The Security Risk Assessment: pricing, scope, and 10-business-day turnaround
Every covered entity and business associate is required to conduct a security risk analysis under 45 CFR 164.308(a)(1)(ii)(A). It is the foundation the rest of the Security Rule builds on, the most frequently cited deficiency in OCR investigations, and the artifact MIPS reporters attest to each year. It also covers your whole ePHI surface as it actually exists: OCR expects the analysis to address the AI tools in use, vendor AI access, and shadow AI alongside everything else, and this assessment does. Rote delivers it fixed-scope and priced up front, starting at $3,500: a practitioner's judgment on Rote's analysis engine, every finding evidence-cited, in 10 business days from complete intake.
Enter where your program actually is:
| Offer | Price | What you get |
|---|---|---|
| HIPAA Self-Check | Free | Run the open-source HIPAA skills yourself, including the Risk Assessment skill, or start with the free Snapshot. A first read of your posture in your own environment. |
| HIPAA Security Risk Assessment | starting at $3,500 | The security risk analysis required by 45 CFR 164.308(a)(1)(ii)(A), conducted by a practitioner on Rote's analysis engine: asset and ePHI inventory (including AI tools and vendor AI access, which OCR expects the analysis to address), reasonably anticipated threats and vulnerabilities, likelihood and impact scored with written rationale, a risk register you keep, a risk management plan with 30/60/90 actions, and an attestation-ready summary letter. Every finding evidence-cited. Single entity or site, 10 business days from complete intake. |
| Small-Organization SRA | starting at $1,750 | The same artifact set for single-site organizations that are nonprofit or public, under roughly $2M revenue, or 15 or fewer staff. Mostly automated on standard templates, ratified by the practitioner. If real complexity surfaces, the engagement routes to the full assessment with this fee credited. Nonprofit and public-entity discount applies. |
| Risk Management Project | starting at $8,000 | Implementation of the risk management plan per 45 CFR 164.308(a)(1)(ii)(B): corrected policies and procedures, safeguard documentation, BAA language, and an evidence log showing the analysis was acted on — including AI-specific gaps where the findings warrant it (AI use policy, governance charter, vendor-review process). Already have a risk analysis from another provider? Bring it, and the Project closes the gaps it surfaced. OCR's current enforcement pattern examines exactly this follow-through. |
| Maintenance | starting at $750/mo | The annual SRA refresh (MIPS requires a fresh analysis each performance period; OCR expects it reviewed as your environment changes), quarterly reviews, the annual SAFER Guide self-assessment for MIPS reporters, and a watch on the proposed Security Rule overhaul. The annual refresh alone is the $3,500 assessment. |
The 2026 attestation is two statements, and both point here.
For the Promoting Interoperability category, CMS requires a yes to both: a security risk analysis conducted or reviewed during the calendar year of the performance period (45 CFR 164.308(a)(1)(ii)(A)), and risk management activities that implemented security measures to address what it found (45 CFR 164.308(a)(1)(ii)(B)). Miss the measure and the entire category scores zero, which puts the 75-point threshold, and up to a 9% adjustment on 2028 Medicare payments, in play.
The analysis must be unique to the performance period, conducted January 1 to December 31, and scoped to all ePHI you create, receive, maintain, or transmit, not only the EHR. The assessment above is built to that standard. Maintenance carries the annual refresh and the SAFER Guide self-assessment that reports alongside it.
Groups of 15 or fewer clinicians are automatically reweighted out of the category in 2026. The Security Rule obligation applies regardless of MIPS, and it is what OCR's Risk Analysis Initiative enforces.
Pricing is disclosed up front. Multi-site organizations are quoted per site. Business associates: the assessment includes a findings summary usable in enterprise security reviews. Need the wider HIPAA picture, the Privacy Rule, the proposed Security Rule overhaul, business associates, state law? See the full HIPAA guide.
Common questions about the Security Risk Assessment.
The security risk analysis required by 45 CFR 164.308(a)(1)(ii)(A): an assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI your organization creates, receives, maintains, or transmits. It is the foundation the rest of the Security Rule builds on, the most frequently cited deficiency in OCR investigations, and the subject of OCR's ongoing Risk Analysis Initiative. Rote's fixed-scope Security Risk Assessment delivers it in 10 business days: asset and ePHI inventory, threat and vulnerability analysis with likelihood and impact scoring, a risk register, a risk management plan, and an attestation-ready summary letter, every finding evidence-cited.
Consultant-led assessments typically run $2,000 to $15,000 for small and mid-size organizations and considerably more at enterprise firms, usually behind a quote process. Software platforms run roughly $500 to $4,000 per year and leave the analysis work to you. Rote publishes its pricing: starting at $3,500 for the practitioner-conducted assessment, and starting at $1,750 for qualifying small single-site organizations, delivered in 10 business days, priced up front. The fee credits in full toward the Risk Management Project.
It has to. The analysis must address risks to all ePHI your organization creates, receives, maintains, or transmits, and OCR has made clear that includes AI tools in use, vendor AI access, and unsanctioned staff AI use. Rote's assessment inventories your AI surface as part of the standard scope. If the findings warrant a standing AI governance program rather than point fixes, that is the AI Governance engagement, built from the same assessment.
Yes, for anyone reporting the Promoting Interoperability category. For the 2026 performance period, CMS requires attesting to two things: that a security risk analysis was conducted or reviewed during the calendar year (45 CFR 164.308(a)(1)(ii)(A)), and that risk management activities implemented security measures to address what it found (45 CFR 164.308(a)(1)(ii)(B)). Without both, the entire category scores zero. The analysis must be unique to the performance period and cover all ePHI, not only the EHR. Practices with 15 or fewer clinicians are automatically reweighted out of the category in 2026, but the underlying Security Rule obligation applies to every covered entity and business associate regardless of MIPS.
It can be. The ONC and OCR jointly publish the SRA Tool, and CMS points MIPS participants to it. It is a legitimate way to conduct the analysis if you have the staff time to work through it properly and document the results. What it does not supply is the time itself, findings cited to your actual documents, or a practitioner-signed report and risk management plan. If you have the capacity, use it, and run our free Self-Check alongside. If you do not, that is the gap the fixed-scope assessment fills.
See where your HIPAA program stands.
The Readiness Snapshot is free. It places your organization on Rote's compliance maturity matrix and shows where your documentation is thin against HIPAA, within one week. Diagnostic, not a sales call.