What a first year of HIPAA compliance actually costs, component by component, on publicly reported ranges. Including the one line item that is always zero, because there is no HIPAA certification to buy.
HIPAA compliance costs a small single site organisation roughly US$4,000 to US$12,000 in the first year, and a large multi location organisation US$78,000 and above, on ranges published by Compliancy Group. HIPAA Journal puts a mid range estimate at US$80,000 to US$120,000. None of those totals contains a certification fee, because HIPAA has no certification. The money goes on a security risk analysis, remediating what that analysis finds, policies, workforce training, business associate agreements, and software to hold the evidence. Compliance software is the smallest line: CertAssist is US$225 per month as of September 2026.
HIPAA compliance cost is not one price. It is a set of separately purchased services, of which only one is software. The service figures in the table below are the ranges Compliancy Group publishes for a small single location organisation and for a large multi location organisation. The CertAssist figure was read from certassist.io on 22 September 2026. The two published totals cover services only, so software sits on top of them rather than inside them.
| Cost component | Small single site | Large multi location | Who charges it |
|---|---|---|---|
| Security risk analysis and risk management plan | About US$2,000 | US$20,000 and above | Consultant or assessor, or your own team |
| Remediating what the risk analysis found | US$1,000 to US$8,000 | US$8,000 and above | Mostly internal time, plus any tooling you buy |
| Policies, procedures and workforce training | US$1,000 to US$2,000 | US$5,000 and above | Consultant, training vendor, or a template you edit |
| Onsite audit, where one is commissioned | Rarely commissioned | US$40,000 and above | Audit firm. Voluntary, not a HIPAA requirement |
| Vulnerability scanning | Often bundled | About US$800 | Scanning vendor |
| Penetration testing | Optional | US$5,000 and above | Testing firm |
| Compliance platform | CertAssist is US$225 per month, or US$2,475 per year | Software vendor. Priced the same at either size | |
| HIPAA certification | US$0 | US$0 | Nobody. No HIPAA certification exists |
| Published first year services total | US$4,000 to US$12,000 | US$78,000 and above | Compliancy Group published ranges |
There is no HIPAA certification, so the certification line in a HIPAA budget is always US$0. The Department of Health and Human Services says so directly in its published FAQ on certifying compliance: "there is no standard or implementation specification that requires a covered entity to 'certify' compliance", and "HHS does not endorse or otherwise recognize private organizations' 'certifications' regarding the Security Rule". A badge sold as HIPAA certification buys you a badge. It does not reduce your obligations and it does not stop an enforcement action.
That matters for budgeting, because it is the single biggest structural difference between HIPAA and the frameworks it gets compared against. With ISO 27001 or SOC 2 you pay an accredited certification body or a CPA firm, and that fee is usually the largest line. With HIPAA there is no such fee at all, which is why a small HIPAA programme can cost less than a SOC 2 report while still taking similar internal effort. See SOC 2 versus HIPAA for which one a customer is actually asking you for.
HIPAA compliance software is the most predictable line in the budget and usually the smallest. CertAssist costs US$225 per month as of September 2026, a launch price against a normal rate of US$375 per month, or US$2,475 per year, and that price covers every framework CertAssist supports rather than HIPAA alone. Vanta, Drata and Secureframe do not publish list pricing for their platforms, so a comparable figure for them cannot be quoted honestly here. Their pricing sits behind a sales conversation, which means the only way to get a number is to ask for one and to ask what happens to it at renewal.
What the software is buying is organisation rather than automation: the HIPAA Security, Privacy and Breach Notification Rule requirements laid out as a control set, editable policy templates, an evidence checklist against each requirement, and read only access so an assessor or a customer's auditor can review the evidence without you emailing a zip file. CertAssist has no integrations by design, so it never asks for access to your cloud, identity provider or code. For how the wider market prices this, see what compliance software actually costs.
The security risk analysis is the cost driver, and it is the one item HIPAA explicitly requires. The Security Rule makes a risk analysis a required implementation specification at 45 CFR 164.308(a)(1)(ii)(A), which means it is not optional and not satisfiable by a checklist alone. Compliancy Group publishes about US$2,000 for a small single location organisation and US$20,000 and above for a large multi location one. Doing it internally is legitimate and common, and it trades cash for perhaps 20 to 40 hours of a competent person's time on a first pass. Whichever way it is done, the output has to be a written analysis with identified risks, likelihood, impact and a management plan, because that document is the first thing an investigator asks for.
HIPAA workforce training is usually bundled with policy development in vendor quotes, which is why Compliancy Group publishes US$1,000 to US$2,000 for policies and training together at a small organisation, and US$5,000 and above at a large one. Bought separately, per seat training is normally the cheapest line in the whole programme. The recurring part is what people underestimate: training has to be delivered to new starters and refreshed periodically, and the evidence that matters is the completion record with names and dates, not the course itself.
A realistic HIPAA budget depends far more on how many systems hold protected health information than on headcount. The three profiles below use the published ranges above, with software added at the CertAssist annual price so the totals are comparable. Treat the profiles as planning shapes, not survey data.
| Organisation profile | What the first year usually includes | Indicative first year total |
|---|---|---|
| Solo or small practice, one site, off the shelf systems | Risk analysis, light remediation, policies, training, BAAs, platform | About US$6,500 to US$14,500 |
| Health tech startup acting as a business associate | Risk analysis, engineering remediation, policies, training, BAAs, platform, often a penetration test | About US$12,000 to US$25,000 |
| Large multi location provider | All of the above plus an onsite audit, scanning and testing at scale | US$80,000 and above |
The startup profile is the one most often mispriced. A company that is a business associate rather than a covered entity still has to sign BAAs, run the risk analysis and meet the Security Rule, and its remediation cost lands on engineering rather than on a consultant invoice, so it disappears from the quote and reappears in the sprint.
HIPAA penalties are set out in four culpability tiers at 45 CFR 160.404, which prints a US$1,500,000 calendar year cap against every tier. That is not what the Office for Civil Rights actually applies. Under its 2019 Notification of Enforcement Discretion, HHS lowered the annual cap for the first three tiers and left the regulation text unamended, so the two columns below differ. The per violation figures are statutory base amounts that are adjusted for inflation each year and published at 45 CFR part 102, which means the amounts applied today are higher than the base figures shown.
| Tier | Culpability | Statutory minimum per violation | Annual cap printed in 45 CFR 160.404 | Annual cap HHS applies since 2019 |
|---|---|---|---|---|
| 1 | Did not know, and would not have known with reasonable diligence | US$100 | US$1,500,000 | US$25,000 |
| 2 | Reasonable cause, not willful neglect | US$1,000 | US$1,500,000 | US$100,000 |
| 3 | Willful neglect, corrected within 30 days | US$10,000 | US$1,500,000 | US$250,000 |
| 4 | Willful neglect, not corrected | US$50,000 | US$1,500,000 | US$1,500,000 |
The practical lesson in that table is the gap between tier 3 and tier 4. Correcting a known problem within 30 days moves the statutory minimum from US$50,000 to US$10,000 per violation, and the annual cap HHS applies from US$1,500,000 to US$250,000. That is an argument for keeping a dated record of when an issue was found and when it was fixed, which is ordinary compliance hygiene rather than anything exotic.
A compliance platform is the wrong purchase in three situations. If what you need is someone to perform the security risk analysis for you, buy an assessor, not software, because no platform performs the analysis on your behalf. If you are a single practitioner with one laptop and one practice management system, a well kept folder and a template set may genuinely be enough for the first year. And if your board wants continuous automated evidence collected straight from your cloud infrastructure, CertAssist is not that product, by design: it has no integrations, which is the whole reason it never needs access to your systems.
CertAssist also does not provide legal advice, and it does not stand in for a certification body on the frameworks that have one. On HIPAA specifically, nothing anyone sells makes an organisation HIPAA certified, because that status does not exist.
A small single site organisation should budget roughly US$4,000 to US$12,000 for the first year of HIPAA compliance services, on ranges published by Compliancy Group, and a large multi location organisation US$78,000 and above. Add software on top: CertAssist is US$225 per month as of September 2026. No part of either figure is a certification fee, because HIPAA has no certification.
HIPAA compliance is less expensive than most certifications for a small organisation, because there is no accredited audit to pay for. A solo practice can reach a defensible position for a few thousand US dollars plus staff time. It becomes expensive at scale, where published figures run past US$78,000, and where onsite audits and penetration testing get added.
HIPAA penalties sit in four tiers set by 45 CFR 160.404, based on culpability. The statutory minimums per violation are US$100 for lack of knowledge, US$1,000 for reasonable cause, US$10,000 for corrected willful neglect and US$50,000 for uncorrected willful neglect. Annual caps that HHS applies run from US$25,000 at tier one to US$1,500,000 at tier four. The base figures are adjusted for inflation annually.
HIPAA compliance is mandatory for covered entities and for their business associates. A covered entity is a health plan, a healthcare clearinghouse, or a healthcare provider transmitting health information electronically in connection with a covered transaction. A business associate is any organisation handling protected health information on a covered entity's behalf, which is where most software companies land.
A BAA is a business associate agreement, the written contract a covered entity must have in place with any vendor that handles protected health information on its behalf. The agreement sets out permitted uses, safeguards, breach reporting and what happens to the data at termination. A BAA costs nothing to sign, but chasing signatures across a vendor list takes real time.
CertAssist lays out every HIPAA requirement alongside SOC 2, ISO 27001 and the rest, gives you editable policy and evidence templates, and lets your assessor review it all in one place, for a flat $225 a month.
See pricing FrameworksFlat $225 a month, or $2,475 a year (12 months for the price of 11). All prices in USD.