A questionnaire cannot see your building.

The Security Rule has three families of safeguards: administrative, technical, and physical. Remote assessments handle the first two tolerably and the third badly, because 45 CFR 164.310 is about a place: facility access controls, workstation use and location, device and media controls, and disposal.

Those are observations, not answers. Nobody writes "the workstation faces the waiting room" on an intake form. Nobody lists the unlocked closet with the switch in it, the fax machine that still receives referrals, or the box of drives someone meant to shred in 2019. I walk the building, and those go in the register with everything else.

This is the half of the analysis a software platform structurally cannot do, and it is why the walkthrough is in scope at the published price rather than sold as an option. I can be in your building.

What you get, and what it is scoped to.

Single entity or site. The clock starts at complete intake, not at payment. Multi-site organizations are quoted per site.

01 · Asset and ePHI inventory
Everything that creates, receives, maintains or transmits ePHI, including the AI tools in use, vendor AI access, and the shadow AI nobody put on a list. OCR expects the analysis to cover this surface as it actually exists.
02 · Threat and vulnerability analysis
Reasonably anticipated threats to confidentiality, integrity and availability, assessed against your actual architecture rather than a generic checklist.
03 · Likelihood and impact, scored in writing
Every score carries its rationale. An unexplained score is not an analysis, and it will not survive an OCR document request.
04 · A risk register you keep
Yours, in a format you can maintain after I leave. Not locked in a platform you have to keep paying for to read.
05 · A risk management plan, 30/60/90
What to do, in what order, with what it costs. This is the input to the Risk Management Project if you take one.
06 · An attestation-ready summary letter
The artifact you hand to a MIPS attestation, a buyer's security review, or an OCR investigator.

The assessment is one rung. The fees credit forward.

The assessment ends in one of two places. If the findings are material, the Risk Management Project acts on them and the assessment fee credits in full. If the program is sound, there is nothing to implement and the right next step is Maintenance, which the fee credits against as well. A clean result does not cost you more than a bad one.

Enter where your program actually is:

Fees credit forward. The Security Risk Assessment credits in full toward a Risk Management Project, and the Small-Organization fee credits up if complexity routes you to the full engagement. Half your assessment fee credits against your first months on Maintenance. Half your assessment fee credits to your first month on retainer. You don't pay twice to climb.
EngagementPriceWhat you get
Self-Check Free Run the open-source compliance skills yourself, including the Risk Assessment skill, on rotecompliance.com. A first read of your posture in your own environment. No call, no email gate.
Security Risk Assessment starting at $3,500 The analysis 45 CFR 164.308(a)(1)(ii)(A) requires, conducted by a practitioner and including the on-site physical walkthrough: asset and ePHI inventory (AI tools and vendor AI access included), reasonably anticipated threats and vulnerabilities, likelihood and impact scored with written rationale, a risk register you keep, a risk management plan with 30/60/90 actions, and an attestation-ready summary letter. Single entity or site.
Small-Organization SRA starting at $1,750 The same artifact set for single-site organizations that are nonprofit or public, under roughly $2M revenue, or 15 or fewer staff. Standard templates, ratified by a compliance attorney. If real complexity surfaces, the engagement routes to the full assessment with this fee credited. Nonprofit and public-entity discount applies.
Risk Management Project scoped from the findings Implementation of the risk management plan per 45 CFR 164.308(a)(1)(ii)(B): corrected policies and procedures, safeguard documentation, BAA language, and an evidence log showing the analysis was acted on, including AI-specific gaps where the findings warrant it. Already have a risk analysis from another provider? Bring it, and the Project closes the gaps it surfaced. OCR's current enforcement pattern examines exactly this follow-through.
Maintenance starting at $750/mo The annual SRA refresh (MIPS requires a fresh analysis each performance period; OCR expects it reviewed as your environment changes), quarterly reviews, the annual SAFER Guide self-assessment for MIPS reporters, and a watch on the proposed Security Rule overhaul. The annual refresh alone is the starting at $3,500 assessment.

The 2026 attestation is two statements, and both point here.

For the Promoting Interoperability category, CMS requires a yes to both: a security risk analysis conducted or reviewed during the calendar year of the performance period (45 CFR 164.308(a)(1)(ii)(A)), and risk management activities that implemented security measures to address what it found (45 CFR 164.308(a)(1)(ii)(B)). Miss the measure and the entire category scores zero, which puts the 75-point threshold, and up to a 9% adjustment on 2028 Medicare payments, in play.

The analysis must be unique to the performance period, conducted January 1 to December 31, and scoped to all ePHI you create, receive, maintain or transmit, not only the EHR. This assessment is built to that standard. Maintenance carries the annual refresh and the SAFER Guide self-assessment that reports alongside it.

Groups of 15 or fewer clinicians are automatically reweighted out of the category in 2026. The Security Rule obligation applies regardless of MIPS, and it is what OCR's Risk Analysis Initiative enforces.

Business associates: the assessment includes a findings summary usable in enterprise security reviews. If what you actually need is someone to run the program month over month rather than assess it once, that is the fractional compliance officer retainer, from $2,500/mo, and half your assessment fee credits to your first month on retainer.

Common questions about the Security Risk Assessment.

What is a HIPAA security risk assessment?

The security risk analysis required by 45 CFR 164.308(a)(1)(ii)(A): an assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of all ePHI your organization creates, receives, maintains or transmits. It is the foundation the rest of the Security Rule builds on, the most frequently cited deficiency in OCR investigations, and the subject of OCR's ongoing Risk Analysis Initiative. It is delivered fixed-scope: asset and ePHI inventory, threat and vulnerability analysis with likelihood and impact scoring, a risk register, a risk management plan, and an attestation-ready summary letter, every finding evidence-cited.

How much does a HIPAA security risk assessment cost?

Consultant-led assessments typically run $2,000 to $15,000 for small and mid-size organizations and considerably more at enterprise firms, usually behind a quote process. Software platforms run roughly $500 to $4,000 per year and leave the analysis work to you. My pricing is published: starting at $3,500 for the practitioner-conducted assessment, and starting at $1,750 for qualifying small single-site organizations. The fee credits in full toward the Risk Management Project.

Why does it matter that you come on site?

Because 45 CFR 164.310, the physical safeguards standards, is about the physical environment, and a questionnaire cannot see one. Facility access controls, workstation location and use, device and media disposal: these are observations, not answers. Walking the building is also how the undocumented things surface: the workstation facing the waiting room, the unlocked closet with the switch in it, the fax machine, the box of drives someone meant to shred in 2019. Remote-only assessments miss those by construction.

Does MIPS require a security risk analysis?

Yes, for anyone reporting the Promoting Interoperability category. For the 2026 performance period, CMS requires attesting to two things: that a security risk analysis was conducted or reviewed during the calendar year (45 CFR 164.308(a)(1)(ii)(A)), and that risk management activities implemented security measures to address what it found (45 CFR 164.308(a)(1)(ii)(B)). Without both, the entire category scores zero. The analysis must be unique to the performance period and cover all ePHI, not only the EHR. Practices with 15 or fewer clinicians are automatically reweighted out of the category in 2026, but the underlying Security Rule obligation applies to every covered entity and business associate regardless of MIPS.

How long does it take?

The delivery window is fixed, and I give you the date at scoping rather than publishing one here, because it depends on the size of the environment. What is worth knowing up front: the clock starts when I have the documents and access I need, not when you pay, so nothing is lost if it takes you a couple of weeks to gather things. The on-site visit is usually a single day within that window.

I already have a risk analysis from someone else.

Bring it. If it holds up, you do not need another one from me and I will say so. What you likely need is the Risk Management Project that acts on it, which is the follow-through OCR's current enforcement pattern actually examines. If it does not hold up, you will know why, in writing.

Does the price include travel for the on-site walkthrough?

Within driving distance, yes: the walkthrough is in scope at the published price. Beyond it the assessment is still available, with travel quoted separately before you commit, or scoped remote with the physical-safeguards section explicitly limited and that limitation stated in the report rather than papered over. Where you are decides which of those applies, and we settle it on the scoping call before there is an invoice.

Book a scoping call.

Thirty minutes. Tell me your setting and what triggered the search, and I'll tell you whether this is the assessment you need, whether you qualify for the small-organization price, and what the on-site day looks like for you.