Attestio
HIPAA · 2026 Auditor's Guide

HIPAA auditors: who can perform a HIPAA Security Risk Analysis

There is no formal HIPAA auditor registry. Instead, the de facto market is the 168 SOC 2 audit firms in our directory — most of whom also perform HIPAA Security Risk Analysis for covered entities and business associates. This page is the research base for healthcare organizations, business associates, and health tech vendors looking for an assessor.

✓ Independently verified Last updated June 14, 2026
168
SOC 2 firms
120+
With HIPAA experience
7
Countries
HITRUST + SOC 2 + HIPAA standard
Multi-framework
Editorial illustration of a HIPAA assessment
The buyer's guide

How to choose a firm — and what to expect

HIPAA is unique among the major compliance frameworks: there is no central registry of "HIPAA auditors." The Department of Health and Human Services’ Office for Civil Rights (OCR) audits HIPAA-covered entities and business associates, but does not certify private-sector HIPAA assessors. The de facto market is SOC 2 audit firms — most of whom also perform HIPAA Security Risk Analysis as a parallel engagement. This guide explains the HIPAA audit landscape, what to look for in a HIPAA assessor, and how HIPAA fits with HITRUST CSF, SOC 2, and ISO 27001.

01

Why there is no HIPAA auditor registry

HIPAA is a federal regulation (the Health Insurance Portability and Accountability Act, plus the HITECH Act and the Omnibus Rule), not a certification standard. The enforcement body is HHS OCR, which conducts its own audits but does not certify private-sector assessors. As a result, there is no equivalent of the PCI SSC QSA list or the AICPA SOC 2 registry. The de facto market is SOC 2 audit firms: any CPA firm can perform a HIPAA Security Risk Analysis, and most of the 168 SOC 2 firms in our directory do exactly that. Some firms also hold HITRUST External Assessor credentials, which is the deepest healthcare-specific expertise.

02

How to choose a HIPAA assessor: 5 criteria

1. Healthcare vertical experience. HIPAA is healthcare-specific. An assessor that does 30% of its work in healthcare will write a sharper risk analysis. 2. HITRUST capability. A HITRUST External Assessor brings the deepest healthcare expertise. For organizations pursuing HITRUST CSF, you want a firm that can do both. 3. Multi-framework support. If you need HIPAA + SOC 2 + HITRUST, get a firm that runs all three in parallel with shared evidence. 4. OCR audit support. If you face an OCR investigation, the right assessor can provide expert witness support and remediation. Look for firms with OCR audit experience. 5. Report quality. A HIPAA Security Risk Analysis is a 30-60 page document. Ask for a sample.

03

How much does a HIPAA Security Risk Analysis cost?

For a mid-sized healthcare organization: $15K–$50K. For a small business associate: $5K–$15K. Renewal (annual): $5K–$20K. The variation is driven by scope: number of systems processing PHI, number of locations, complexity of the data flows, and whether the assessment is a one-off SRA or a continuous monitoring engagement. If you also need SOC 2 or HITRUST, the marginal cost of HIPAA is usually $5K–$10K added to the larger engagement.

04

How long does a HIPAA Security Risk Analysis take?

Initial SRA: 4–8 weeks. The SRA is lighter than a SOC 2 Type 2 or HITRUST r2 — there is no audit window, no quarterly testing, and no formal certification. The deliverable is a written risk analysis document that meets the 45 CFR § 164.308(a)(1)(ii)(A) requirement. Renewals: annual, 2–4 weeks. Note: the SRA is required annually for HIPAA compliance. Many organizations also do a continuous risk analysis (quarterly updates) on top of the annual SRA.

05

HIPAA + HITRUST + SOC 2: do you need all three?

For healthcare organizations: HITRUST CSF r2 is the gold standard. It satisfies the HIPAA Security Rule SRA requirement AND provides a certifiable framework that enterprise healthcare buyers recognize. SOC 2 is a complement, not a substitute. The most efficient path: HITRUST CSF r2 as the primary framework, SOC 2 in parallel for the SaaS / B2B side, HIPAA SRA as a subset of the HITRUST scope. An assessor that delivers all three in a single engagement (with shared evidence) is the most cost-effective option.

HIPAA is a regulation, not a certification. There is no "HIPAA certificate" — instead, you get a Security Risk Analysis document that meets the regulatory requirement. The firms in our directory are SOC 2 audit firms that also perform HIPAA SRAs; many of them are HITRUST External Assessors as well. Use the directory to filter by HITRUST capability, by US state coverage, and by the assessor’s multi-framework delivery.
Editor's picks

Six firms worth shortlisting

For each use case below, we picked one firm from the 168 SOC 2 firms in our directory that also performs HIPAA Security Risk Analysis. These are the firms we’d shortlist first.

Best for hospital systems

Coalfire

HIPAA + HITRUST + SOC 2 for health systems

Coalfire is a HITRUST External Assessor with deep hospital-system experience. They run HIPAA SRA as a subset of the HITRUST scope, so health systems do one engagement and get three deliverables: HIPAA SRA, HITRUST r2, and SOC 2 Type 2 (if needed).

HIPAA + HITRUST + SOC 2 in one engagement
View profile →
Best for health tech SaaS

A-LIGN

HIPAA + SOC 2 for health tech

For health tech SaaS companies, A-LIGN runs HIPAA SRA alongside SOC 2 Type 2 in a single engagement with shared evidence. The HIPAA SRA is a subset of the SOC 2 control testing — no double work for your team.

Joint HIPAA + SOC 2 standard
View profile →
Best for payers and health plans

Schellman Compliance

HIPAA + HITRUST for payers

Schellman is a HITRUST External Assessor with deep payer / health plan experience. They run HIPAA SRA as a subset of the HITRUST CSF r2 engagement, so the SRA is a deliverable from a broader healthcare-specific assessment.

HITRUST External Assessor; payer specialist
View profile →
Best for business associates

Linford & Company

HIPAA SRA for mid-market BAs

Linford specializes in mid-market business associates (BAs) — the vendors that process PHI on behalf of covered entities. Their HIPAA SRA is a focused 4-week engagement, often followed by SOC 2 if the BA’s customers require it.

Mid-market BA specialist
View profile →
Best for clinical research / life sciences

BARR Advisory

HIPAA + HITRUST for clinical research

BARR has specific experience with clinical research organizations (CROs) and life sciences vendors. Their HIPAA SRA includes FDA 21 CFR Part 11 and GxP-aligned control testing, which is essential for organizations that operate under both HIPAA and FDA regulations.

HIPAA + GxP scope standard
View profile →
Best for OCR audit support

Moss Adams

HIPAA + OCR audit response

Moss Adams is one of the few firms with explicit OCR audit support experience. If you face an HHS OCR investigation, Moss Adams can provide expert witness support, remediation planning, and a follow-up SRA. They are a HITRUST Readiness Licensee for organizations preparing for validated HITRUST.

OCR audit response experience
View profile →
How we pick: Picks are based on the firm’s track record in healthcare, HITRUST External Assessor status, multi-framework delivery capability (HIPAA + SOC 2 + HITRUST in parallel), and OCR audit experience. We do not accept payment for inclusion. Firms: <a href="/operators/claim">claim your profile</a> to update your listing.
How we verify

There is no formal HIPAA auditor registry. We source the firms in this directory from the SOC 2 audit registry, cross-referenced with the HITRUST Alliance External Assessor list.

Verified quarterly Last verified June 14, 2026 Last crawled June 14, 2026
HITRUST External Assessors and Readiness Licensees — the deepest healthcare-specific expertise.
The most comprehensive SOC 2 audit firm registry. 168 CPA firms; ~120 also perform HIPAA SRAs.
The American Institute of CPAs — the body that defines the SOC 2 standard. All 168 firms in our directory hold an active AICPA peer review.
Direct verification
Firms with a claimed profile can update their HIPAA specialization, multi-framework capability, and OCR audit experience directly.
📋

Get the free checklist

We'll email you the PDF. Plus weekly compliance insights. No spam, unsubscribe with one click.

We use this only to send your checklist. One-click unsubscribe in every email.

The full directory

All 168 SOC 2 (HIPAA experience) firms

Filter by name or search.

Showing 168 firms

Sage Audits

✓ Verified
🌐 sageaudits.com

360 Advanced

🌐 360advanced.com

A-LIGN

🌐 a-lign.com

AAFCPAs

🌐 aafcpa.com

AARC-360

🌐 aarc-360.com

ATA (Alexander Thompson Arnold)

🌐 ata.net

Accedere

🌐 accedere.io

Accorp Partners

🌐 accorppartners.com

Aprio

🌐 aprio.com

Armanino LLP

🌐 armaninollp.com

Assent Risk Management

🌐 assentriskmanagement.co.uk

AssurancePoint

🌐 assurancepoint.cpa

Audit Advantage Group

🌐 auditadvantagegroup.com

Audit Peak

🌐 auditpeak.com

Auditwerx

🌐 auditwerx.com

BARR Advisory

🌐 barradvisory.com

BD Emerson

🌐 bdemerson.com

BDO Australia

🌐 bdo.com.au

BDO Canada

🌐 bdo.ca/services/financial-advisory-services/risk-advisory-services/independent-third-party-reviews/soc-2-compliance

BDO UK

🌐 bdo.co.uk

BDO USA

🌐 bdo.com

BPM

🌐 bpm.com

BSI Group

🌐 bsigroup.com

Baker Tilly

🌐 bakertilly.com

Barnes Dennig

🌐 barnesdennig.com

BerryDunn

🌐 berrydunn.com

Boulay Group

🌐 boulaygroup.com

Bulletproof

🌐 bulletproof.co.uk

CAS Assurance

🌐 casassurance.com

CBIZ (formerly Marcum LLP)

🌐 cbiz.com

CLA (CliftonLarsonAllen)

🌐 claconnect.com

Canadian Cyber

🌐 canadiancyber.ca

Carr, Riggs & Ingram (CRI)

🌐 cricpa.com

CertPro

🌐 certpro.com

CertPro Germany

CertValue Germany

🌐 certvalue.com

Cherry Bekaert

🌐 cbh.com

Citrin Cooperman

🌐 citrincooperman.com

Clark Nuber

🌐 clarknuber.com

Coalfire

🌐 coalfire.com

CohnReznick

🌐 cohnreznick.com

Consilium Labs

🌐 consilium-labs.com

Constellation GRC

🌐 constellationgrc.com

ControlCase

🌐 controlcase.com

Copeland Buhl

🌐 copelandbuhl.com

Councilor, Buchanan & Mitchell (CBM)

🌐 cbmcpa.com

Crowe Global

🌐 crowe.com

Crowe LLP

🌐 crowe.com

Crowe MacKay LLP

🌐 crowemackay.ca

CyberCrest

🌐 cybercrestcompliance.com

CyberGuard Advantage

🌐 cgcompliance.com

CyberSapiens Australia

🌐 cybersapiens.com.au

CyberSapiens Germany

🌐 cybersapiens.com.au

Dansa D'Arata Soucia LLP

🌐 darata.com

Dantia

Decrypt Compliance

Deloitte

🌐 deloitte.com

Deloitte Australia

🌐 deloitte.com/au

Deloitte Canada

🌐 deloitte.com/ca

Deloitte Germany

🌐 deloitte.com/de

Deloitte India

🌐 www2.deloitte.com/in

Doeren Mayhew

🌐 doeren.com

Drummond Group

🌐 drummondgroup.com

EY (Ernst & Young)

🌐 ey.com

EY Australia

🌐 ey.com/en_au

EY Canada

🌐 ey.com/en_ca

EY Germany

🌐 ey.com/en_de

Eide Bailly

🌐 eidebailly.com

EisnerAmper

🌐 eisneramper.com

Elliott Davis

🌐 elliottdavis.com

Ferro Technics

🌐 ferrotechnics.com

FinAudit CPA

🌐 finauditcpa.com

Fortreum

🌐 fortreum.com

Forvis Mazars

🌐 forvismazars.us

Frank, Rimerman + Co.

🌐 frankrimerman.com

Frazier & Deeter

🌐 frazierdeeter.com

GRF CPAs & Advisors

🌐 grfcpa.com

Geels Norton

🌐 geelsnorton.com

Grant Thornton

🌐 grantthornton.com

Grant Thornton Australia

🌐 grantthornton.com.au

Grant Thornton Canada

🌐 grantthornton.ca

Grant Thornton UK

🌐 grantthornton.co.uk

Grassi

🌐 grassiadvisors.com

HLB Mann Judd

🌐 hlb.com.au

Herbein + Company

🌐 herbein.com

Holbrook & Manter

🌐 holbrookmanter.com

IS Partners

🌐 ispartnersllc.com

ITGRC Advisory

🌐 itgrcadvisory.com

Insight Assurance

🌐 insightassurance.com

Johanson Group

🌐 johansonllp.com

KLR (Kahn Litwin Renza)

🌐 kahnlitwin.com

KPMG

🌐 kpmg.com

KPMG Australia

🌐 kpmg.com/au

KPMG Canada

🌐 kpmg.com/ca

KPMG Germany

🌐 kpmg.com/de

KSM (Katz, Sapper & Miller)

🌐 ksmcpa.com

Keiter

🌐 keitercpa.com

Ken & Co

🌐 ken-co.cpa

KirkpatrickPrice

🌐 kirkpatrickprice.com

LBMC

🌐 lbmc.com

Larson & Company

🌐 larsco.com

Lazarus Alliance

🌐 lazarusalliance.com

Linford & Company

🌐 linfordco.com

MHM Professional Corporation

🌐 mhmcpa.ca

MJD Advisors

🌐 mjd.cpa

MNP LLP

🌐 mnp.ca

Manning Elliott LLP

🌐 manningelliott.com

Mauldin & Jenkins

🌐 mjcpa.com

Mazars Germany

🌐 forvismazars.com/de

Mazars UK

🌐 forvismazars.com/uk

McKonly & Asbury

🌐 macpas.com

Modern Assurance

🌐 modassurance.com

Moore Colson

🌐 moorecolson.com

Moore Kingston Smith

🌐 mooreclear.com

NDB

🌐 ndbcpa.com

Nucleus Networks

🌐 yournucleus.ca

Oread Risk & Advisory

🌐 oreadrisk.com

PBMares

🌐 pbmares.com

PKF O'Connor Davies

🌐 pkfod.com

PYA

🌐 pyapc.com

Pease Bell CPAs

🌐 peasebell.com

Plante Moran

🌐 plantemoran.com

Prager Metis

🌐 pragermetis.com

Prescient Security

🌐 prescientsecurity.com

Prowise Systems

🌐 prowisesystems.com

PwC (PricewaterhouseCoopers)

🌐 pwc.com

PwC Australia

🌐 pwc.com.au

PwC Canada

🌐 pwc.com/ca

PwC Germany

🌐 pwc.de

RS Assurance & Advisory

🌐 rsassure.com

RSM Australia

🌐 rsm.com.au

RSM Canada

🌐 rsmcanada.com/services/risk-fraud-cybersecurity/governance-risk-compliance/system-and-organization-controls.html

RSM Ebner Stolz

🌐 ebnerstolz.de

RSM US

🌐 rsmus.com

Rehmann

🌐 rehmann.com

Render Compliance

🌐 rendercompliance.com

Richey May Advisory

🌐 richeymay.com

RubinBrown

🌐 rubinbrown.com

SAV Associates

🌐 savassociates.ca

SC&H Group

🌐 schgroup.com

Saltmarsh, Cleaveland & Gund

🌐 saltmarshcpa.com

Schellman

🌐 schellman.com

Schneider Downs

🌐 schneiderdowns.com

Securance

🌐 securance.com

Securisea

🌐 securisea.com

Sensiba LLP

🌐 sensiba.com

Sentry Assurance

🌐 sentryassurance.com

Siege Cyber

🌐 siegecyber.com.au

SingerLewak

🌐 singerlewak.com

Smith + Howard

🌐 smith-howard.com

Sustainable Certification

🌐 sustainablecertification.com.au

Tanner LLC

🌐 tannerco.com

Tempo Audits

🌐 tempoaudits.com

The Pun Group

🌐 pungroup.cpa

Thoropass

🌐 thoropass.com/customers/beyond-automation-how-array-behavioral-care-found-a-true-audit-partner-in-thoropass

TrustNet

🌐 trustnetinc.com

Truvo

🌐 truvo.ca

VISTA InfoSec

🌐 vistainfosec.com

Warren Averett

🌐 warrenaverett.com

Weaver

🌐 weaver.com

Windes

🌐 windes.com

Windham Brannon

🌐 windhambrannon.com

Wipfli

🌐 wipfli.com

Withum

🌐 withum.com

Wolf & Company

🌐 wolfandco.com

YHB CPAs & Consultants

🌐 yhbcpa.com

Zero Day CPA

🌐 zerodaycpa.com

eDelta Consulting

🌐 edeltaconsulting.com
FAQ

Common questions

Is there a HIPAA certification?

No. HIPAA is a federal regulation, not a certification standard. There is no "HIPAA certificate." The closest is a HITRUST CSF r2 certificate, which demonstrates compliance with the HIPAA Security Rule as a subset of the broader HITRUST framework.

What is a HIPAA Security Risk Analysis?

A Security Risk Analysis (SRA) is a written assessment of the risks to the electronic Protected Health Information (ePHI) that your organization creates, receives, maintains, or transmits. The SRA is required by 45 CFR § 164.308(a)(1)(ii)(A) for all HIPAA covered entities and business associates. A SOC 2 audit firm or HITRUST External Assessor typically performs it.

Is a SOC 2 report enough for HIPAA?

No. SOC 2 is a security audit; it does not satisfy the HIPAA Security Rule SRA requirement. You need both. The most efficient path: SOC 2 + HIPAA SRA in a single engagement with shared evidence, or HITRUST CSF r2 (which satisfies the SRA requirement as a subset).

How often is a HIPAA SRA required?

Annually, per HHS OCR guidance. Many organizations also do continuous risk analysis (quarterly updates) on top of the annual SRA. The SRA should be updated whenever there is a significant change to the environment (new system, new vendor, new location).