Skip to main content

The HIPAA Risk Assessment: What It Is, Why It’s Required, and How to Actually Do One

HIPAA Risk Assessment – Atlantic Computer Systems

Of all the HIPAA requirements that small medical practices fail to meet, the Risk Assessment is the most consequential — and the most misunderstood. Practices either skip it entirely, confuse it with a checklist, or do it once and forget it exists.

The Office for Civil Rights cited failure to conduct an adequate Risk Analysis in over 60% of HIPAA enforcement actions between 2020 and 2024. It is not just a compliance checkbox — it is the documented foundation that every other security decision in your practice is supposed to rest on.

This guide explains exactly what a HIPAA Risk Assessment is, what it must include to satisfy OCR, how often you need to do it, and how to actually complete one without hiring a consultant.

In This Article
  • What a HIPAA Risk Assessment actually is (and what it is not)
  • What HIPAA requires — the exact regulatory language
  • How often you need to do one
  • The 8 components OCR expects to see
  • Common mistakes that invalidate your assessment
  • Free tools and templates to get it done

What a HIPAA Risk Assessment Actually Is

A HIPAA Risk Assessment (formally called a Risk Analysis under the Security Rule) is a documented process of identifying the risks to the confidentiality, integrity, and availability of electronic protected health information (ePHI) in your practice — and evaluating how likely those risks are to occur and how severe the consequences would be.

It is not a one-page checklist. It is not a vendor questionnaire. It is not the same as a penetration test or vulnerability scan (though those can feed into it). It is a systematic, documented analysis of your specific environment, your specific threats, and your specific vulnerabilities.

✓ A Risk Assessment IS…
  • A documented inventory of where ePHI lives in your practice
  • An analysis of threats and vulnerabilities specific to your environment
  • A written evaluation of current controls and their effectiveness
  • A risk rating for each identified threat
  • An ongoing process, not a one-time event
✕ A Risk Assessment is NOT…
  • A generic HIPAA compliance checklist
  • A vendor security questionnaire
  • A penetration test or network scan
  • A one-page self-attestation
  • Something you do once at setup and never revisit

What HIPAA Actually Requires

The requirement comes from the Administrative Safeguards section of the HIPAA Security Rule. Here is the exact language:

“Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate.”
— HIPAA Security Rule, 45 CFR Part 164

The regulation does not prescribe a specific format or methodology — OCR has consistently said the assessment must be “accurate and thorough” and appropriate for the size and complexity of your organization. What it does require is that the process be documented and that you act on the findings.

How Often Do You Need to Do One?

HIPAA does not specify a frequency. What it requires is that the Risk Assessment be kept current. OCR guidance says you must review and update it whenever:

You adopt new technology (new EHR, new telehealth platform, new cloud storage)
You add a new location or change your physical environment
You experience a security incident or breach
There are significant changes in the regulatory environment
Enough time has passed that your current assessment no longer reflects reality
In practice: most compliance advisors recommend a full reassessment annually and a review whenever significant changes occur. OCR has penalized practices whose most recent Risk Assessment was more than two years old.

The 8 Components OCR Expects to See

1
Scope of the analysis
Define what you are assessing: all systems, devices, applications, and locations where ePHI is created, received, maintained, or transmitted. Your EHR, billing software, email, fax, tablets, laptops, phones — all of it.
2
ePHI inventory
Document where ePHI actually lives — not where you think it lives. It often ends up in email inboxes, shared drives, old backup tapes, staff personal phones, and third-party apps never formally vetted.
3
Identify threats
List realistic threats: human (hackers, phishing, disgruntled staff) and non-human (hardware failure, fire, flood). Be specific to your environment.
4
Identify vulnerabilities
Weaknesses a threat could exploit: no MFA, unencrypted laptops, shared passwords, outdated OS, no firewall, unlocked server room. Document what you find.
5
Assess current controls
Document what you already have and how effective it is. Be honest — a firewall not updated in three years is a control, but an ineffective one. The goal is accuracy, not a good score.
6
Determine likelihood and impact
Rate each threat/vulnerability: how likely is it to occur (high/medium/low) and how severe would the impact be? This produces your risk level for each item.
7
Document findings
Everything must be in writing, dated, and signed by someone with authority. A spreadsheet, formal report, or output from an approved tool all work — as long as it is documented.
8
Implement a Risk Management Plan
Document how you plan to reduce identified risks: which controls you will implement, in what timeframe, and who is responsible. An assessment with no action plan does not satisfy HIPAA.

Common Mistakes That Invalidate Your Assessment

Using a generic template without customizing it. A downloaded checklist that does not reference your specific systems is not a Risk Assessment.
Not inventorying all ePHI locations. If your assessment only covers the EHR and ignores email, billing software, and staff phones, it is incomplete.
No risk ratings. Listing threats without assessing likelihood and impact does not satisfy the “accurate and thorough” standard.
No Risk Management Plan. An assessment with no remediation action plan does not satisfy HIPAA.
Never updating it. A Risk Assessment from 2019 that has not been reviewed since does not reflect your current environment.

Free Tools to Get It Done

🏢
HHS Security Risk Assessment (SRA) Tool
A free downloadable app from HHS designed for small and medium practices. It walks through each required component, generates a report, and produces documentation suitable for OCR review. Available at healthit.gov/topic/privacy-security-and-hipaa/security-risk-assessment-tool.
📄
OCR Guidance on Risk Analysis
HHS OCR’s published guidance describes each component in plain language and is the authoritative source for what is expected during an audit.
📋
NIST SP 800-30
The NIST Risk Assessment framework is commonly used in healthcare and is well-regarded by OCR auditors. Good for larger or more complex environments.

The Bottom Line

The HIPAA Risk Assessment is not glamorous. It does not block a phishing email or encrypt a hard drive. What it does is give you a documented, defensible picture of where your risks actually are — and a legal obligation to address the serious ones.

If your practice has never completed a Risk Assessment, or if your last one is more than two years old, that is your highest-priority compliance action right now.

Atlantic Computer Systems
Need help completing your HIPAA Risk Assessment?
Our free 30-minute IT & HIPAA Security Assessment covers the key elements of a Risk Analysis and gives you a clear picture of where your practice stands. No obligation, no jargon.
Book Your Free Assessment →

Is your practice’s IT actually secure?

Book a free 30-minute IT & HIPAA security assessment with our team, no obligation, no jargon.

Book a Free Assessment

Related articles

Request a Quote

Fill out the form below and our team will get back to you within one business day.

Free IT & HIPAA security assessment