Free HIPAA SRA tool

A free HIPAA Security Risk Assessment — actually complete.

No trial timer, no "request a demo," no card. Ward's free tier runs the entire Security Risk Assessment a small practice needs — and keeps your patient data on your own machine.

Start your free SRA → vs. the ONC SRA Tool

What "free" actually includes

Free isn't a teaser tier. It's a genuine ONC-tool replacement that a clinic can rely on for its annual risk analysis.

🛡️

All 7 safeguard areas

Administrative, physical, and technical safeguards across the full HIPAA Security Rule, each question tied to its 45 CFR citation.

🧮

~120 rubric-scored questions

Seeded from the ONC content, each with plain-English guidance and a Required / Now-Required-2026 flag.

📊

Risk register & heatmap

Rate each gap by likelihood × impact into Low / Moderate / High, ranked into a risk-management plan.

⏱️

Live 2026 readiness meter

See which new mandatory items you've met and what's left — encryption, MFA, asset inventory, BA verification — updating live as you answer.

💻

1 user, 1 entity, on-device

Runs entirely in your browser for a single practice — no account, no card, no PHI in anyone's cloud.

🔓

No trial timer

The questionnaire and readiness meter are free forever, not a teaser that expires.

Where Solo ($159/mo) starts: exports (PDF/CSV/Excel/Markdown), the POA&M tracker, asset inventory, the policy module, the scan/IR cadence tracker, the OCR audit binder, and cloud sync across devices. The MSP multi-client console is its own tier. The SRA questionnaire and readiness meter stay free, forever. See pricing →

Common questions

Is the HIPAA SRA tool really free?
Yes — the local tier runs the full SRA questionnaire and the live 2026 readiness meter at $0, for one practice, on your own machine. No signup, no card.
What's the catch?
None on the questionnaire. Solo ($159/mo) adds the working tools — exports, the POA&M tracker, asset inventory, the policy module, cadence tracking, and the OCR audit binder — plus cloud sync; the MSP console is its own tier. The SRA questionnaire and readiness meter stay free.
Does it meet the HIPAA SRA requirement for MIPS?
Ward produces a documented, dated risk analysis and risk-management plan using the same 7 sections and NIST-aligned method the MIPS measure expects. It's a self-assessment aid, not legal advice.

Start your free HIPAA SRA now.

Runs in your browser. No signup, no card, no PHI in anyone's cloud.

Launch the free SRA