ONC SRA Tool alternative

The ONC SRA Tool, without the Windows-only catch.

The free ONC/HHS Security Risk Assessment Tool is the credible baseline — but it only runs on Windows (or as an Excel workbook), it's single-user, and it stops at the SRA. Ward keeps the rigor, runs anywhere, and adds the 2026 readiness report.

Try the free SRA → See the 2026 changes

Where Ward keeps the ONC tool — and where it goes further

Ward deliberately mirrors the ONC SRA Tool's 7 sections, ~120 rubric-scored questions, threat/vulnerability catalog, and likelihood × impact rating, so it's familiar and audit-credible. Then it closes the gaps clinics complain about.

CapabilityONC/HHS SRA ToolWard
PriceFreeFree (local tier)
Runs on Mac & LinuxNo (Windows / Excel only)Yes — browser + Mac/Win/Linux desktop
7 sections, rubric-scored questionsYesYes — same structure & 45 CFR citations
Threat/vulnerability catalogYesYes — extended with 2026-era threats
Likelihood × impact ratingYes (Low/Mod/High)Yes — identical NIST-aligned math
Plain-English guidance per questionLimitedYes — written for a non-technical Security Officer
PHI stays on your machineYesYes — local-first by default
2026 Security Rule readiness reportNoYes — one-click, live meter
Vendor / BAA trackingVendor list onlyYes — BAA status + 2026 verification
Import an in-progress ONC filen/aOn the roadmap (migration importer)
Multi-user / MSP multi-clientNoYes (cloud tiers)

Why this matters: the ONC tool's biggest real-world complaints are "it won't run on our Macs," "only one person can use it," and "it doesn't tell me about 2026." Ward fixes all three without giving up the local-first PHI model that makes the gov tool trustworthy.

Common questions

Is there a free alternative to the ONC SRA Tool that runs on Mac?
Yes — Ward runs in any browser and as a desktop app on macOS, Windows, and Linux, with the same rubric-based scoring. The ONC SRA Tool is Windows-only or an Excel workbook.
Does Ward keep PHI local like the ONC tool?
Yes. Ward is local-first by default: your answers and any patient data stay on your machine and are never uploaded to our servers.
Can I import my existing ONC SRA Tool file?
Ward is built to import an in-progress ONC SRA Tool export (Excel or JSON) so switchers don't start over. See the repo STATUS for current availability.

Keep the rigor. Lose the Windows-only catch.

Run a complete HIPAA Security Risk Assessment on any machine — free, local-first, with a built-in 2026 readiness report.

Start your free SRA