This models what a breach would costif one happened. It does not estimate how likely that is, and it is not what a compliance program or a risk assessment costs to buy — that question is answered here.
Looking for a security risk assessment? →Free tool
What a HIPAA breach would cost your practice.
Most breach cost figures are hospital figures. This one models an independent practice, from a single number you supply, using Patient Protect’s published methodology — every assumption in it stated on this page. It answers what a breach would cost if one occurred. It does not tell you whether one will.
$442
Per record
Patient Protect model baseline
3–4x
10-year multiplier
Year-1 costs compound — they do not conclude
6
Cost categories
Regulatory, legal, insurance, patient loss, recovery, fraud
100%
Free
No login, no credit card, no trial expiration
How many records a breach would reach — not everything the practice holds. It is the only figure the model takes from you; everything below is a Patient Protect assumption, stated in full.
Strong-control scenario
×1.0Modeled first-year impact if a breach occurs
$1.1M
Modeled 10-year scenario range
$3.3M – $5.5M
first year × 3–5
Weak-control scenario
×1.3Modeled first-year impact if a breach occurs
$1.4M
Modeled 10-year scenario range
$4.3M – $7.2M
first year × 3–5
These are the two multipliers the Patient Protect methodology defines — 1.0 and 1.3, with nothing in between. They are scenario assumptions, not a judgement about your practice, and the methodology does not set out what would qualify a program as one or the other. That question is what the Exposure Diagnostic is for.
How this number was produced
- You entered
2,500 records potentially affected
- Patient Protect assumes
$442 per compromised record — the Patient Protect model baseline
A control multiplier of 1.0 or 1.3
A long-tail scenario factor of 3× to 5×
- The calculator computes
First-year impact, conditional on a breach occurring
A ten-year directional range, first year multiplied by the long-tail factor
- It does not determine
Whether a breach will happen, or how likely that is
Whether a HIPAA violation or a reportable breach occurred
Whether OCR would impose a penalty
What a specific incident would actually cost
Model 1.0 · 2026-08-28· figures rounded to two significant figures, because the model does not know the third
Cost channels considered in the research
The methodology reaches its per-record baseline by studying six channels through which breach costs arrive. It does not establish how a given incident divides across them, and this calculator does not pretend to either — composition varies enormously, and a particular breach may carry nothing at all in a given channel.
Regulatory and enforcement
OCR settlements and civil monetary penalties. Many breaches result in none.
Litigation
Legal defense and plaintiff settlements, often resolving over several years.
Insurance
Cyber coverage repriced at renewal, sometimes for multiple cycles.
Patient attrition
Revenue lost when patients leave or new ones do not arrive.
Remediation
Incident response, forensics, notification, and the security spend that follows.
Downstream fraud
Costs borne by affected individuals — identity repair, disputes, lost time.
Take it with you
Download my breach-cost scenario
A one-page summary with your figures, the full assumption ledger and the model’s limits — the thing you forward before a budget conversation.
The summary is built in your browser. Your record count and the figures above are not sent to Patient Protect — only your email and that checkbox.
Methodology
The whole model, in two lines.
There is no hidden layer. This is section 10.2.2 of the Patient Protect methodology, implemented exactly and nowhere extended.
first year = records × $442 × control multiplier
ten years = first year × 3 to 5$442 per record
The Patient Protect model baseline. Not an external benchmark, and no derivation is published for it.
1.0 or 1.3
The control multiplier. The methodology defines two states, strong and weak. There is no middle value, so we do not invent one.
3× to 5×
The long-tail scenario factor. A range, applied to the first-year figure, representing costs that continue after the incident.
The methodology is Patient Protect’s own, published as SSRN preprint 5257628. A preprint server hosts work; it does not review or validate it, and nothing here has been independently calibrated. The paper is explicit about what it is for: directional understanding and planning, not legal, forensic-accounting or actuarial precision.
The long tail
A breach does not end when the incident does.
The costs people picture are the first ones: forensics, notification, perhaps an enforcement action. Those arrive quickly and they are visible. The research behind this model is concerned with what follows — litigation that takes years to resolve, cyber cover repriced across several renewals, patients who do not come back, and fraud costs borne by the people whose records were taken.
The Patient Protect methodology represents that tail with a scenario factor of 3× to 5× the modeled first-year impact. That is an assumption, not a measurement, and it is the reason the ten-year figure above is shown as a range rather than a number. The calculator multiplies; it does not simulate a year-by-year path, and the methodology does not claim to.
What none of this establishes is whether a breach will happen to you. The model has no probability term, and the methodology names probabilistic modeling as future work rather than something it does today.
Go deeper
Get a complete risk picture
This models money, conditional on an event. It cannot tell you where you actually stand. The Exposure Diagnostic is the operational counterpart — findings tied to your own answers, and a remediation queue.
Take the Free AssessmentRead the research
The data behind the model
The methodology behind this calculator is The Economics of ePHI Exposure, published as SSRN preprint 5257628 — a long-term impact model built across six cost channels. Patient Protect-authored, and not independently validated.
Read the PaperA number is not a plan.
This page models a cost. Knowing where your practice actually stands is a different question, and it is the one worth answering next. Patient Protect manages the ongoing work behind it — monitoring, business associate agreements, workforce training, and incident response.
Every figure on this page is conditional on a breach occurring and rests on Patient Protect’s own model assumptions, which are stated above in full. This is a scenario model for directional understanding and planning — not a probability forecast, a forensic accounting exercise, an actuarial estimate, or legal advice. Actual costs vary with circumstances, jurisdiction, insurance and much else. See our Terms of Use.
Part of the HIPAA Foundation · Free tools & resources
See the full collectionQuantify consequences
This is your exposure. The platform reduces the multipliers that drive it — vendor concentration, unencrypted data, missing BAAs, workforce access.
Next in the sequence
Risk AssessmentModel year-one and 10-year breach exposure using record count, practice size, security profile, and vendor surface.
