Pricing

Flat pricing, no per-seat surprises.

Every plan includes unlimited staff, unlimited policies, and the full HIPAA checklist. Add on devices and monitoring when you're ready.

Starter

Solo practitioners & practices up to 5 staff. Everything you need to pass a first audit.

$149
per practice / month · billed annually
  • Full HIPAA checklist & risk assessment
  • 23 policy templates, practice-customized
  • Staff training & attestations
  • Policy chat (AI, grounded in your docs)
  • One-click audit export
  • Email support
Start free trial
Most popular
Growth

Multi-provider practices and therapy networks. Everything in Starter, plus what scales.

$349
per practice / month · billed annually
  • Everything in Starter
  • Unlimited staff & locations
  • Vendor & BAA tracking
  • Custom roles & task routing
  • SSO (Google, Microsoft)
  • Quarterly compliance review call
  • Priority support
Start free trial
Enterprise

Multi-site healthcare orgs and DSOs. Custom contracts, custom rollout.

Let's talk
Volume pricing & MSA
  • Everything in Growth
  • Dedicated implementation manager
  • Custom policy authoring
  • API & data residency options
  • Named security engineer
  • SLA & custom MSA
Contact sales
Add-ons

Optional, when you're ready.

Expand beyond the compliance program. Priced per-device or per-practice, add or remove anytime.

Managed MacBook

Pre-configured, encrypted, shipped to your staff.

$100
per device / mo

24/7 Monitoring (SIEM/XDR)

Managed detection & response on your endpoints.

$49
per device / mo

Custom policy authoring

Our team writes & reviews your policies with you.

$1,500
one-time

Audit response

Hands-on support if OCR comes knocking.

$250
per hour
FAQ

Common questions.

Is there really no per-seat fee?

Correct. One practice, one price. Add unlimited staff to your plan. We believe compliance software shouldn't punish you for hiring.

What if I already have a BAA with another vendor?

Import it. hms. tracks every BAA you have, renewal dates, and countersignature status. No need to migrate everything at once.

Do I still need a HIPAA officer?

Yes — HIPAA requires a designated Privacy & Security Officer. hms. gives that person the tools they need; we don't replace the role.

What happens after the 14-day trial?

Your data stays. If you don't convert, we archive the program for 90 days so you can export it. No lock-in.

Does hms. handle SOC 2 or other frameworks?

No — and that's intentional. We're HIPAA-only, by design. If you need multi-framework, Vanta or Drata will serve you better.

Ready when you are.

14-day trial. No credit card. Cancel anytime.