- HIPAA Risk Assessment: Security Rule Requirements Guide
- What Is a HIPAA Risk Assessment?
- Why a HIPAA Risk Assessment Is Required
- Risk Analysis vs. Risk Assessment vs. Risk Management
-
How to Conduct a HIPAA Risk Assessment
- Step 1 — Identify and Inventory ePHI Assets and Systems
- Step 2 — Identify Threats and Vulnerabilities
- Step 3 — Assess Current Security Measures
- Step 4 — Determine Likelihood and Impact
- Step 5 — Determine and Document Risk Levels and Required Controls
- Step 6 — Document the Risk Analysis and Establish a Risk Management Plan
- Step 7 — Review, Update, and Audit
- HIPAA Risk Assessment Requirements Checklist
- Templates and Tools
- Software and Solutions
- How Often to Run a HIPAA Risk Assessment
- Risk Assessment for Specialty Practices
- Common HIPAA Risk Assessment Examples
- How to Simplify HIPAA Risk Assessments
- Key Takeaways
-
HIPAA Risk Assessment FAQs
- What is a HIPAA risk assessment?
- What is the main purpose of a HIPAA risk assessment?
- Is a HIPAA risk assessment required?
- How often should a HIPAA risk assessment be performed?
- How do you conduct a HIPAA risk assessment?
- What is the difference between a HIPAA risk assessment and a HIPAA risk analysis?
- How much does a HIPAA risk assessment cost?
- What should a HIPAA risk assessment template include?
HIPAA Risk Assessment: Security Rule Requirements Guide
A HIPAA risk assessment anchors both a Health Insurance Portability and Accountability Act (HIPAA) security program and the HIPAA Security Rule that governs it. Every covered entity (CE) and business associate (BA) that handles ePHI must run one, document it, and keep it current. When the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) investigates a breach, it cites a missing or stale risk analysis more often than any other failure.
This guide covers what HIPAA requires, the step-by-step process to conduct an assessment, a requirements checklist for audit prep, the tools that support the work, and how often the process must be repeated. The guidance applies to organizations of every size, from a solo practice to a multi-site health plan.
What Is a HIPAA Risk Assessment?
A HIPAA risk assessment is the analysis a covered entity or business associate runs to find, rate, and reduce risks to the ePHI it holds. The HIPAA Security Rule requires it as the Risk Analysis implementation specification, and OCR treats it as the foundation of a compliance program.
HIPAA risk assessments are compliance evaluations that map where ePHI lives, score the threats against it, and record the fixes. The review grounds a HIPAA, HITECH, and NIST SP 800-66 Rev. 2 program by giving OCR the documented, current risk analysis the Security Rule demands.
The assessment examines the ePHI an organization holds across administrative, physical, and technical safeguards. For each family, it weighs how well current controls protect the confidentiality, integrity, and availability of that ePHI and where gaps leave the organization exposed.
Because a HIPAA risk assessment is risk-based, it starts from the ePHI an organization actually holds and the threats it actually faces. Two organizations of the same size can therefore reach different, equally valid safeguard decisions from the same process. That risk-based logic is what the Required and Addressable distinction turns into concrete safeguard choices.
Required vs. Addressable Specifications
The HIPAA Security Rule sorts every implementation specification into two categories, Required and Addressable. A risk assessment is what tells a covered entity or business associate how to satisfy each one.
- A Required specification must be implemented exactly as written.
- An Addressable specification still carries a mandatory obligation, and the risk analysis supplies the evidence behind how an organization meets it.
For each Addressable safeguard, organizations can take one of three documented paths:
- Implement it as written. Apply the safeguard when the risk analysis shows it is reasonable and appropriate for the environment.
- Adopt an equivalent alternative. Substitute a measure that reaches the same level of protection and fits the environment better.
- Document a decision to forgo it. Record the rationale when the risk analysis points to a better-fitting approach, along with any compensating controls already in place.
Encryption of ePHI at rest is a common example. Here, a covered entity weighs its own risk analysis, then either encrypts, adopts an equivalent control, or documents why another safeguard covers the risk. The label sets the method of compliance, and the documented risk analysis justifies every choice.
Why a HIPAA Risk Assessment Is Required
A HIPAA risk assessment is required by the Risk Analysis implementation specification of the HIPAA Security Rule. Under 45 CFR § 164.308(a)(1)(ii)(A), every covered entity and business associate that creates, receives, maintains, or transmits ePHI must conduct one and document the results.
Section 164.308(a)(1)(ii)(A) requires “an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability” of ePHI. Because the specification is Required, every organization must perform it as written.
Every other safeguard decision under the HIPAA Security Rule flows from the risk analysis. Encryption, access control, training cadence, and contingency planning all depend on knowing where ePHI is at risk.
OCR routinely names the risk analysis as a contributing factor in its largest enforcement actions. Its Risk Analysis Initiative produced seven enforcement actions in its first six months, and a separate review tied roughly $1.7 million in fines across four firms to risk-analysis failures.
The obligation reaches every covered entity and business associate regardless of size. A one-person practice carries the same requirement as a hospital system, with no small-organization exemption. The regulatory term “risk analysis” also means a formal, documented process. A one-time vulnerability scan, a vendor questionnaire, or a penetration test alone does not satisfy it.
Published on January 6, 2025, the HHS Notice of Proposed Rulemaking (NPRM) proposes more prescriptive risk-analysis requirements. It would require a written risk analysis reviewed at least every 12 months, plus a written technology asset inventory and network map on the same cadence. The rule remains proposed and not yet effective.
Risk Analysis vs. Risk Assessment vs. Risk Management
HIPAA uses two regulatory terms, risk analysis and risk management, and practitioners commonly add a third, risk assessment.
- Risk analysis is the documented finding step.
- Risk management is the controls step that acts on those findings.
- Risk assessment is the practitioner umbrella term that covers both, and it lends its name to the HHS OCR Security Risk Assessment (SRA) Tool.
In enforcement, OCR often examines whether an organization performed the risk analysis and then acted on it through risk management. Producing an analysis without evidence of management is a common audit failure.
How to Conduct a HIPAA Risk Assessment
Most organizations can run a HIPAA risk assessment in seven steps. Each step produces a clear deliverable, and together they form the documented record OCR expects.
The following step-by-step process aligns with the HHS OCR Final Guidance on Risk Analysis and the NIST SP 800-30 Rev. 1 methodology.
Step 1 — Identify and Inventory ePHI Assets and Systems
Build an inventory of every system, application, device, and third-party service that creates, receives, maintains, or transmits ePHI. Include:
- Electronic health record (EHR) and electronic medical record (EMR) systems
- Billing platforms
- Email that carries ePHI
- Backup media
- Mobile devices
- Business-associate systems
- Cloud storage
The inventory sets the scope for every step that follows. For scope and boundary cases, see the guide to electronic protected health information (ePHI).
Step 2 — Identify Threats and Vulnerabilities
Catalog the threats to each asset, whether natural, environmental, or human, and both intentional and unintentional. Then, list the vulnerabilities a threat could exploit.
Use the NIST SP 800-30 Rev. 1 threat sources and the HHS OCR Risk Analysis Guidance threat categories as the reference set. Pair each vulnerability with the system it affects.
Step 3 — Assess Current Security Measures
Document the administrative, physical, and technical safeguards already in place for each asset. Map every existing control to the ePHI it protects. Flag controls that are partial, undocumented, or inconsistently applied across locations. This current-state view shows where the real gaps sit.
Step 4 — Determine Likelihood and Impact
Rate the likelihood that each threat exploits each vulnerability. Then rate the impact on the confidentiality, integrity, and availability of ePHI if it does. A 5×5 likelihood-by-impact matrix is the common method. Record each score in a register that ties the finding to its safeguard category.
Step 5 — Determine and Document Risk Levels and Required Controls
Assign a risk level, low, medium, or high, to each finding, and specify the remediation action that reduces it. Each control should map back to a 164.308 administrative safeguard, a 164.310 physical safeguard, or a 164.312 technical safeguard. The HIPAA administrative safeguards guide breaks down the full categorical set.
Step 6 — Document the Risk Analysis and Establish a Risk Management Plan
Produce the final risk-analysis report and a risk management plan with owners, due dates, and acceptance criteria for residual risk. This report is the canonical artifact the designated HIPAA Security Officer owns. Isora GRC consolidates the risk-analysis report and risk register into a single workspace, with each finding tied back to the originating safeguard and assessment owner.
Step 7 — Review, Update, and Audit
Set a documented review cadence, annually at minimum, and keep an audit trail of changes. For the audit-control logging that pairs with the review cadence, see the HIPAA security audit guide.
HIPAA Risk Assessment Requirements Checklist
Use the following checklist to confirm a HIPAA risk assessment meets 45 CFR § 164.308(a)(1)(ii)(A) and the HHS OCR Risk Analysis Guidance. It mirrors the 164.308 standard, so it doubles as audit-prep documentation.
Scope and ePHI inventory
- [ ] Documented inventory of every system, application, device, and third-party service handling ePHI
- [ ] Business associates and subcontractors that handle ePHI included in scope
Threat and vulnerability identification
- [ ] Documented threat sources (natural, environmental, human — intentional and unintentional)
- [ ] Documented vulnerabilities per asset
Existing controls assessment
- [ ] Administrative, physical, and technical safeguards mapped to each ePHI asset
- [ ] Gaps and partial controls flagged
Risk determination
- [ ] Likelihood and impact ratings on confidentiality, integrity, and availability
- [ ] Combined risk levels assigned (low / medium / high)
Documentation
- [ ] Written risk-analysis report
- [ ] Risk register linking findings to safeguards
- [ ] Date, scope, and assessor identified
- [ ] Reviewed and approved by the designated Security Officer
Risk management plan
- [ ] Remediation actions assigned with owners and due dates
- [ ] Acceptance criteria for residual risk
Review cadence
- [ ] Documented review frequency (annually at minimum)
- [ ] Trigger conditions for off-cycle reassessment
Documentation must be retained for six years under 45 CFR § 164.316.
Templates and Tools
Several free templates and tools support a HIPAA risk assessment. The most widely used are the HHS Security Risk Assessment (SRA) Tool, NIST-aligned worksheets, and SaltyCloud’s downloadable HIPAA Risk Assessment Template.
The HHS SRA Tool is the official free application from OCR and the Office of the National Coordinator (ONC), available in Windows-desktop and iPad versions. It walks small-to-mid-size practices through the analysis with branching questions. HHS released a significant update to version 3.6 in September 2025. For what changed, what stayed the same, and how to install it, see the HHS Security Risk Assessment Tool — 2025 update guide.
NIST-aligned worksheets derive from NIST SP 800-30 Rev. 1 and NIST SP 800-66 Rev. 2, which supply the methodology behind several published templates from health-sector Information Sharing and Analysis Centers (ISACs) and the Health Sector Coordinating Council.
The HIPAA Risk Assessment Template from SaltyCloud is a free, editable Excel and PDF template covering all seven steps and mapping each finding to its originating 164.308, 164.310, or 164.312 safeguard. Download the HIPAA Risk Assessment Template to start documenting a risk analysis aligned to 164.308(a)(1)(ii)(A).
Several vendors now offer AI-assisted risk-analysis tooling. Artificial intelligence can accelerate threat cataloging and inventory normalization, but the documented analysis still needs human review and Security-Officer approval. Isora GRC’s approach pairs prebuilt HIPAA questionnaires with the connected risk register, so AI suggestions feed into a human-reviewed record. Multi-framework teams can also map controls with the HIPAA Security Rule Crosswalk Toolkit.
Software and Solutions
Purpose-built HIPAA risk assessment software extends a HIPAA program past the HHS SRA Tool’s practical limits. Those limits usually surface with multi-site practices, business-associate networks, or multi-framework compliance. Teams typically outgrow the tool once distributed system owners need to contribute to a single analysis.
HIPAA risk assessment software usually provides:
- Prebuilt questionnaire libraries aligned to 164.308, 164.310, and 164.312
- Distributed assessment workflows for departments, system owners, and BAs
- A risk register that maps findings to safeguards
- An audit trail and documentation export for OCR audits
- Cross-framework reuse across HIPAA, NIST CSF, and NIST 800-53
Cost varies with workflow scope. Organizations should compare the all-in three-year cost, weighing assessment volume, BA count, and framework breadth, rather than the per-seat list price. Training providers such as the Health Care Compliance Association (HCCA), the American Health Information Management Association (AHIMA), and vendor academies also offer HIPAA risk-assessment courses for security officers and assessors.
| Dimension | HHS SRA Tool | NIST-aligned worksheets | Purpose-built software |
|---|---|---|---|
| Cost | Free | Free | Subscription |
| Best for | Solo and small practices | Methodology reference | Multi-site CEs, BAs, multi-framework programs |
| Distributed assessments | No | No | Yes |
| Multi-framework reuse | No | Indirect (NIST family) | Yes |
| Audit trail | Limited | Do-it-yourself | Built-in |
Isora GRC is purpose-built HIPAA risk assessment software for organizations that have outgrown the SRA Tool. See the HIPAA risk assessment software page for detail.
How Often to Run a HIPAA Risk Assessment
The HIPAA Security Rule requires periodic risk analysis but names no fixed interval. HHS OCR guidance and NIST SP 800-66 Rev. 2 both describe risk analysis as an ongoing, periodic activity. Annual review is the practitioner baseline, plus reassessment whenever a triggering event changes the risk picture.
Two provisions frame the cadence.
- Section 164.308(a)(8) requires a “periodic technical and non-technical evaluation.”
- Section 164.316(b)(2)(iii) requires documentation review “as needed.”
Neither sets a number, so the annual baseline comes from OCR guidance and practitioner consensus. Off-cycle reassessment is warranted when a new system or vendor begins handling ePHI, after an organizational change such as a merger or a new clinic, following a breach or near-miss, on a regulatory change, or after a major infrastructure shift such as a cloud migration.
The 2025 NPRM signals a move toward a more prescriptive 12-month cadence and asset-inventory refresh.
Risk Assessment for Specialty Practices
Small and specialty practices carry the same Security Rule obligations as large hospitals, with very different operational realities.
Federally Qualified Health Centers (FQHCs)
FQHCs are Health Resources and Services Administration (HRSA)-funded and often multi-site, and HRSA Health Center Program reporting adds to the baseline HIPAA obligation. For the FQHC-specific workflow, including the HRSA reporting overlap, see the HIPAA risk analysis for federally qualified health centers guide.
Dental Offices
Dental offices are frequently single-location, with imaging vendors acting as business associates. Common gaps include imaging-vendor BA oversight and workstation security in shared operatories, and the HHS SRA Tool fits this scale well.
Small Physician Offices
Small physician practices, from solo to 2–10 providers, most often lack a maintained risk register and a documented business associate agreement (BAA) inventory. HHS OCR Security Series Paper 7 addresses implementation for the small provider.
Common HIPAA Risk Assessment Examples
Three examples drawn from common practice patterns show how a HIPAA risk assessment translates from procedure into documented findings.
A 50-bed hospital migrating to a cloud EHR inventories the cloud-hosted EHR, an on-premises legacy lab system, email, and clinician mobile access. A sample finding: the legacy lab system transmits ePHI in cleartext to an ancillary reporting tool, rated high likelihood and high impact. The remediation implements Transport Layer Security (TLS) 1.2 or higher on that transmission, addressing the transmission-security standard at 45 CFR § 164.312(e)(1).
A four-provider dental office inventories cloud practice-management software, a vendor-hosted digital imaging system, and operatory workstations. A sample finding: operatory workstations lack auto-logoff in shared spaces, rated medium likelihood and medium impact. The remediation enforces a five-minute auto-logoff, addressing the automatic-logoff specification at 45 CFR § 164.312(a)(2)(iii), and adds privacy-screen filters.
A regional health plan with 15 business associates inventories a claims-processing platform, a member portal, and a BA pharmacy network. A sample finding: three BAs have signed BAAs but no annual security questionnaire on file, rated medium likelihood and high impact. The remediation implements an annual BA-questionnaire cadence and remediates or removes non-compliant BAs. A downloadable set of worked examples ships with the HIPAA Risk Assessment Template.
How to Simplify HIPAA Risk Assessments
Teams running HIPAA risk assessments need the analysis to be repeatable, distributed across system owners and business associates, and tied into a connected risk register. Three capabilities of Isora GRC, the GRC Assessment Platform™, make that pattern work, each mapped to a moment in the procedure above.
Questionnaires & Surveys answers the slow-inventory moment in Steps 1 and 3. A prebuilt HIPAA questionnaire library aligned to 164.308, 164.310, and 164.312 distributes to department heads, system owners, and business associates, so no team writes the question set from scratch. The same library serves HIPAA, NIST CSF, and NIST 800-53 programs, so teams are not rebuilding questions before every audit.
Risk Management answers the stranded-findings moment in Steps 5 and 6. Findings publish to a connected risk register with full context, each tied to its originating safeguard and the assessment that produced it. Risk details, attributes, and export options keep the analysis documented and current for the evidence OCR expects.
Assessment Management answers the multi-site and BA-network moment across distributed workflows. Teams distribute assessments to the right system owner, track completion, and consolidate findings into one register. Time-stamped completion records show that the analysis is current across every site.
See how Isora GRC simplifies HIPAA Security Rule compliance →
Key Takeaways
A HIPAA risk assessment is required under 164.308(a)(1)(ii)(A) and runs in seven documented steps, from ePHI inventory to risk-management plan. The most-cited control in OCR enforcement is the missing or stale risk analysis. Run the procedure annually, document everything, and tie every finding back to the safeguard it serves.
The organizations that stay audit-ready treat the assessment as a living program. They keep the ePHI inventory current, revisit risk ratings after each material change, and carry every finding through to documented remediation.
See the GRC Assessment Platform™ in action →
HIPAA Risk Assessment FAQs
What is a HIPAA risk assessment?
A HIPAA risk assessment is the documented process of identifying, analyzing, and mitigating risks to electronic protected health information (ePHI). It is required under 45 CFR § 164.308(a)(1)(ii)(A) for every covered entity and business associate that handles ePHI.
What is the main purpose of a HIPAA risk assessment?
The main purpose is to determine where ePHI is at risk and which administrative, physical, and technical safeguards reduce that risk to a reasonable and appropriate level. It is the foundation for every other Security Rule compliance decision.
Is a HIPAA risk assessment required?
Yes. It is a Required implementation specification under 45 CFR § 164.308(a)(1)(ii)(A), and every covered entity and business associate must complete and document one regardless of size.
How often should a HIPAA risk assessment be performed?
Annually at minimum, plus whenever a triggering event changes the risk picture, such as a new system, a breach, an organizational change, or a regulatory change. The Rule sets no fixed cadence, but HHS OCR treats annual as the baseline.
How do you conduct a HIPAA risk assessment?
In seven steps: identify ePHI assets, identify threats and vulnerabilities, assess existing controls, determine likelihood and impact, document risk levels, write the risk-analysis report and management plan, and review on a defined cadence.
What is the difference between a HIPAA risk assessment and a HIPAA risk analysis?
“Risk analysis” is the regulatory term in 164.308(a)(1)(ii)(A). “Risk assessment” is the practitioner umbrella term and the SRA Tool name. In OCR language, risk analysis is the documented finding step, and risk management is the controls step that follows.
How much does a HIPAA risk assessment cost?
It can be free with the HHS SRA Tool, or reach five figures for consultant-led assessments at multi-site organizations. Purpose-built software is typically priced per user or per assessment, and the all-in three-year cost is the better comparison.
What should a HIPAA risk assessment template include?
An ePHI asset inventory, a threat and vulnerability catalog, a current-controls inventory, likelihood and impact ratings, a risk register linking findings to safeguards, a written risk-analysis report, and a risk management plan with owners and due dates.
This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.