HIPAA Risk Assessment Toolby Agent Trust Cloud

How often should you do a HIPAA risk assessment?

The current rule doesn't give a number of months. It does require the analysis to stay accurate, which in practice means reviewing it regularly and whenever things change.

What the current rule requires

HHS's HHS Office for Civil Rights: Guidance on Risk Analysis describes risk analysis as an ongoing process and doesn't set a fixed interval. Many organizations review yearly because it's easy to schedule and to show.

Triggers for an update between reviews

A realistic yearly rhythm for a small practice

WhenWhat
Once a yearUpdate the inventory and risk register; review policies; security training
Twice a yearTest a backup restore; review user access
Every monthCheck open remediation items; look at sign-in alerts
On changeNew system, move, new vendor, incident: update the analysis

Proposed rule: the January 2025 proposal (Federal Register, 6 January 2025: HIPAA Security Rule proposed rule (90 FR 898)) would require, among other things, reviewing and updating the risk analysis and the technology asset inventory at least every 12 months. It isn't final; see the rule status page.

Find your gaps and build a risk register in about 15 minutes: Start the free HIPAA risk assessment

Questions

Is a yearly HIPAA risk assessment required by law?

The current Security Rule does not set a fixed interval, but it requires the analysis to stay accurate and evaluations to follow environmental or operational changes; yearly review is common practice. The January 2025 proposed rule would add a 12-month requirement if finalized.

What should trigger a new HIPAA risk assessment?

New systems or vendors that handle ePHI (including AI tools), an office move, a security incident, a merger, or any change that affects how ePHI is stored, received, maintained or transmitted.

Not legal advice. This is a free self-assessment aid, not an audit, a certification or legal advice, and it isn't affiliated with or endorsed by HHS. A quick check is not a full risk analysis: HHS expects an accurate and thorough assessment of the risks to all the ePHI you hold.

Sources