HIPAA Risk Assessment Toolby Agent Trust Cloud

HIPAA risk assessment requirements

What the Security Rule actually requires, what the risk assessment is for, and which other requirements depend on it.

What is the main purpose of a HIPAA risk assessment?

To find out where the ePHI you hold is exposed, and how badly, so you can choose safeguards that reduce those risks to a "reasonable and appropriate" level. HHS's HHS Office for Civil Rights: Guidance on Risk Analysis calls risk analysis the first step in identifying and implementing safeguards: the rest of the Security Rule's flexibility (choosing how to implement each standard) depends on it.

The requirements, from the rule text

RequirementCitationStatus
Risk analysis: accurate and thorough assessment of risks and vulnerabilities to ePHI45 CFR 164.308: administrative safeguards (a)(1)(ii)(A)Required
Risk management: security measures that reduce risks to a reasonable and appropriate level164.308(a)(1)(ii)(B)Required
Information system activity review164.308(a)(1)(ii)(D)Required
Periodic technical and non-technical evaluation164.308(a)(8)Required
Assess each addressable specification and document the decision45 CFR 164.306: general rules, including addressable specifications (d)(3)Required process
Keep documentation six years; review and update it periodically45 CFR 164.316: policies, procedures and documentation (b)(2)Required

The full list of standards, each marked required or addressable, is the Appendix A to Subpart C of Part 164: Security Standards Matrix (eCFR); our checklist reproduces it with a question for each.

What the requirement does not say

What the proposed rule would change

The January 2025 proposed rule (Federal Register, 6 January 2025: HIPAA Security Rule proposed rule (90 FR 898)) would, among other things, spell out what a risk analysis must contain and require a written technology asset inventory and network map. It is not final; the current rule applies. See the rule status page.

Find your gaps and build a risk register in about 15 minutes: Start the free HIPAA risk assessment

Questions

What is the main purpose of a HIPAA risk assessment?

To identify the risks and vulnerabilities to the confidentiality, integrity and availability of the ePHI an organization holds, so it can choose and document safeguards that reduce those risks to a reasonable and appropriate level.

Does HHS require a specific risk assessment tool?

No. The Security Rule doesn't prescribe a method or tool, and HHS doesn't endorse commercial tools. HHS's own SRA Tool says using it isn't required by law and is no guarantee of compliance.

Not legal advice. This is a free self-assessment aid, not an audit, a certification or legal advice, and it isn't affiliated with or endorsed by HHS. A quick check is not a full risk analysis: HHS expects an accurate and thorough assessment of the risks to all the ePHI you hold.

Sources