HIPAA risk assessment template
A template helps only if its columns force the thinking the rule asks for. These are the three sheets we use, with the columns and a worked example. The free tool fills in sheet 2 for you.
Sheet 1: ePHI asset inventory
| Asset | Type | Location / host | Owner | Stores / processes / transmits ePHI | Vendor and BAA |
|---|---|---|---|---|---|
| Front desk PC 1 | Workstation | Reception | Office manager | Processes (EHR in browser) | Not a vendor |
| Hosted EHR | Cloud application | Vendor data center | Practice owner | Stores, processes, transmits | EHR vendor, BAA signed |
Use asset names and tags only. Never put patient information in the inventory.
Sheet 2: risk register
| Asset | Threat | Vulnerability | Existing controls | Likelihood (1-5) | Impact (1-5) | Risk | Safeguard | Decision |
|---|---|---|---|---|---|---|---|---|
| Office email | Phishing leads to account takeover | No multi-factor authentication | Spam filter, yearly training | 4 | 4 | 16 High | 164.312(d) | Reduce: turn on MFA |
Risk = likelihood × impact (the qualitative approach in NIST SP 800-30 Rev. 1: Guide for Conducting Risk Assessments). Keep a reason for each rating in a notes column.
Sheet 3: remediation plan
| Risk | Action | Owner | Due | Status | Evidence |
|---|---|---|---|---|---|
| Email account takeover | Enable MFA for all mailboxes; block legacy sign-in | IT provider | 30 days | Open | Screenshot of MFA policy |
The plan is the risk management specification, 45 CFR 164.308: administrative safeguards (a)(1)(ii)(B): a register without a plan is a common gap.
Let the free tool draft sheet 2
Answer the safeguard questions in the free HIPAA risk assessment tool and it builds the risk register for you: one row per gap, with the citation, a default likelihood and impact you can change, the score and level, a recommended action, and owner and due-date fields. Download it as CSV for Excel or Google Sheets, or as a printable report.
Find your gaps and build a risk register in about 15 minutes: Start the free HIPAA risk assessment
Questions
What columns should a HIPAA risk register have?
At least: asset, threat, vulnerability, existing controls, likelihood, impact, risk score, the Security Rule safeguard concerned, the decision (reduce, accept, transfer or avoid), owner and due date. Keep the reason for each rating.
Is there a free HIPAA risk assessment template in Excel?
The free tool on this site downloads your risk register as a CSV file that opens in Excel or Google Sheets, with one row per safeguard gap and columns for likelihood, impact, risk, action, owner and due date.
Not legal advice. This is a free self-assessment aid, not an audit, a certification or legal advice, and it isn't affiliated with or endorsed by HHS. A quick check is not a full risk analysis: HHS expects an accurate and thorough assessment of the risks to all the ePHI you hold.