HIPAA Risk Assessment Toolby Agent Trust Cloud

HIPAA risk assessment template

A template helps only if its columns force the thinking the rule asks for. These are the three sheets we use, with the columns and a worked example. The free tool fills in sheet 2 for you.

Sheet 1: ePHI asset inventory

AssetTypeLocation / hostOwnerStores / processes / transmits ePHIVendor and BAA
Front desk PC 1WorkstationReceptionOffice managerProcesses (EHR in browser)Not a vendor
Hosted EHRCloud applicationVendor data centerPractice ownerStores, processes, transmitsEHR vendor, BAA signed

Use asset names and tags only. Never put patient information in the inventory.

Sheet 2: risk register

AssetThreatVulnerabilityExisting controlsLikelihood (1-5)Impact (1-5)RiskSafeguardDecision
Office emailPhishing leads to account takeoverNo multi-factor authenticationSpam filter, yearly training4416 High164.312(d)Reduce: turn on MFA

Risk = likelihood × impact (the qualitative approach in NIST SP 800-30 Rev. 1: Guide for Conducting Risk Assessments). Keep a reason for each rating in a notes column.

Sheet 3: remediation plan

RiskActionOwnerDueStatusEvidence
Email account takeoverEnable MFA for all mailboxes; block legacy sign-inIT provider30 daysOpenScreenshot of MFA policy

The plan is the risk management specification, 45 CFR 164.308: administrative safeguards (a)(1)(ii)(B): a register without a plan is a common gap.

Let the free tool draft sheet 2

Answer the safeguard questions in the free HIPAA risk assessment tool and it builds the risk register for you: one row per gap, with the citation, a default likelihood and impact you can change, the score and level, a recommended action, and owner and due-date fields. Download it as CSV for Excel or Google Sheets, or as a printable report.

Find your gaps and build a risk register in about 15 minutes: Start the free HIPAA risk assessment

Questions

What columns should a HIPAA risk register have?

At least: asset, threat, vulnerability, existing controls, likelihood, impact, risk score, the Security Rule safeguard concerned, the decision (reduce, accept, transfer or avoid), owner and due date. Keep the reason for each rating.

Is there a free HIPAA risk assessment template in Excel?

The free tool on this site downloads your risk register as a CSV file that opens in Excel or Google Sheets, with one row per safeguard gap and columns for likelihood, impact, risk, action, owner and due date.

Not legal advice. This is a free self-assessment aid, not an audit, a certification or legal advice, and it isn't affiliated with or endorsed by HHS. A quick check is not a full risk analysis: HHS expects an accurate and thorough assessment of the risks to all the ePHI you hold.

Sources