPAA-specific is the risk analysis itself, business associate agreements and the breach notification process. Complies cross-maps SOC 2, ISO 27001, HIPAA, GDPR and PCI DSS from Growth at $199 a month.

Nothing, until something goes wrong, which is precisely why the exposure is underestimated. The risk analysis is rarely discovered in isolation; OCR asks for it after a breach report, and its absence turns an incident into a documented compliance failure with a corrective action plan attached. The practical advice is unglamorous: do a rough one now covering all nine elements, rather than waiting until you have time to do a perfect one.

GO DEEPER

Frameworks and guides

Run the HIPAA risk analysis as a living record, not an annual PDF

Prices published, $79 to $499 a month. Monthly billing. Start today, no sales call.