Screenata

SOC 2 Cost and Budget

How much does a HIPAA audit cost?

August 22, 20263 min read

How much does a HIPAA audit cost?

It depends on which of three things you mean. A third-party HIPAA risk assessment runs roughly $5,000 to $20,000 for a small organization. A formal third-party attestation examination against the HHS rules runs roughly $10,000 to $30,000 or more depending on size. And an OCR investigation, the only audit-like event with government force behind it, is not something you buy at all. There is no official HIPAA audit and no official HIPAA certification, so every quoted price is for private work.

The three things "HIPAA audit" can mean

What people meanWhat it actually isRough cost
Risk assessment or gap assessmentA review of how PHI moves through your systems and where safeguards fall short; required by the Security Rule and can be done internallyRoughly $5,000 to $20,000 with a third-party consultant for a small organization; internal cost is staff time
Third-party attestation or examinationAn independent firm examines your safeguards against the Privacy and Security Rules and issues a report you can show customersRoughly $10,000 to $30,000 or more, scaling with organization size
OCR investigationA regulatory action by the HHS Office for Civil Rights, triggered by a breach report or complaintNot purchasable; costs arrive as legal fees, corrective action plans, and potential penalties

When a customer asks for proof of your HIPAA compliance, they usually mean the second row. When your own team says "we should get a HIPAA audit," they usually mean the first.

What drives the price

Scope. An assessor prices the engagement on the number of systems that store or transmit PHI, the number of PHI flows between them and to vendors, workforce size, and physical locations. A ten-person telehealth startup with one cloud environment sits at the bottom of the ranges above. A multi-site provider group with an EHR, imaging systems, and dozens of business associates sits well past the top of them.

The quoted fee is also not the whole cost. An assessment produces findings, and remediating them, tightening access, adding logging, signing missing BAAs, writing the policies that do not exist yet, is engineering and administrative time the assessor's invoice never shows.

There is no official certification to buy

This is the fact that reframes the budget question. HHS certifies nothing and endorses no assessor, so no amount of spending produces a government-recognized HIPAA credential. A third-party attestation is still worth paying for, because customers accept it as evidence, but it is evidence of a private examination, and any vendor selling a "HIPAA certification" is selling exactly that. What the law actually requires is the underlying work: a documented risk analysis, safeguards that operate, and BAAs with every vendor that touches PHI.

Where Screenata fits

Screenata covers the readiness and evidence side of that work: the documented risk assessment, policies generated from scans of your actual infrastructure, and about 70% of evidence collected automatically, packaged in cryptographically signed evidence packs. The HIPAA program costs $5,988/year per framework ($499/mo) for teams under 50 employees; see /pricing. If a customer requires a third-party examination on top of that, the examining firm is independent and its fee is separate.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.