Healthcare IT

HIPAA Risk Assessments: Scope & Cost

The risk analysis is the one document every practice is expected to produce on request, and the one most commonly missing. What a real assessment covers, published cost ranges, and how to avoid paying for a checkbox.

Published July 16, 2026 • Synergy Telecom & Medical Systems, Rome GA

Why this document matters more than the rest

The Security Rule requires covered entities and business associates to conduct an accurate, thorough assessment of risks to ePHI. It is the foundation the rest of compliance stands on, because you cannot safeguard what you have not mapped.

It also has practical teeth beyond enforcement: cyber insurance applications, some payer and incentive programs, and breach investigations all ask for it. When regulators cite practices, a missing or stale risk analysis is one of the most frequent findings. Our HIPAA IT requirements guide shows where it sits among the other safeguards.

What a proper assessment covers

A real risk analysis is a mapping exercise before it is a judgment exercise:

  • Inventory of everywhere ePHI is created, stored, and sent
  • The threats and vulnerabilities that apply to each location
  • The safeguards currently in place
  • Likelihood and impact ratings for each risk
  • A prioritized, dated remediation plan

The output should read like a map of your practice, naming your EHR, your devices, your vendors, and your workflows. If a report could describe any practice in Georgia by swapping the letterhead, you bought a template, not an assessment.

What it costs

Published 2026 ranges vary with practice size and scope:

  • Small single-site practice: $2,000 to $10,000+
  • Larger or multi-site organizations: $10,000 to $25,000+

There is also a legitimate free path: HHS and ONC publish a Security Risk Assessment (SRA) tool that walks a practice through the exercise. It is genuinely usable for a small practice with a patient owner and time to invest; its limits are honesty about your own blind spots and the hours it quietly consumes. Many practices land on a hybrid: an independent assessment first, then the tool for interim years.

How often, and what triggers a redo

Annual review is the working standard, with a fresh look after material changes: a new EHR, a new location, a merger, or an incident.

The document is supposed to be alive. A five-year-old PDF describing software you no longer run does not help you in an audit, and it does not help your team make decisions today.

The part that actually reduces risk

The assessment is the diagnosis. The remediation plan is the treatment, and it is the half that vendors selling assessment theater tend to skip.

Findings should convert into dated, owned fixes: MFA rollouts, backup testing, BAA cleanup, disposal procedures. That work often folds naturally into a managed IT relationship, which is how we structure it on our HIPAA compliance engagements. Paying for findings twice because nobody fixed them the first time is the most expensive outcome on this page.

Risk assessment: FAQs

Is a risk analysis legally required? Yes, for covered entities and business associates under the Security Rule. It is not an optional best practice, and being small does not exempt a practice from it.

Can we do the assessment ourselves? A small practice can, using the free HHS/ONC SRA tool, if someone senior gives it real hours and honest answers. Independent assessments earn their fee by catching the risks you have normalized and by producing documentation that stands up to outside scrutiny.

Is this what Synergy Telecom charges for one? The figures here are published market ranges, not our quote. Scope drives cost: provider count, locations, and how much of the environment has been documented before. We price after a scoping conversation, which costs nothing.

How long does an assessment take? For a small practice, typically days of focused work spread over a few weeks of elapsed time, driven mostly by interview scheduling and document gathering. Multi-site organizations run longer.

Overdue for one, or never had one? Contact us to scope a risk assessment that ends in fixes, not just findings.

2026 Cost Ranges

Published ranges. Scope and site count drive the number.

• Small practice: $2,000 to $10,000+
• Multi-site: $10,000 to $25,000+
• DIY: free SRA tool + your hours
• Cadence: annual + after changes
Scope My Assessment

Related reading: HIPAA IT requirementsManaged IT costs