HIPAA Risk Assessment Toolby Agent Trust Cloud

HIPAA security risk assessment

Every covered entity and business associate has to assess the risks to the electronic protected health information (ePHI) it holds. Here is what that means in practice, with the rule text one click away.

Rule status, checked 1 October 2026: a risk analysis is required today under 45 CFR 164.308(a)(1)(ii)(A). HHS's proposed Security Rule update (January 2025) is not final; the current rule applies. Details and dates.

The requirement in one sentence

The Security Rule tells covered entities and business associates to conduct "an accurate and thorough assessment of the potential risks and vulnerabilities" to the confidentiality, integrity and availability of the ePHI they hold (45 CFR 164.308: administrative safeguards, paragraph (a)(1)(ii)(A)). The rule calls it a risk analysis; most people say security risk assessment or SRA. They mean the same document.

Who has to do one

Size doesn't change the requirement. 45 CFR 164.306: general rules, including addressable specifications lets you weigh your size, capabilities and costs when choosing safeguards (paragraph (b)); it doesn't let you skip the analysis.

What HHS expects the assessment to contain

HHS's HHS Office for Civil Rights: Guidance on Risk Analysis doesn't prescribe a method, but it describes the elements a sound analysis includes:

  1. Scope: all ePHI, in every form of electronic media: servers, laptops, phones, cloud services, backups, medical devices.
  2. Data collection: where ePHI is stored, received, maintained or transmitted.
  3. Threats and vulnerabilities: reasonably anticipated threats (ransomware, phishing, theft, fire, staff error) and the weaknesses they could exploit.
  4. Current security measures, and whether they're configured and used properly.
  5. Likelihood that each threat will occur and its impact if it does.
  6. Level of risk: likelihood combined with impact.
  7. Documentation of all of the above, and periodic review and updates.

Scope: follow the ePHI, not the org chart

Trace a patient visit: scheduling, intake forms, the EHR, e-prescribing, imaging, billing, claims, email, patient messages, backups and anything a vendor hosts. Every system on that path is in scope.

Where ePHI often hidesWhy it's missed
Email and shared drivesSeen as office tools, not clinical systems
Backups and old serversOut of sight once set up
Multifunction printers and scannersMany keep images on an internal drive
Staff phones and home computersUsed "just this once" for work
Vendors and AI toolsePHI leaves your systems entirely

Rating likelihood and impact

Most practices use a qualitative 1-to-5 scale for each, the method described in NIST SP 800-30 Rev. 1: Guide for Conducting Risk Assessments. Multiply them for a score from 1 to 25 and band it: 1-4 low, 5-9 medium, 10-16 high, 20-25 critical. Write down why you chose each rating ("no MFA on email, staff receive phishing weekly" is a reason; "medium" alone isn't). NIST's NIST SP 800-66 Rev. 2: Implementing the HIPAA Security Rule (February 2024) walks through the whole process for regulated entities.

What to keep

45 CFR 164.316: policies, procedures and documentation requires you to keep required documentation, including assessments, for six years from creation or from when it was last in effect, whichever is later. Keep each year's version: it shows the analysis is maintained.

Where the free tool fits

The free tool on this site asks one question for each of the Security Rule's 46 implementation specifications and standards (24 required, 22 addressable), plus a scope check for AI tools, and turns the gaps into a likelihood × impact risk register you can download. A quick check is not a full risk analysis: HHS expects an accurate and thorough assessment. Use it to find where to start and to structure the register, then complete the asset inventory and threat analysis.

Find your gaps and build a risk register in about 15 minutes: Start the free HIPAA risk assessment

Questions

Is a HIPAA security risk assessment mandatory?

Yes. 45 CFR 164.308(a)(1)(ii)(A) requires covered entities and business associates to conduct an accurate and thorough assessment of risks to the ePHI they hold. It is a required implementation specification, not an addressable one.

Is a risk assessment the same as a risk analysis?

In HIPAA usage, yes. The regulation says risk analysis; most guidance and vendors say security risk assessment (SRA).

How long do I keep a risk assessment?

Six years from the date it was created or last in effect, whichever is later, under 45 CFR 164.316(b)(2)(i).

Not legal advice. This is a free self-assessment aid, not an audit, a certification or legal advice, and it isn't affiliated with or endorsed by HHS. A quick check is not a full risk analysis: HHS expects an accurate and thorough assessment of the risks to all the ePHI you hold.

Sources