The HIPAA Security Risk Assessment
What Small Healthcare Practices Need to Know
If you’ve been told you need to “do a Security Risk Assessment” and you’re not entirely sure what that means, you’re not alone. Most small practices and facilities encounter this requirement the same way: someone mentions it during onboarding, a vendor brings it up in a sales call, or it surfaces during a compliance review — and then it sits on a to-do list, half-understood, until something forces the issue.
This page covers what the Security Risk Assessment (SRA) actually is, why it exists, who’s required to complete one, what it actually involves, and what happens after you’ve done it. Where a topic needs more depth than fits here, we link out to a dedicated article.
What Is a HIPAA Security Risk Assessment?
A Security Risk Assessment — also called a risk analysis — is a required review of the risks and vulnerabilities facing the electronic protected health information (ePHI) your organization creates, receives, stores, or transmits. It’s not a form you fill out once. It’s a process: identify where ePHI lives, identify what could go wrong, and document what you’re doing about it.
The requirement comes from the HIPAA Security Rule (45 CFR §§164.302–318), and it applies to every covered entity and business associate — regardless of size. A five-person practice and a five-hundred-bed facility are held to the same underlying standard, even though what “reasonable and appropriate” looks like will differ significantly based on resources and complexity.
One important distinction worth getting right: the SRA requirement comes from HHS’s Office for Civil Rights (OCR) and Office of the National Coordinator for Health IT (ONC) — not CMS. CMS oversees facility survey and certification (F-tags, Requirements of Participation), which is a separate — though related — layer of compliance for skilled nursing facilities. If your organization is managing both, it’s worth keeping the two tracks distinct in your documentation, since they’re evaluated by different agencies.
Why This Matters Right Now
This isn’t a theoretical requirement. A few things are worth knowing:
- OCR has an active, standing enforcement initiative specifically targeting risk analysis failures, launched in 2024 and still a stated priority heading through 2026. The agency has moved from simply checking whether an assessment exists to evaluating whether an organization is actually acting on what it finds.
- Risk analysis failures are consistently one of the most common findings when OCR investigates a breach. In OCR’s last full round of compliance audits, most audited entities were not fully compliant with this specific provision — meaning an incomplete or outdated risk analysis is more the norm than the exception among organizations that haven’t prioritized it.
- This applies to business associates too, not just covered entities — and this isn’t a new risk. In 2016, a business associate providing management and IT services to six skilled nursing facilities was fined $650,000 after an unencrypted, password-free company phone containing residents’ PHI was stolen; the business associate hadn’t conducted a risk analysis or put mobile device policies in place. The case is nearly a decade old now, but that’s the point — this exposure has existed, and been enforced, for a long time, and it hasn’t gone away.
The pattern in enforcement cases is consistent: risk analysis failures rarely surface on their own. They surface after a ransomware attack, a stolen device, or a breach — at which point OCR’s first question is usually “what did your risk analysis say about this?” Organizations that can’t answer that question are in a materially worse position than organizations that can.
(Note: a broader overhaul of the HIPAA Security Rule has been proposed but is not yet finalized — HHS has indicated further action is not expected before mid-2027. The current risk analysis requirement described here is unaffected by that pending rule and remains fully in effect.)
Who Actually Needs to Do This?
If your organization creates, receives, maintains, or transmits ePHI, you need a risk analysis. This includes:
- Skilled nursing facilities and long-term care providers
- Small and mid-size physician practices, dental practices, and specialty clinics
- Telehealth and behavioral health providers
- Business associates — billing companies, IT vendors, EHR platforms, and any contractor with access to PHI on your behalf
There’s no size exemption. There’s also no one-time exemption — a risk analysis from three years ago, before your organization added new software, changed vendors, or expanded services, doesn’t reflect your current environment and won’t hold up as “accurate and thorough” if it’s reviewed.
What the Risk Analysis Actually Requires
HHS doesn’t prescribe one specific method, but its published guidance lays out the questions a thorough risk analysis needs to answer, including:
- Have you identified all the ePHI your organization creates, receives, maintains, or transmits — including ePHI that outside vendors or consultants touch on your behalf?
- What are the human, natural, and environmental threats to the systems that contain that ePHI?
- What safeguards — administrative, physical, and technical — are currently in place, and are they adequate for the risks identified?
In practice, that means walking through:
- Scope — Where does ePHI live? EHR systems, billing software, email, mobile devices, backup systems, third-party portals.
- Threats and vulnerabilities — What could realistically go wrong? Lost devices, phishing, unpatched software, an employee with more access than their role requires, a vendor without a signed BAA.
- Current safeguards — What’s already protecting that ePHI, and where are the gaps?
- Risk rating — How likely is each risk, and how severe would the impact be?
- Remediation plan — What are you going to do about the risks you’ve identified, who owns each item, and by when?
The output isn’t just a report — it’s a working document your organization uses to prioritize security decisions for the following year.
The Free Tool HHS Publishes
HHS’s Office for Civil Rights and ONC jointly maintain a free Security Risk Assessment Tool, built specifically for small and medium-sized providers. It’s a downloadable, wizard-style application that walks you through the risk analysis process — multiple-choice questions, threat and vulnerability review, and vendor/asset tracking — and generates a report you can save and use as documentation.
A few things worth knowing before you use it:
- It’s free, and it runs locally — nothing you enter is transmitted to or stored by HHS.
- It’s available as a Windows desktop application or as an Excel workbook, for organizations that need a non-Windows option.
- HHS is explicit that completing the tool does not, by itself, guarantee HIPAA compliance. It’s a structured starting point, not a substitute for judgment about your specific environment — and it works best when someone with real familiarity with your operations is answering the questions, not filling it out as a checkbox exercise.
You can find the current version through HealthIT.gov’s Security Risk Assessment Tool page, alongside HHS’s companion Guidance on Risk Analysis, which lays out the regulatory expectations in more detail.
Doing It Yourself, Hiring a Consultant, or Using a Platform
Small organizations generally have three paths, and none of them is automatically wrong:
- DIY with the free HHS tool — lowest cost, but requires someone internally who can commit real time to it and understands your systems well enough to answer accurately.
- Hiring a consultant — higher cost, but brings outside expertise and an independent perspective, which can matter if you’re preparing for scrutiny.
- Using a compliance platform — sits between the two, typically automating documentation and tracking while still requiring internal input to be accurate.
The right choice depends on your organization’s size, internal capacity, and risk tolerance — not on which option is trendiest. What matters most to OCR isn’t which path you chose, but whether the result is accurate, thorough, and something you’re actively using.
Common Mistakes Small Facilities Make
- Treating it as a one-time task. A risk analysis reflects a moment in time. New software, a new vendor, a new location, or a new EHR module all change your risk picture.
- Documenting policies without evidence they’re followed. OCR’s stated expectation is moving toward proof that controls are implemented and tested — not just that a policy document exists.
- Skipping business associates. If a vendor touches ePHI on your behalf, their risk posture is part of your exposure. A signed Business Associate Agreement is necessary but doesn’t cover everything a BAA leaves exposed — that’s covered in more depth in the linked article below.
- No remediation follow-through. Identifying a risk and not acting on it is, from an enforcement perspective, close to not having identified it at all.
What Happens After the Assessment
Completing the SRA is the beginning of an ongoing responsibility, not the end of one. Most of the actual compliance work — and most of the risk of drifting out of compliance — happens in the months between assessments, when there’s no deadline forcing attention back to it. We cover a simple, sustainable maintenance cadence for that period in a companion article.
Coming Soon…
This page is the starting point for our HIPAA fundamentals series. For more detail on specific parts of this process:
- Your SRA Passed. Now What? A Month-by-Month Maintenance Cadence — a practical, month-by-month maintenance cadence for the period between assessments.
- The HIPAA Compliance Officer Job Nobody Applied For — for the office manager or nurse who’s been handed the Security Officer title with no formal handoff.
- What a BAA Actually Protects You From (And What It Doesn’t) — where a signed Business Associate Agreement still leaves your organization exposed.
- Telehealth Consent Forms: What HIPAA Requires vs. What Your Platform Vendor Tells You — for telehealth and behavioral health practices navigating vendor claims.
Official Sources
- HHS Security Risk Assessment Tool — HealthIT.gov
- HHS Guidance on Risk Analysis
- HHS OCR Resolution Agreements
This page is maintained by AffableONE and reviewed for accuracy against current HHS and OCR guidance. It is intended as educational content, not legal advice.