Sentinel SRA
An honest comparison

The free HHS tool, and a performed analysis

They are not competitors. They are two different things, and the difference is worth understanding before you spend either money or a weekend.

Start here

The tool is a questionnaire. The analysis is the work.

The HIPAA Security Rule requires a risk analysis. It does not name a product, endorse a vendor, or say who has to do it — you are free to do it yourself, and many practices do. So the real question is not which one satisfies the rule. It is who is going to do the thinking, and what you will be able to show afterwards.

Published by ONC and HHS OCR

The HHS/ONC SRA Tool

Free
  • A downloadable application that asks you a structured set of questions
  • Built for small and medium practices, and genuinely well made
  • Your answers stay on your own computer — nothing is transmitted
  • Produces a report from whatever you enter
  • You supply the inventory, the judgement, and the follow-through
Performed for you

The Sentinel Security Risk Analysis

$2,895 — published, flat
  • Someone else does the work and is accountable for it
  • We find the places electronic patient information lives, including the ones nobody set up on purpose
  • Findings are ranked, with an owner and a target date attached to each
  • A Remediation Register that defines what evidence closes each item
  • A six-month review documenting what actually happened afterwards
What the tool says about itself

We are not going to tell you the free tool is bad

It is a useful, honestly documented government resource, and its own documentation is the clearest statement of what it does and does not do. We would rather quote it than characterise it.

“…use of this tool is neither required by nor guarantees compliance with Federal, State or local laws.”

ONC / HealthIT.gov — Security Risk Assessment Tool · read it yourself

That single sentence is the whole distinction. Running the tool is not what satisfies the rule; conducting an accurate and thorough assessment of your actual environment is what satisfies the rule. The tool is a way to organise that work. It cannot know what you did not tell it.

Which is why the honest test of any risk analysis — ours, yours, or one produced with the free tool — is not whether a document exists. It is whether the answers inside it were complete, and whether anyone reviewing your practice would reach the same conclusions.

Side by side

Where the two actually differ

Both approaches can satisfy the Security Rule. They differ in who carries the work.
  HHS/ONC SRA Tool Sentinel SRA
Who does the work Your team, in hours you do not currently have spare Sentinel, on a defined schedule
Finding where ePHI lives You list it from memory Structured discovery, including systems nobody formally adopted
Judging likelihood and impact Your own assessment of your own practice An outside practitioner who has seen the same gaps elsewhere
What happens to a finding It appears in the report Owner, target date, and the evidence that closes it
Six months later Nothing, unless you schedule it A remediation review documenting what was actually done
Exclusion screening Not included — different obligation, different lists Federal lists screened twice during the engagement; Texas HHSC for Texas practices
If someone asks for proof You assemble it A dated record you can hand over
Cost Free, plus your team’s time $2,895, flat and published

When the free tool is the right choice

We would rather say this plainly than have you discover we left it out. The HHS tool is the better answer when:

  • You have someone in-house with the time and the security background to do it properly
  • Your practice is small, your systems are few, and you genuinely know where all of them are
  • You want to understand the questions before deciding whether to bring anyone in
  • Budget is the binding constraint right now — a completed self-assessment is far better than an analysis you never got round to

Running it yourself first is also a perfectly good way to decide whether you want help. Practices that do usually come back with the same two sentences: the questions were answerable, and they were not sure whether their answers were right.

The part most people have not seen

Finding the risk is the first half

Every risk analysis produces findings. The question nobody asks until it matters is what happened to them afterwards — and that is the half a questionnaire cannot do for you, because it is work rather than documentation. Look at both samples and judge for yourself.

Still not sure which one you need?

Ask us. If the honest answer is that you can handle it in-house, we will tell you that — it costs us one sale and saves you $2,895.

See the Sentinel SRA Start a conversation