Directory

    HIPAA Auditors in North America

    14 accredited HIPAA audit firms serving North America on Nomona. HIPAA is US law governing how protected health information is safeguarded. There is no official certificate. Compliance is shown through independent assessment. Typical timeline: HIPAA compliance is continuous. An initial risk analysis and remediation typically take a few weeks to a few months; an independent assessment can then be performed and refreshed periodically, commonly annually.. Typical cost: Independent HIPAA assessment fees vary with scope and the state of your program. Pairing HIPAA with SOC 2 or pursuing HITRUST changes the cost profile; budget for remediation on top of assessment..

    JG

    Johanson Group LLP

    Unverified Peer ReviewedUnclaimed account
    United States
    SOC 1SOC 2SOC 3ISO 27001HIPAA
    0.0(0)

    Fixed-fee SOC 2 with rapid turnaround.

    SaaSFintech
    PS

    Prescient Security

    Unverified Peer ReviewedUnclaimed account
    Nashville, United States
    SOC 2ISO 27001ISO 42001HIPAAGDPRPCI DSSCREST
    0.0(0)

    Security-first audits, built by pen testers.

    SaaSFintechGovernment
    K

    KirkpatrickPrice

    UnverifiedUnclaimed account
    Tampa, United States
    SOC 1SOC 2ISO 27001HIPAAPCI DSS
    0.0(0)
    Pricing not published

    Multi-framework CPA and cybersecurity assessment firm

    SaaSHealthcareFintech
    SL

    Sensiba LLP

    UnverifiedUnclaimed account
    Pleasanton, United States
    SOC 1SOC 2ISO 27001ISO 27701ISO 42001HIPAA
    0.0(0)
    Pricing not published

    Top 100 US CPA firm and certified B Corp, fixed-fee SOC 2 and ISO audits

    SaaSFintech
    W

    WithumSmith+Brown

    UnverifiedUnclaimed account
    Princeton, United States
    SOC 1SOC 2ISO 27001HIPAA
    0.0(0)
    Pricing not published

    National top-25 CPA and advisory firm with a SOC audit practice

    SaaSFintechHealthcare
    A

    AARC-360

    UnverifiedUnclaimed account
    Atlanta, United States
    SOC 1SOC 2SOC 3ISO 27001HIPAAPCI DSS
    0.0(0)
    Pricing not published

    PCAOB-registered CPA firm serving small and mid-sized companies.

    SaaSFintech
    AB

    Anchin Block & Anchin

    UnverifiedUnclaimed account
    New York, United States
    SOC 1SOC 2HIPAA
    0.0(0)
    Pricing not published

    New York CPA firm focused on the mid-market.

    SaaSFintechRetail
    T

    Thoropass

    UnverifiedUnclaimed account
    New York, United States
    SOC 2ISO 27001HIPAAPCI DSS
    0.0(0)
    Pricing not published

    GRC platform and CPA audit under a single contract

    SaaSFintechHealthcare
    ZD

    Zero Day CPA

    UnverifiedUnclaimed account
    Troy, United States
    SOC 2HIPAA
    0.0(0)
    Pricing not published

    SOC 2 and HIPAA audits with flexible delivery for smaller organizations

    SaaSHealthcare
    A

    AAFCPAs

    UnverifiedUnclaimed account
    Westborough, United States
    SOC 1SOC 2HIPAA
    0.0(0)
    Pricing not published

    IT audit services for service organizations.

    SaaSHealthcare
    A

    A-LIGN

    UnverifiedUnclaimed account
    Tampa, United States
    SOC 1HITRUSTFedRAMPSOC 2PCI DSSHIPAAISO 27001
    0.0(0)
    Pricing not published

    Single-provider audits across SOC 2, ISO 27001, FedRAMP, HITRUST, and PCI DSS

    SaaSFintechHealthcareGovernment
    FA

    Fine Assurance

    Verified Peer Reviewed
    Pittsburgh, United States
    SOC 2SOC 1SOC 3ISO 27001ISO 42001HIPAAGDPROther: ISO 27701
    0.0(0)

    Quality-first SOC audits — not checkbox compliance.

    SaaSFintechHealthcareAIStartups
    Axipro

    Axipro

    Readiness Partner
    London, United Kingdom
    SOC 2ISO 27001ISO 27701ISO 42001HIPAAGDPRPCI DSSNISTDORACMMCCREST
    0.0(0)
    Pricing not published

    Certification audits and compliance services — SOC 2, ISO 27001 and more — with CREST-accredited penetration testing.

    SaaSFintechOther
    MA

    Modern Assurance

    Verified Peer Reviewed
    United States
    SOC 1SOC 2SOC 3HIPAAGDPR
    0.0(0)

    Peer-reviewed CPA firm with no GRC platform partnerships.

    SaaSFintechHealthcareAIStartups

    HIPAA in North America: regulatory status

    US

    HHS proposed Security Rule update published December 2024 (public comment closed March 2025). Final rule and effective date still pending as of mid-2026.

    Last verified Jul 13, 2026

    Frequently asked

    How many HIPAA auditors serve North America?

    Nomona lists 14 independent, accredited HIPAA audit firms serving North America today, including firms with global coverage.

    How much does a HIPAA audit typically cost?

    Independent HIPAA assessment fees vary with scope and the state of your program. Pairing HIPAA with SOC 2 or pursuing HITRUST changes the cost profile; budget for remediation on top of assessment.