Free HIPAA SRA tool

A free HIPAA Security Risk Assessment — actually complete.

No trial timer, no "request a demo," no card. Ward's free tier runs the entire Security Risk Assessment a small practice needs — and keeps your patient data on your own machine.

Start your free SRA → vs. the ONC SRA Tool

What "free" actually includes

Free isn't a teaser tier. It's a genuine ONC-tool replacement that a clinic can rely on for its annual risk analysis.

🛡️

All 7 safeguard areas

Administrative, physical, and technical safeguards across the full HIPAA Security Rule, each question tied to its 45 CFR citation.

🧮

~120 rubric-scored questions

Seeded from the ONC content, each with plain-English guidance and a Required / Now-Required-2026 flag.

📊

Risk register & heatmap

Rate each gap by likelihood × impact into Low / Moderate / High, ranked into a risk-management plan.

⏱️

2026 readiness meter

See which new mandatory items you've met and what's left — encryption, MFA, asset inventory, BA verification.

🤝

Vendor & BAA tracking

Track each business associate's ePHI access and BAA status, including the 2026 verification expectation.

📄

Reports & print-to-PDF

Export a full SRA, executive summary, POA&M, and CSV risk register — or print an audit binder, all on-device.

Where the paid tiers start: cloud sync across devices, the full 2026 gap report with a tracked POA&M, policy/BAA/training management, the OCR audit binder, and the MSP multi-client console. The assessment itself is free, forever. See pricing →

Common questions

Is the HIPAA SRA tool really free?
Yes — the local tier is a complete SRA at $0, including the risk register, the 2026 readiness meter, vendor/BAA tracking, and exports. No signup, no card.
What's the catch?
None on the SRA. Paid tiers add cloud sync, the full 2026 gap report with POA&M, policy/BAA/training, the audit binder, and the MSP console — but the assessment and its reports stay free.
Does it meet the HIPAA SRA requirement for MIPS?
Ward produces a documented, dated risk analysis and risk-management plan using the same 7 sections and NIST-aligned method the MIPS measure expects. It's a self-assessment aid, not legal advice.

Start your free HIPAA SRA now.

Runs in your browser. No signup, no card, no PHI in anyone's cloud.

Launch the free SRA