Best HIPAA Risk Assessment Software
Five kinds of tool are sold for the HIPAA risk analysis, and each produces a different document. What each covers, where it stops, and what OCR looks for.
By the Scrutineer team
September 2026 · 8 min read
Try it while you read
No account, nothing to install.
Pick a framework or a vendor and run a scrutiny. You get per-control statuses, the evidence behind each one, and a prioritized gap list.
›
Illustrative sample · not an audit attestation
Five genuinely different products are sold for the HIPAA risk analysis, and each one produces a different document. The free HHS Security Risk Assessment Tool gives you a completed questionnaire. HIPAA compliance suites give you policies, training records and a risk analysis in one place. Consultants give you a point-in-time report with findings. Control-linked compliance platforms give you a mapped control library with dated evidence behind it. Enterprise risk platforms give you a configurable register and board reporting. Choose by the document you are missing, not by which homepage says HIPAA the most times.
The confusion is understandable, because the regulation itself is short on detail. 45 CFR 164.308(a)(1)(ii)(A) says, in full, to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate. That specification is marked Required, so there is no reasonable-and-appropriate escape hatch on it. What it does not contain is a method, a template, a frequency, or a product. Vendors filled that vacuum with five different answers.
What is the best HIPAA risk assessment software?
It depends on the size of your environment and whether anyone outside your organization is going to read the result. A two-provider practice with one EHR and four vendors has a genuinely different problem from a health tech company whose customers demand a risk analysis, a SOC 2 report and a completed security questionnaire before signing. The table below is organized by output, because output is the part that never appears on a pricing page.
| Category | What it actually produces | Best for | Where it stops |
|---|---|---|---|
| The free HHS and ONC SRA Tool | A completed structured questionnaire and an exportable report covering the Security Rule safeguards | Solo practitioners and small single-location practices doing this properly for the first time | It analyzes what you type in. It cannot discover an ePHI repository you forgot, read your business associate agreements, or track remediation between reviews |
| HIPAA compliance suites | A policy library, workforce training records, BAA tracking and a risk analysis document, bundled | Small and mid-sized practices that want the whole program in one subscription | Most do not connect to live systems, so what looks like evidence is usually an attestation that someone ticked a box, not an observed control state |
| Consultant-delivered assessments | A point-in-time written report with rated findings, recommendations and often a letter you can show a customer | A first assessment, a complicated environment, or a situation where independence matters for defensibility | It ages from the day it lands. Buy one every year and you buy the same discovery work every year, because nothing carried forward |
| Control-linked compliance platforms | A control library mapped across frameworks, automated evidence collection, and a risk register wired to the controls that treat each risk | Business associates and health tech vendors who owe HIPAA plus SOC 2, ISO 27001 or HITRUST to the same customer | It does not walk your building or interview your front desk. Physical safeguards and clinical workflow still need a human, and it is heavy for a two-provider practice |
| Enterprise IT risk and GRC platforms | A configurable risk taxonomy, issue management and executive reporting across many departments and facilities | Health systems and large payers with a dedicated risk function and administrators to run the tool | The configuration is the product. HIPAA content is a module you buy or build, and without staff to maintain it the register goes stale quietly |
We build in the fourth row, so treat that row with appropriate suspicion. The honest limitation is real: a control-linked platform is very good at making the analysis durable and reusable across frameworks, and it does not replace a physical walkthrough or an interview with the person who actually handles paper charts. What it does buy you is that one access review can evidence a HIPAA technical safeguard, a SOC 2 criterion and an ISO 27001 control at once. If you only owe HIPAA and nothing else, that advantage mostly disappears and one of the first three rows will serve you better.
Is the free HHS SRA Tool good enough?
For a small practice, often yes. It is a real piece of work, it is free, and HHS built it precisely so that cost would not be the reason a small provider skipped the analysis. The disclaimer on the tool is worth reading before you rely on it, because it says the quiet part out loud: use of this tool is neither required by nor guarantees compliance with federal, state or local laws.
That is not a knock on the software. It is a description of what a questionnaire can do. The tool assesses what you tell it about, which means the analysis inherits the boundaries of your own memory of the environment. The gap that shows up in enforcement is almost never a missing document. It is a document that covered the EHR and stopped there, while ePHI also sat in nightly backups, a shared referrals mailbox, an imaging archive managed by a vendor, biomedical devices on their own inventory, and the systems of eleven business associates. Our HIPAA risk assessment software page runs a full table of those locations and why each one gets missed.
What do OCR enforcement actions actually find?
The same thing, over and over. HHS Office for Civil Rights runs a Risk Analysis Initiative aimed at this one implementation specification, and by 2026 it had announced more than a dozen enforcement actions under it, alongside a run of ransomware settlements in which the recurring finding is a failure to conduct an accurate and thorough risk analysis before the incident.
Read that phrasing closely, because it tells you what to buy. The word doing the work is not "conduct". It is "accurate and thorough". Organizations in these cases generally had an assessment. What they did not have was one that reached the whole environment, and in many cases they had no record that the risks they did find were ever driven down. The second half is its own Required specification: 164.308(a)(1)(ii)(B) tells you to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. A rated list with nothing recorded against it satisfies the first specification badly and the second one not at all.
How much does HIPAA risk assessment software cost?
Published figures spread too widely to quote a single number honestly, and the spread is driven by scope rather than by vendor. The variables that actually move the price: how many locations and systems are in scope, whether an ePHI inventory already exists or has to be built, how many business associates you track, whether a human assessor or advisory hours are bundled in, and whether you are buying a one-time report or software that maintains the analysis between reviews.
One comparison is worth making explicitly. A consultant-delivered report priced once per year is usually the most expensive option per year of coverage, because the discovery work is repurchased every cycle and the document is stale within a quarter. That is not an argument against consultants, who are often the right call for a first assessment or a messy environment. It is an argument against treating the report as the deliverable when the regulation asks for an ongoing process.
How often does a HIPAA risk assessment have to be done?
The Security Rule sets no frequency at all. The word annual does not appear in the risk analysis specification. The annual habit comes from a different place: the CMS Promoting Interoperability and MIPS Security Risk Analysis measure, which asks participants to conduct or review an analysis at least once each calendar year and attest that they did. That measure is scoped to certified EHR technology and attached to a payment program.
The defensible standard is to reassess whenever the environment changes materially: a new EHR, an acquisition, a new location, a breach, or a significant new vendor. An assessment built to satisfy the CMS attestation will usually be narrower than the one OCR expects, which is how organizations end up holding a document that satisfies an auditor and not a regulator.
Should you wait for the new HIPAA Security Rule?
No. HHS proposed a substantial overhaul on January 6, 2025, Federal Register document 2024-30983 under RIN 0945-AA22, running 125 pages. It would remove the Addressable and Required distinction so nearly everything becomes required, and add explicit duties including a technology asset inventory and network map, multi-factor authentication, encryption of ePHI at rest and in transit, annual compliance audits, and vulnerability scanning and penetration testing on a set cadence. The comment period closed March 7, 2025 and drew close to 5,000 comments.
It has not been finalized. Reporting on the 2026 Unified Agenda places the rule on the Long-Term Actions list with July 2027 given as the anticipated timeframe for final action, which in practice means HHS does not expect a final rule within the next twelve months. Buying a platform today because it advertises readiness for that rule is buying a forecast. Meanwhile the 2003 Security Rule is what OCR is enforcing, and its risk analysis specification is Required right now.
What to check before you buy
Six questions separate tools that will hold up from tools that produce a nice PDF.
- Does it help you find ePHI, or only assess what you list? Scope failure is the dominant finding in enforcement, so a tool that starts from a blank inventory inherits your blind spots.
- Does it track remediation with an owner and a date? That is the 164.308(a)(1)(ii)(B) half, and most assessment tools simply stop at the rated list.
- Does it hold your business associates? A current BA inventory, executed agreements and a review date belong in the same system as the risk register, not in a separate spreadsheet.
- Does it version the assessment? You will eventually need to show what you knew, and when, which means a dated history rather than a file that gets overwritten.
- Does it reuse controls across frameworks? If you also owe SOC 2 or HITRUST, evidencing the same control twice is pure waste. Our HITRUST compliance software page covers how much of that overlap is real.
- Does it cover the workforce standard? Security awareness and training is its own Security Rule standard, and most teams satisfy it with a general corporate learning platform that records who completed which course and when rather than anything healthcare-specific.
One last note on language, because it trips up buyers constantly. There is no such thing as HIPAA certified software, and no vendor can make you HIPAA compliant. Compliance is a property of your organization and its practices, not of a product you subscribe to. What software can do is make the analysis accurate, keep it current, and leave behind the dated evidence that the risks you found were actually managed down. If you want the wider program view, our HIPAA compliance software page covers the full set of safeguards, and the HIPAA compliance checklist walks the administrative, physical and technical requirements in order. If you are assessing risk beyond HIPAA, the general method is laid out in our guide to how to conduct a cybersecurity risk assessment, and vendor-side work is covered under vendor security assessment.
See Scrutineer scrutinize your posture
Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.