HIPAA Security Risk Assessment · Free · Local-first

Your HIPAA Security Officer in a box.

A free, plain-English Security Risk Assessment built for the clinic where the office manager is the Security Officer. A live 2026 Security Rule readiness meter shows exactly where you stand — mandate by mandate, severity-weighted — and turns every gap into a tracked plan. All without your patient data ever leaving your machine.

Start your free SRA → See the 2026 changes
40%
Live 2026 readiness meter
Toggle what you've already got — higher-severity mandates move it more. Watch your readiness climb.
PHI never leaves your machine
Built for the 2026 Security Rule
45 CFR §164 cited on every question
Mac · Windows · Linux · browser

Everything an auditor asks for — in an afternoon

Ward mirrors the ONC/HHS SRA Tool's rigor and adds what nobody in the small-practice price band ships well: a live, severity-weighted 2026 readiness meter, and the modules the new rule turns into requirements — asset inventory, written policies, recurring-test tracking, and an incident & breach log with built-in notification deadlines.

🛡️

Guided 7-section SRA

Administrative, physical, and technical safeguards across the full HIPAA Security Rule — each question in plain English, tied to the exact 45 CFR citation.

⏱️

Live 2026 readiness meter

Ten headline 2026 mandates, each scored Ready / Partial / Gap and weighted by severity — and each labeled proposed or final so you know what's settled. Your single most-important number, live as you answer.

📋

Per-mandate & per-question POA&M

Risk management, not just analysis. Give every gap — and every 2026 mandate — an owner, target date, and status. Ward flags what's overdue and sorts the 2026-required items first.

🗂️

Asset inventory & data map

The 2026-required inventory of every system that touches ePHI, with a written data map. Ward flags any asset that holds ePHI but isn't encrypted.

📑

Policy management

Ten editable, plain-English HIPAA policy templates — each CFR-cited — with local version history and workforce attestation. Export the whole manual.

🔁

Scan / pen-test / IR cadence

Track the recurring 2026 obligations — vuln scans, pen tests, BA verification, backup-restore and IR-plan tests. Ward computes the next due date and warns you before it lapses.

📊

Risk register & heatmap

Rate each gap by likelihood × impact into Low / Moderate / High, ranked into an audit-ready risk-management plan.

🤝

Vendors & BAAs

Track every business associate, their ePHI access, and BAA status — and the 2026 vendor-verification expectation.

🚨

Incident & breach log

Document security incidents and breach determinations as 45 CFR 164.308(a)(6) requires — and Ward computes the Breach Notification Rule deadlines (individuals, HHS, media) from the discovery date, flagging anything overdue.

🎓

Workforce training records

Track who's on staff, the courses they owe, and completion dates — with annual-renewal flags and an exportable training log auditors ask for.

🔒

Local-first by default

It all runs in your browser. Your answers and patient data stay on your machine. Nothing to leak, nothing in someone else's cloud — and the local tier is free.

From zero to audit-ready, in four steps

Answer the questions

Work through the 7 safeguard areas. Each has plain-English guidance — no security background needed.

Rate your risks

For each gap, pick a threat and rate likelihood and impact. Ward computes Low / Moderate / High automatically.

Track every gap to closure

The severity-weighted meter shows which 2026 mandates you've met and what's left. Assign each gap and each mandate an owner, target date, and status — Ward flags what's overdue.

Export your binder

One click bundles the SRA, risk-management plan, POA&M, 2026 gap report, asset inventory, policy manual, cadence log, and incident & breach log into an OCR audit binder. Print to PDF for your records or an auditor.

Launch the free SRA →

See the working tool

A readiness score, not a 200-page checklist.

Ward opens to one number: how ready you are for the proposed 2026 Security Rule. Ten headline mandates roll up into a live, severity-weighted meter — a missed critical (encryption, MFA, risk management) moves it more than a moderate one — with the exact gaps ranked by what to fix first.

  • Each mandate labeled proposed or final — no overclaiming
  • Every mandate becomes a tracked POA&M item (owner / target / status)
  • Renders entirely in your browser — no PHI uploaded

Open the live app →

Built for the person who got handed "HIPAA"

Office managers, practice owners, and fractional CISOs use Ward to finish a real SRA without a security background — or a hospital budget.

"I'm the office manager, the scheduler, and apparently the Security Officer. Ward got us a finished risk assessment in an afternoon — and nothing left the building."

Practice manager · 4-provider dental clinic

"The 2026 readiness meter is the first time anyone showed me, in plain English, exactly what we still have to fix before the new rule lands."

Owner · behavioral health practice

"As an MSP I was paying per-client for tools that still didn't have a real SRA. Ward bundles the whole program for a fraction."

vCISO · healthcare-focused MSP

Illustrative scenarios representing Ward's target users while the product is in early access.

More program, a fraction of the price

The named alternatives are cloud-only and priced for hospitals or funded startups. Ward sits in the small-practice band with more included.

  Ward Accountable Medcurity Compliancy Group
Entry price$0 / $159/mo$199/mo~$499/yr~$2k–$8k+/yr
Free SRA questionnaire + 2026 metertrial
Local-first PHI
2026 readiness meter (per-mandate, weighted)partialpartialpartial
Asset inventory · policies · cadence tracking Solopartialpartialtiered
Vuln/pen-test & custom rolesincluded$799 tierupselltiered

See the full comparison & pricing →

Common questions

Is Ward really a free HIPAA Security Risk Assessment tool?
Yes. Ward Free runs the full 7-safeguard SRA questionnaire and the live, severity-weighted 2026 readiness meter — at $0, for 1 user and 1 entity, running locally in your browser with no signup and no card. It's built to replace the free ONC/HHS SRA Tool for clinics that need a Mac/Linux- and browser-friendly option. Solo ($159/mo) adds the working tools: exports, the POA&M tracker, asset inventory, the policy module, cadence tracking, and the OCR audit binder.
What does the 2026 readiness meter actually do?
It scores you against the ten headline obligations of the proposed 2026 Security Rule and updates live as you answer. Each mandate is marked Ready, Partial, or Gap and weighted by severity — so a missed critical (encryption, MFA, written risk management) costs you more than a moderate one. Because the rule isn't final yet, Ward labels each mandate individually as proposed or final and ships the rule as a versioned content pack, so it stays honest about what's settled. Each mandate also becomes a tracked POA&M item with an owner, target date, and status.
How is Ward different from the ONC SRA Tool?
The ONC SRA Tool is Windows-only and SRA-only. Ward runs in any browser (and as a desktop app on Mac, Windows, and Linux), keeps the same rubric-based rigor, and adds a one-click 2026 Security Rule readiness report plus a vendor/BAA tracker — while keeping the gov tool's best feature: your patient data never leaves your machine.
Does my patient data (PHI) stay private?
Yes. Ward is local-first: your answers and any patient data are stored in your own browser or on your own device, never uploaded to our servers by default. Reports are rendered on your machine. Optional cloud sync (a paid feature) syncs control state, not patient data.
What is the 2026 HIPAA Security Rule and why does it matter?
The proposed 2026 overhaul (the December 2024 NPRM — not yet final) ends the "addressable vs. required" distinction and makes encryption everywhere, MFA on ePHI, regular vulnerability scans, a written asset inventory and data map, and business-associate verification mandatory. Every small practice has to re-baseline — and Ward's readiness meter, asset-inventory module, and cadence tracker map directly to the new requirements so you can see exactly where you stand.
Who is Ward for?
Small healthcare practices and business associates in the USA and Canada — primary care, dental, behavioral health, optometry, chiro, PT, med spas, billing companies — where the office manager or owner is the designated HIPAA Security Officer with no security background. There's also an MSP multi-client console.

You don't need a security team. You need Ward.

The free local SRA questionnaire and 2026 readiness meter are an ONC-tool replacement that runs on any machine. Start now; no signup, no card, no PHI in anyone's cloud.

Start your free SRA

Explore Ward

Free HIPAA SRA tool

What "free" actually includes — and how it replaces the ONC tool.

SRA tool for Mac

The ONC tool is Windows-only. Ward runs on Mac, Linux, and the browser.

For healthcare MSPs

Run a templated SRA across every client and bulk the 2026 gap report.

Compare Ward

vs. the ONC SRA Tool, Accountable, Medcurity, and Compliancy Group.