How often should you do a HIPAA risk assessment?
The current rule doesn't give a number of months. It does require the analysis to stay accurate, which in practice means reviewing it regularly and whenever things change.
What the current rule requires
- The analysis must be accurate and thorough (45 CFR 164.308: administrative safeguards (a)(1)(ii)(A)), so it has to reflect your systems as they are now.
- You must perform a periodic evaluation, including in response to environmental or operational changes (45 CFR 164.308: administrative safeguards (a)(8)).
- You must review documentation periodically and update it as needed (45 CFR 164.316: policies, procedures and documentation (b)(2)(iii)).
HHS's HHS Office for Civil Rights: Guidance on Risk Analysis describes risk analysis as an ongoing process and doesn't set a fixed interval. Many organizations review yearly because it's easy to schedule and to show.
Triggers for an update between reviews
- A new EHR, practice management system or other major software
- Moving office or opening a location
- A new vendor handling ePHI, including AI tools
- A security incident or breach
- Mergers, acquisitions or big changes in staff
A realistic yearly rhythm for a small practice
| When | What |
|---|---|
| Once a year | Update the inventory and risk register; review policies; security training |
| Twice a year | Test a backup restore; review user access |
| Every month | Check open remediation items; look at sign-in alerts |
| On change | New system, move, new vendor, incident: update the analysis |
Proposed rule: the January 2025 proposal (Federal Register, 6 January 2025: HIPAA Security Rule proposed rule (90 FR 898)) would require, among other things, reviewing and updating the risk analysis and the technology asset inventory at least every 12 months. It isn't final; see the rule status page.
Find your gaps and build a risk register in about 15 minutes: Start the free HIPAA risk assessment
Questions
Is a yearly HIPAA risk assessment required by law?
The current Security Rule does not set a fixed interval, but it requires the analysis to stay accurate and evaluations to follow environmental or operational changes; yearly review is common practice. The January 2025 proposed rule would add a 12-month requirement if finalized.
What should trigger a new HIPAA risk assessment?
New systems or vendors that handle ePHI (including AI tools), an office move, a security incident, a merger, or any change that affects how ePHI is stored, received, maintained or transmitted.
Not legal advice. This is a free self-assessment aid, not an audit, a certification or legal advice, and it isn't affiliated with or endorsed by HHS. A quick check is not a full risk analysis: HHS expects an accurate and thorough assessment of the risks to all the ePHI you hold.