Tools
Should you use the free HHS SRA Tool? An honest look
Published July 24, 2026
Here’s something a compliance vendor doesn’t usually lead with: the federal government publishes a free security risk assessment tool, it’s legitimate, and for some practices it’s the right choice. We make a competing product, so read this with that in mind — but the honest comparison is the one worth writing.
What the HHS SRA Tool is
The SRA Tool comes from ONC and OCR — the federal offices that write health-IT policy and enforce HIPAA — and it’s aimed squarely at small and medium practices. It ships two ways: a Windows desktop application and an Excel workbook for everyone else. It walks you through seven sections of multiple-choice questions with education notes alongside, has you rate the likelihood and impact of the threats you identify, and produces reports at the end — including a remediation report where you can assign fixes an owner and a due date.
One thing worth respecting: HHS states plainly that everything you enter stays on your own computer — “HHS does not collect, view, store, or transmit any information entered into the SRA Tool.” That’s the right way to build this kind of tool. (It’s the same promise we make about your answers in HIPAAPath, so consider it table stakes, not a tiebreaker.)
What it does well
- Provenance. It’s the government’s own tool — the “why did you use this?” question answers itself.
- Referenced to the letter. Questions link back to the specific HIPAA citations and security frameworks they come from — useful if you want to see the regulatory machinery.
- Follow-through built in. The remediation report tracks who owns each fix and when it’s due, and a 2025 update added a section sign-off that records who reviewed what, and when — good audit-trail habits.
- Free, with no upsell waiting at the end.
Where it’s heavy going
The desktop app is Windows-only — HHS says so directly — so a Mac practice gets the Excel-workbook route instead. The question set is substantial: the count you’ll see cited around the web — 156 — actually traces to an older, retired edition of the tool, and HHS doesn’t publish one for the current seven-section version. HHS’s own guidance is to “invest a significant amount of time”, and New York’s Medicaid program warns the assessment takes more than a couple of hours — before counting the time to gather the documentation it needs. The questions also assume you already understand your own technology setup; HHS’s own advice is to spend time understanding where patient data lives in your practice before you start.
And it’s an assessment tool, not a documentation engine: it tells you where you’re weak, but it doesn’t write your policies or produce the day-to-day paperwork of a security program. HHS’s own report cover says using the tool is optional and completing it is no promise of compliance — which is honest of them, and true of every tool in this category, ours included. A risk assessment is where compliance work starts, whatever software you do it in.
How HIPAAPath differs, honestly
Same job — a documented security risk assessment — different shape. HIPAAPath asks its questions as a plain-English walkthrough, one at a time, built for people who hate admin; it runs in the browser — Mac or Windows alike; and instead of a findings report, it ends in a Security Manual — the written documentation of your safeguards, which is usually the next thing you’d have to produce anyway. What the HHS tool has that we don’t: the government’s name on it, the visible citation mappings, and the assign-an-owner remediation tracker. The full assessment is free in both — what we sell sits after it, not in front of it.
The honest bottom line: a risk assessment you actually finish beats a more thorough one you abandon in section three. If the HHS tool’s shape fits how you work, use it — it costs nothing and it’s the real thing. If you’ve opened it and stalled, that’s the practice we built for.
Free — no account needed to start, and your answers never leave your browser. Not legal advice: for questions about your specific obligations, talk to a healthcare attorney.