The Security Risk Assessment: starting at $3,500, and I come to the building.
If your organization handles patient data, HIPAA requires you to conduct a security risk analysis and to keep it current. It is the foundation the rest of the Security Rule builds on, the most frequently cited deficiency in OCR investigations, and the artifact MIPS reporters attest to every year. Fixed scope, priced up front, every finding evidence-cited.
A questionnaire cannot see your building.
The Security Rule has three families of safeguards: administrative, technical, and physical. Remote assessments handle the first two tolerably and the third badly, because 45 CFR 164.310 is about a place: facility access controls, workstation use and location, device and media controls, and disposal.
Those are observations, not answers. Nobody writes "the workstation faces the waiting room" on an intake form. Nobody lists the unlocked closet with the switch in it, the fax machine that still receives referrals, or the box of drives someone meant to shred in 2019. I walk the building, and those go in the register with everything else.
This is the half of the analysis a software platform structurally cannot do, and it is why the walkthrough is in scope at the published price rather than sold as an option. I can be in your building.
What you get, and what it is scoped to.
Single entity or site. The clock starts at complete intake, not at payment. Multi-site organizations are quoted per site.
The assessment is one rung. The fees credit forward.
The assessment ends in one of two places. If the findings are material, the Risk Management Project acts on them and the assessment fee credits in full. If the program is sound, there is nothing to implement and the right next step is Maintenance, which the fee credits against as well. A clean result does not cost you more than a bad one.
Enter where your program actually is:
| Engagement | Price | What you get |
|---|---|---|
| Self-Check | Free | Run the open-source compliance skills yourself, including the Risk Assessment skill, on rotecompliance.com. A first read of your posture in your own environment. No call, no email gate. |
| Security Risk Assessment | starting at $3,500 | The analysis 45 CFR 164.308(a)(1)(ii)(A) requires, conducted by a practitioner and including the on-site physical walkthrough: asset and ePHI inventory (AI tools and vendor AI access included), reasonably anticipated threats and vulnerabilities, likelihood and impact scored with written rationale, a risk register you keep, a risk management plan with 30/60/90 actions, and an attestation-ready summary letter. Single entity or site. |
| Small-Organization SRA | starting at $1,750 | The same artifact set for single-site organizations that are nonprofit or public, under roughly $2M revenue, or 15 or fewer staff. Standard templates, ratified by a compliance attorney. If real complexity surfaces, the engagement routes to the full assessment with this fee credited. Nonprofit and public-entity discount applies. |
| Risk Management Project | scoped from the findings | Implementation of the risk management plan per 45 CFR 164.308(a)(1)(ii)(B): corrected policies and procedures, safeguard documentation, BAA language, and an evidence log showing the analysis was acted on, including AI-specific gaps where the findings warrant it. Already have a risk analysis from another provider? Bring it, and the Project closes the gaps it surfaced. OCR's current enforcement pattern examines exactly this follow-through. |
| Maintenance | starting at $750/mo | The annual SRA refresh (MIPS requires a fresh analysis each performance period; OCR expects it reviewed as your environment changes), quarterly reviews, the annual SAFER Guide self-assessment for MIPS reporters, and a watch on the proposed Security Rule overhaul. The annual refresh alone is the starting at $3,500 assessment. |
The 2026 attestation is two statements, and both point here.
For the Promoting Interoperability category, CMS requires a yes to both: a security risk analysis conducted or reviewed during the calendar year of the performance period (45 CFR 164.308(a)(1)(ii)(A)), and risk management activities that implemented security measures to address what it found (45 CFR 164.308(a)(1)(ii)(B)). Miss the measure and the entire category scores zero, which puts the 75-point threshold, and up to a 9% adjustment on 2028 Medicare payments, in play.
The analysis must be unique to the performance period, conducted January 1 to December 31, and scoped to all ePHI you create, receive, maintain or transmit, not only the EHR. This assessment is built to that standard. Maintenance carries the annual refresh and the SAFER Guide self-assessment that reports alongside it.
Groups of 15 or fewer clinicians are automatically reweighted out of the category in 2026. The Security Rule obligation applies regardless of MIPS, and it is what OCR's Risk Analysis Initiative enforces.
Business associates: the assessment includes a findings summary usable in enterprise security reviews. If what you actually need is someone to run the program month over month rather than assess it once, that is the fractional compliance officer retainer, from $2,500/mo, and half your assessment fee credits to your first month on retainer.
Common questions about the Security Risk Assessment.
The security risk analysis required by 45 CFR 164.308(a)(1)(ii)(A): an assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of all ePHI your organization creates, receives, maintains or transmits. It is the foundation the rest of the Security Rule builds on, the most frequently cited deficiency in OCR investigations, and the subject of OCR's ongoing Risk Analysis Initiative. It is delivered fixed-scope: asset and ePHI inventory, threat and vulnerability analysis with likelihood and impact scoring, a risk register, a risk management plan, and an attestation-ready summary letter, every finding evidence-cited.
Consultant-led assessments typically run $2,000 to $15,000 for small and mid-size organizations and considerably more at enterprise firms, usually behind a quote process. Software platforms run roughly $500 to $4,000 per year and leave the analysis work to you. My pricing is published: starting at $3,500 for the practitioner-conducted assessment, and starting at $1,750 for qualifying small single-site organizations. The fee credits in full toward the Risk Management Project.
Because 45 CFR 164.310, the physical safeguards standards, is about the physical environment, and a questionnaire cannot see one. Facility access controls, workstation location and use, device and media disposal: these are observations, not answers. Walking the building is also how the undocumented things surface: the workstation facing the waiting room, the unlocked closet with the switch in it, the fax machine, the box of drives someone meant to shred in 2019. Remote-only assessments miss those by construction.
Yes, for anyone reporting the Promoting Interoperability category. For the 2026 performance period, CMS requires attesting to two things: that a security risk analysis was conducted or reviewed during the calendar year (45 CFR 164.308(a)(1)(ii)(A)), and that risk management activities implemented security measures to address what it found (45 CFR 164.308(a)(1)(ii)(B)). Without both, the entire category scores zero. The analysis must be unique to the performance period and cover all ePHI, not only the EHR. Practices with 15 or fewer clinicians are automatically reweighted out of the category in 2026, but the underlying Security Rule obligation applies to every covered entity and business associate regardless of MIPS.
The delivery window is fixed, and I give you the date at scoping rather than publishing one here, because it depends on the size of the environment. What is worth knowing up front: the clock starts when I have the documents and access I need, not when you pay, so nothing is lost if it takes you a couple of weeks to gather things. The on-site visit is usually a single day within that window.
Bring it. If it holds up, you do not need another one from me and I will say so. What you likely need is the Risk Management Project that acts on it, which is the follow-through OCR's current enforcement pattern actually examines. If it does not hold up, you will know why, in writing.
Within driving distance, yes: the walkthrough is in scope at the published price. Beyond it the assessment is still available, with travel quoted separately before you commit, or scoped remote with the physical-safeguards section explicitly limited and that limitation stated in the report rather than papered over. Where you are decides which of those applies, and we settle it on the scoping call before there is an invoice.
Book a scoping call.
Thirty minutes. Tell me your setting and what triggered the search, and I'll tell you whether this is the assessment you need, whether you qualify for the small-organization price, and what the on-site day looks like for you.