HIPAA security risk assessment
Every covered entity and business associate has to assess the risks to the electronic protected health information (ePHI) it holds. Here is what that means in practice, with the rule text one click away.
Rule status, checked 1 October 2026: a risk analysis is required today under 45 CFR 164.308(a)(1)(ii)(A). HHS's proposed Security Rule update (January 2025) is not final; the current rule applies. Details and dates.
The requirement in one sentence
The Security Rule tells covered entities and business associates to conduct "an accurate and thorough assessment of the potential risks and vulnerabilities" to the confidentiality, integrity and availability of the ePHI they hold (45 CFR 164.308: administrative safeguards, paragraph (a)(1)(ii)(A)). The rule calls it a risk analysis; most people say security risk assessment or SRA. They mean the same document.
Who has to do one
- Covered entities: health plans, health care clearinghouses, and health care providers that send health information electronically in connection with standard transactions such as claims. That includes most medical, dental, therapy and chiropractic practices that bill insurance.
- Business associates: vendors that create, receive, maintain or transmit ePHI for a covered entity, such as billing companies, IT providers and cloud services.
Size doesn't change the requirement. 45 CFR 164.306: general rules, including addressable specifications lets you weigh your size, capabilities and costs when choosing safeguards (paragraph (b)); it doesn't let you skip the analysis.
What HHS expects the assessment to contain
HHS's HHS Office for Civil Rights: Guidance on Risk Analysis doesn't prescribe a method, but it describes the elements a sound analysis includes:
- Scope: all ePHI, in every form of electronic media: servers, laptops, phones, cloud services, backups, medical devices.
- Data collection: where ePHI is stored, received, maintained or transmitted.
- Threats and vulnerabilities: reasonably anticipated threats (ransomware, phishing, theft, fire, staff error) and the weaknesses they could exploit.
- Current security measures, and whether they're configured and used properly.
- Likelihood that each threat will occur and its impact if it does.
- Level of risk: likelihood combined with impact.
- Documentation of all of the above, and periodic review and updates.
Scope: follow the ePHI, not the org chart
Trace a patient visit: scheduling, intake forms, the EHR, e-prescribing, imaging, billing, claims, email, patient messages, backups and anything a vendor hosts. Every system on that path is in scope.
| Where ePHI often hides | Why it's missed |
|---|---|
| Email and shared drives | Seen as office tools, not clinical systems |
| Backups and old servers | Out of sight once set up |
| Multifunction printers and scanners | Many keep images on an internal drive |
| Staff phones and home computers | Used "just this once" for work |
| Vendors and AI tools | ePHI leaves your systems entirely |
Rating likelihood and impact
Most practices use a qualitative 1-to-5 scale for each, the method described in NIST SP 800-30 Rev. 1: Guide for Conducting Risk Assessments. Multiply them for a score from 1 to 25 and band it: 1-4 low, 5-9 medium, 10-16 high, 20-25 critical. Write down why you chose each rating ("no MFA on email, staff receive phishing weekly" is a reason; "medium" alone isn't). NIST's NIST SP 800-66 Rev. 2: Implementing the HIPAA Security Rule (February 2024) walks through the whole process for regulated entities.
What to keep
45 CFR 164.316: policies, procedures and documentation requires you to keep required documentation, including assessments, for six years from creation or from when it was last in effect, whichever is later. Keep each year's version: it shows the analysis is maintained.
- The asset and ePHI inventory
- The risk register with ratings and reasons
- The risk management plan with owners, dates and completion notes (required by 45 CFR 164.308: administrative safeguards (a)(1)(ii)(B))
- Evidence that safeguards exist: settings screenshots, policies, training records, backup restore tests, signed business associate agreements
Where the free tool fits
The free tool on this site asks one question for each of the Security Rule's 46 implementation specifications and standards (24 required, 22 addressable), plus a scope check for AI tools, and turns the gaps into a likelihood × impact risk register you can download. A quick check is not a full risk analysis: HHS expects an accurate and thorough assessment. Use it to find where to start and to structure the register, then complete the asset inventory and threat analysis.
Find your gaps and build a risk register in about 15 minutes: Start the free HIPAA risk assessment
Questions
Is a HIPAA security risk assessment mandatory?
Yes. 45 CFR 164.308(a)(1)(ii)(A) requires covered entities and business associates to conduct an accurate and thorough assessment of risks to the ePHI they hold. It is a required implementation specification, not an addressable one.
Is a risk assessment the same as a risk analysis?
In HIPAA usage, yes. The regulation says risk analysis; most guidance and vendors say security risk assessment (SRA).
How long do I keep a risk assessment?
Six years from the date it was created or last in effect, whichever is later, under 45 CFR 164.316(b)(2)(i).
Not legal advice. This is a free self-assessment aid, not an audit, a certification or legal advice, and it isn't affiliated with or endorsed by HHS. A quick check is not a full risk analysis: HHS expects an accurate and thorough assessment of the risks to all the ePHI you hold.
Sources
- 45 CFR 164.308: administrative safeguards
- 45 CFR 164.306: general rules, including addressable specifications
- 45 CFR 164.316: policies, procedures and documentation
- HHS Office for Civil Rights: Guidance on Risk Analysis
- NIST SP 800-66 Rev. 2: Implementing the HIPAA Security Rule (February 2024)
- NIST SP 800-30 Rev. 1: Guide for Conducting Risk Assessments
- Checked 1 October 2026.