Notifications
You're all caught up.

The law requires a risk analysis. AI is how you finish one this month.

45 CFR 164.308(a)(1)(ii)(A) requires an accurate and thorough risk analysis, in writing, kept for six years. Most organizations know that and still do not have one, because doing it properly by hand takes months of expert time. Sherpa, the AI compliance guide inside HIPAA Sherpa, reads your evidence against the requirement each question cites, drafts your findings, risks, remediation plan, and policies, and hands a person the judgment call. One flat rate, unlimited users, no per-seat fees.

One full assessment on any framework, no credit card, up to 5 users. Unlimited users, report export, the risk register, and auditor links are paid-plan features.

The expert work, done in the time you actually have

A risk analysis is mostly reading: reading a policy to judge whether it satisfies a citation, reading a control to work out what evidence would prove it, reading a gap to decide what to do about it. Sherpa does that reading against your own data and shows its reasoning. You keep every decision.

Reviews your answers against your evidence

Sherpa reads each answer plus the documents attached to it, compares both to the requirement the question cites, and returns a verdict. It passes only what it is confident in and writes a short, specific note about what is missing when something falls short.

Reads the documents you already have

Upload a policy, a contract, or a screenshot and Sherpa summarizes what it demonstrates and which assessment questions it supports. That replaces the cross-referencing that makes evidence collection feel endless.

Drafts the risk register and the remediation plan

Deficiencies become risk-register entries with likelihood and impact, and a sequenced remediation plan with concrete steps. You review, edit, assign an owner, and set a due date rather than starting from an empty document.

Writes the policies the rule requires

Incident response, sanctions, contingency planning, device and media controls, and the rest. Each draft is seeded from your own organization context, with explicit placeholders where only you can supply the detail.

Rehearses the hard questions

Sherpa asks the kind of questions an investigator would, weighted toward your weakest areas, and rates how ready each answer is, so you find the soft spots on your own schedule instead of during an inquiry.

Triages a suspected breach against the clock

On an incident, Sherpa computes the Breach Notification Rule deadlines from the discovery date and affected count, and drafts the HHS four-factor risk assessment for your team to finalize.

Answers questions about your own program

Ask whether you are ready for an audit, or which vendors are missing a BAA, and get an answer grounded only in your organization's data, plus your three highest-impact next actions.

Never applies anything by itself

Every suggestion lands in one AI Suggestions inbox and is reviewed on its native page. A person accepts it or does not. Every AI action is written to the audit log with a timestamp and a user.

How your data is handled, stated plainly. AI processing is performed by a subprocessor under a business associate agreement with us, configured for zero retention: your content generates the response and is not retained for training. Most AI features send only aggregate counts, short labels, and regulatory text. The two features that read your uploaded evidence send that file content, which may contain PHI, to that same BAA-covered service. AI is opt-in per organization and stays off until an administrator accepts the disclosure. Nothing it produces is applied without a person accepting it, and every action it takes is audit-logged. Your organization should confirm this processing fits its own privacy and BAA posture before enabling it. Sherpa accelerates expert work. It does not replace your judgment, your counsel, or your auditor.

A risk analysis is the first thing the Security Rule asks for

The Security Rule opens with the Security Management Process standard, and the first implementation specification under it is the risk analysis. Everything else in the rule depends on it, because you cannot decide which safeguards are reasonable and appropriate for your organization until you know what your risks are.

“Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all electronic protected health information held by the covered entity or business associate.”
45 CFR § 164.308(a)(1)(ii)(A), Risk analysis (Required)

The regulation is quoted as published. How it applies to your organization depends on your role and your environment, and this page is not legal advice.

Two words in that sentence do the work, and both are testable:

  • Accurate. It has to reflect your actual environment, which means an inventory of where ePHI is created, received, maintained, and transmitted. A generic template carried over from another organization, without work to reflect your own environment, is the most common way this element fails.
  • Thorough. It has to cover the whole scope: administrative, physical, and technical safeguards, every system that touches ePHI, and every business associate that handles it on your behalf.

The obligations that follow depend on the output. 164.308(a)(1)(ii)(B) requires risk management, meaning security measures sufficient to reduce the risks you identified to a reasonable and appropriate level. 164.306(e) requires ongoing review and modification as things change. 164.308(a)(8) requires periodic evaluation. None of those are answerable without an analysis to point at.

164.308(a)(1)(ii)(A) Risk analysis
164.308(a)(1)(ii)(B) Risk management
164.308(a)(1)(ii)(D) Information system activity review
164.308(a)(8) Periodic evaluation
164.316(b)(1) Written documentation
164.316(b)(2)(i) Six-year retention
Each one cites the section it implements

“Required” means required. There is no alternative route.

The Security Rule labels each implementation specification either Required or Addressable, and the difference is frequently misread as mandatory versus optional. It is not.

Required

You must implement it, full stop

Risk analysis is Required. So are risk management, the sanction policy, information system activity review, and the six-year documentation retention. There is no reasonableness assessment to perform and no alternative measure to substitute. Either it exists and is documented, or you are out of compliance. How you satisfy it can still scale to your size and complexity under 164.306(b), but whether you satisfy it is not optional.

Addressable

Still not optional, just flexible

For an Addressable specification you assess whether it is reasonable and appropriate in your environment. If it is, you implement it. If it is not, you document why and implement an equivalent alternative measure if one is reasonable and appropriate. If neither the specification nor an alternative is reasonable and appropriate, you document that determination. Skipping it silently is the failure mode, because the written rationale is itself the compliance artifact.

HIPAA Sherpa carries the specific CFR citation and its regulatory text on every question, and marking any question Not Applicable requires a written justification, so a scoping decision is never silent. The policy templates handle the distinction directly: a clause resting on an Addressable specification is qualified in the document itself, so it never reads as a commitment you did not make.

An undocumented assessment did not happen

This is the requirement that turns good intentions into findings. You can have run a careful analysis, fixed real problems, and still fail an audit if you cannot produce the record.

“Maintain the policies and procedures implemented to comply with this subpart in written (which may be electronic) form; and if an action, activity or assessment is required by this subpart to be documented, maintain a written (which may be electronic) record of the action, activity, or assessment.”
45 CFR § 164.316(b)(1), Documentation

164.316(b)(2)(i) sets retention at six years from creation or the date last in effect, whichever is later. 164.316(b)(2)(iii) requires periodic review and updating as the environment changes. So the obligation is not one document; it is a maintained record with history.

HIPAA Sherpa keeps that record as a side effect of doing the work. Every answer, evidence upload, finding, status change, and comment is timestamped and attributed. The audit log is hash-chained and HMAC-keyed, so an alteration or a mid-chain insertion is detectable, and daily checkpoints make deletion of the tail detectable too. To be precise about what that claim is worth: it is tamper-evident, not immutable.

Every change timestamped and attributed
Hash-chained audit log, six-year retention
Signed assessments with integrity hashes
Point-in-time auditor packet with manifest
Recurring schedule carries answers forward
Full export in standard formats, any time

Weeks of calendar time, not quarters

The reason so many organizations are out of compliance on a Required specification is not that they disagree with it. It is that the traditional route is a consulting engagement measured in months, at a price that makes it an annual event rather than an operating practice.

Step
Typical manual effort
With HIPAA Sherpa
Scoping and standing up the assessment
Days of meetings
Minutes
Working through the question set
Weeks
Hours, guided
Judging evidence against each citation
Weeks of expert time
Reviewed as you go
Writing findings and the risk register
Days
Drafted, you approve
Building the remediation plan
Days
Drafted and assignable
Producing the auditor-ready report
Days of formatting
One click
Next year's cycle
Start again
Review and update

The left column is a typical range for a manual or consultant-led engagement, not a measured benchmark. Your own timeline depends on how much evidence you already have and how quickly your team reviews.

One price. No per-seat tax on compliance.

Compliance is a team activity. Your security officer, privacy officer, IT lead, practice manager, and every department head who owns a control all need to be in the system. Per-seat pricing makes you choose between doing that and paying for it, and the usual outcome is one person with a spreadsheet. So we do not charge per seat: Professional and above carry unlimited users, and Starter covers a team of up to five.

$299/mo Month to month
$299/mo Annual, paid monthly
$2,999/yr Annual, prepaid

Professional pricing. Commit to a year and pay monthly with nothing up front, or prepay the year and save close to two months. Starter is $99 a month for a single organization. Enterprise is sold direct.

Unlimited users

Every person who owns a control can be in the system, on Professional and above.

Multi-organization management

Health systems, MSOs, and consultants managing separate client entities. An Enterprise capability.

20+ frameworks

HIPAA, SOC 2, ISO 27001 and 42001, the NIST frameworks, HITRUST, PCI, and more. Answer once, reuse across all of them.

Employee HIPAA training

Annual Security and Privacy courses for unlimited employees, with quizzes, certificates, reminders, and an exportable transcript. Included on every plan.

Sherpa AI

Included on every plan, not sold as an add-on tier.

A signed BAA before any PHI

Regulated data entry is blocked until our BAA is executed by both parties. Sign ours in the app, send it to your own signatory, or upload your own paper for us to countersign.

See full pricing and plan comparison, or read the guide to HIPAA for the regulation in plain language.

The questions buyers actually ask

Is a HIPAA risk assessment actually required by law? +

Yes. The HIPAA Security Rule makes it the first thing on the list. 45 CFR 164.308(a)(1)(ii)(A) requires every covered entity and business associate to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all electronic protected health information it holds. It is a Required implementation specification, not an Addressable one, so there is no alternative-measure route and no size exemption. A solo practice is held to it just as a hospital system is, though 164.306(b) lets the depth of the analysis scale to your size, complexity, and capabilities.

How often do we have to redo it? +

The rule sets no fixed interval, which is the part that trips people up. 45 CFR 164.308(a)(8) requires periodic technical and nontechnical evaluation, and 164.306(e) requires you to review and modify your security measures as needed to keep providing reasonable and appropriate protection. Because "periodic" is undefined, most organizations adopt an annual cycle as their documented baseline and re-run the analysis whenever something material changes, such as a new EHR, a new location, a merger, a move to the cloud, or an incident. What matters to an investigator is that your interval is defined, justified, and actually followed. HIPAA Sherpa schedules the recurrence and carries your previous answers and evidence forward, so year two is a review rather than a rebuild.

Does a security scan or penetration test count as a risk analysis? +

No, and this is one of the most common and most expensive misunderstandings. A vulnerability scan looks at technical weaknesses in systems. A risk analysis is a documented, organization-wide evaluation that identifies where ePHI lives, the threats to it, the vulnerabilities those threats could exploit, the likelihood and impact of each, and your resulting risk determinations. OCR's risk analysis guidance is explicit that it must be enterprise-wide and cover administrative and physical safeguards, not only technical ones, and inadequate risk analysis is among the findings OCR cites most frequently in its enforcement actions.

What has to be written down, and for how long? +

45 CFR 164.316(b)(1) requires your policies and procedures to be kept in writing, and requires a written record of any action, activity, or assessment the rule requires to be documented. 164.316(b)(2)(i) sets the retention period at six years from the date of creation or the date it was last in effect, whichever is later. 164.316(b)(2)(iii) requires periodic review and updating. In practice an assessment you cannot produce as a record is very hard to defend: 164.316(b)(1) makes the documentation its own obligation, so a missing record is a finding in itself, independent of whether the work was done. Everything HIPAA Sherpa produces is timestamped, attributed, and exportable, and the audit trail is hash-chained so you can show the record has not been altered.

What happens if we do not have one? +

Inadequate risk analysis appears repeatedly in OCR's published resolution agreements, and it tends to show up as a root cause rather than a footnote. Civil money penalties are tiered by culpability under 45 CFR Part 160 Subpart D, from lack of knowledge up to willful neglect left uncorrected, with per-violation amounts adjusted for inflation annually and calendar-year limits that HHS applies per provision violated. The current figures are published by HHS and change, so check them rather than relying on a number in a vendor's marketing. State attorneys general have independent authority, both to bring federal HIPAA actions under HITECH, with their own lower statutory limits, and to enforce state privacy and consumer-protection laws, which is where most multistate settlements arise. Where OCR does impose a corrective action plan it typically runs for a period of years with reporting obligations to HHS throughout, though many investigations close with technical assistance instead. Beyond penalties, a missing analysis undermines your position in any breach investigation, payer audit, or acquisition diligence.

How does the AI handle our data? We are a covered entity. +

AI processing is performed by a subprocessor under a business associate agreement with us, configured for zero retention: your content is used to generate the response and is not retained for training. Most AI features send only aggregate counts, short labels, and regulatory text. The two features that read your uploaded evidence send that file content, which may contain PHI, to that same BAA-covered, zero-retention service. AI is opt-in per organization and stays off until an administrator accepts the disclosure, every AI action is written to the audit log, and nothing the AI produces is ever applied on its own. Verdicts, drafted policies, risks, remediation plans, and framework mappings all land in a review queue and a person accepts them. Your organization should confirm this processing fits its own privacy and BAA posture before enabling it.

Can we hand your output straight to an auditor or to OCR? +

Yes, with your counsel's review. Submitting anything to OCR in an open investigation is a legal decision, not a document export. What the platform does is make the record easy to produce and easy to defend. Every question carries the specific CFR citation it implements, findings link to the requirement they implicate, evidence attaches to the control it supports, and the report exports as a formatted document with an executive summary, question-by-question detail, gap analysis, and the risk register. The auditor packet is a single point-in-time export with a manifest, and you can also issue a time-limited read-only link to the live program instead of emailing files around. We are not a law firm and this is not legal advice.

What does it cost, and are there per-seat fees? +

Flat rate, and no per-seat fees. Professional is $299 a month with unlimited users, or $2,999 for the year if you prepay, which saves close to two months. You can also commit to a year and pay $299 monthly with nothing up front. Employee HIPAA training is included on every plan for unlimited employees. Every plan starts with a free 30-day evaluation and one full assessment, no credit card.

Not legal advice. HIPAA Sherpa is a compliance platform, not a law firm, and nothing on this page is legal advice. The citations here are to the regulation as published; your obligations depend on your organization, your role as a covered entity or business associate, and applicable state law, which HIPAA does not displace where it is more stringent (45 CFR 160.202 and 160.203). Have your counsel or your auditor review what you rely on.

Start the assessment the rule requires

Free for 30 days, one full assessment on any framework, no credit card, up to 5 users. Unlimited users, report export, the risk register, and auditor links are paid-plan features.