Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

This models what a breach would costif one happened. It does not estimate how likely that is, and it is not what a compliance program or a risk assessment costs to buy — that question is answered here.

Looking for a security risk assessment? →

Free tool

What a HIPAA breach would cost your practice.

Most breach cost figures are hospital figures. This one models an independent practice, from a single number you supply, using Patient Protect’s published methodology — every assumption in it stated on this page. It answers what a breach would cost if one occurred. It does not tell you whether one will.

Free·No login required·$442/record model baseline·Assumptions shown in full

$442

Per record

Patient Protect model baseline

3–4x

10-year multiplier

Year-1 costs compound — they do not conclude

6

Cost categories

Regulatory, legal, insurance, patient loss, recovery, fraud

100%

Free

No login, no credit card, no trial expiration

How many records a breach would reach — not everything the practice holds. It is the only figure the model takes from you; everything below is a Patient Protect assumption, stated in full.

Strong-control scenario

×1.0

Modeled first-year impact if a breach occurs

$1.1M

Modeled 10-year scenario range

$3.3M$5.5M

first year × 35

Weak-control scenario

×1.3

Modeled first-year impact if a breach occurs

$1.4M

Modeled 10-year scenario range

$4.3M$7.2M

first year × 35

These are the two multipliers the Patient Protect methodology defines — 1.0 and 1.3, with nothing in between. They are scenario assumptions, not a judgement about your practice, and the methodology does not set out what would qualify a program as one or the other. That question is what the Exposure Diagnostic is for.

How this number was produced

You entered

2,500 records potentially affected

Patient Protect assumes

$442 per compromised record — the Patient Protect model baseline

A control multiplier of 1.0 or 1.3

A long-tail scenario factor of 3× to 5×

The calculator computes

First-year impact, conditional on a breach occurring

A ten-year directional range, first year multiplied by the long-tail factor

It does not determine

Whether a breach will happen, or how likely that is

Whether a HIPAA violation or a reportable breach occurred

Whether OCR would impose a penalty

What a specific incident would actually cost

Model 1.0 · 2026-08-28· figures rounded to two significant figures, because the model does not know the third

Cost channels considered in the research

The methodology reaches its per-record baseline by studying six channels through which breach costs arrive. It does not establish how a given incident divides across them, and this calculator does not pretend to either — composition varies enormously, and a particular breach may carry nothing at all in a given channel.

  • Regulatory and enforcement

    OCR settlements and civil monetary penalties. Many breaches result in none.

  • Litigation

    Legal defense and plaintiff settlements, often resolving over several years.

  • Insurance

    Cyber coverage repriced at renewal, sometimes for multiple cycles.

  • Patient attrition

    Revenue lost when patients leave or new ones do not arrive.

  • Remediation

    Incident response, forensics, notification, and the security spend that follows.

  • Downstream fraud

    Costs borne by affected individuals — identity repair, disputes, lost time.

Take it with you

Download my breach-cost scenario

A one-page summary with your figures, the full assumption ledger and the model’s limits — the thing you forward before a budget conversation.

The summary is built in your browser. Your record count and the figures above are not sent to Patient Protect — only your email and that checkbox.

Methodology

The whole model, in two lines.

There is no hidden layer. This is section 10.2.2 of the Patient Protect methodology, implemented exactly and nowhere extended.

first year = records × $442 × control multiplier
ten years  = first year × 3 to 5

$442 per record

The Patient Protect model baseline. Not an external benchmark, and no derivation is published for it.

1.0 or 1.3

The control multiplier. The methodology defines two states, strong and weak. There is no middle value, so we do not invent one.

3× to 5×

The long-tail scenario factor. A range, applied to the first-year figure, representing costs that continue after the incident.

The methodology is Patient Protect’s own, published as SSRN preprint 5257628. A preprint server hosts work; it does not review or validate it, and nothing here has been independently calibrated. The paper is explicit about what it is for: directional understanding and planning, not legal, forensic-accounting or actuarial precision.

The long tail

A breach does not end when the incident does.

The costs people picture are the first ones: forensics, notification, perhaps an enforcement action. Those arrive quickly and they are visible. The research behind this model is concerned with what follows — litigation that takes years to resolve, cyber cover repriced across several renewals, patients who do not come back, and fraud costs borne by the people whose records were taken.

The Patient Protect methodology represents that tail with a scenario factor of 3× to 5× the modeled first-year impact. That is an assumption, not a measurement, and it is the reason the ten-year figure above is shown as a range rather than a number. The calculator multiplies; it does not simulate a year-by-year path, and the methodology does not claim to.

What none of this establishes is whether a breach will happen to you. The model has no probability term, and the methodology names probabilistic modeling as future work rather than something it does today.

Go deeper

Get a complete risk picture

This models money, conditional on an event. It cannot tell you where you actually stand. The Exposure Diagnostic is the operational counterpart — findings tied to your own answers, and a remediation queue.

Take the Free Assessment

Read the research

The data behind the model

The methodology behind this calculator is The Economics of ePHI Exposure, published as SSRN preprint 5257628 — a long-term impact model built across six cost channels. Patient Protect-authored, and not independently validated.

Read the Paper

A number is not a plan.

This page models a cost. Knowing where your practice actually stands is a different question, and it is the one worth answering next. Patient Protect manages the ongoing work behind it — monitoring, business associate agreements, workforce training, and incident response.

Every figure on this page is conditional on a breach occurring and rests on Patient Protect’s own model assumptions, which are stated above in full. This is a scenario model for directional understanding and planning — not a probability forecast, a forensic accounting exercise, an actuarial estimate, or legal advice. Actual costs vary with circumstances, jurisdiction, insurance and much else. See our Terms of Use.

Part of the HIPAA Foundation · Free tools & resources

See the full collection
QuantifyFree · proprietary

Quantify consequences

This is your exposure. The platform reduces the multipliers that drive it — vendor concentration, unencrypted data, missing BAAs, workforce access.

Next in the sequence

Risk Assessment

Model year-one and 10-year breach exposure using record count, practice size, security profile, and vendor surface.