HIPAA risk assessment requirements
What the Security Rule actually requires, what the risk assessment is for, and which other requirements depend on it.
What is the main purpose of a HIPAA risk assessment?
To find out where the ePHI you hold is exposed, and how badly, so you can choose safeguards that reduce those risks to a "reasonable and appropriate" level. HHS's HHS Office for Civil Rights: Guidance on Risk Analysis calls risk analysis the first step in identifying and implementing safeguards: the rest of the Security Rule's flexibility (choosing how to implement each standard) depends on it.
The requirements, from the rule text
| Requirement | Citation | Status |
|---|---|---|
| Risk analysis: accurate and thorough assessment of risks and vulnerabilities to ePHI | 45 CFR 164.308: administrative safeguards (a)(1)(ii)(A) | Required |
| Risk management: security measures that reduce risks to a reasonable and appropriate level | 164.308(a)(1)(ii)(B) | Required |
| Information system activity review | 164.308(a)(1)(ii)(D) | Required |
| Periodic technical and non-technical evaluation | 164.308(a)(8) | Required |
| Assess each addressable specification and document the decision | 45 CFR 164.306: general rules, including addressable specifications (d)(3) | Required process |
| Keep documentation six years; review and update it periodically | 45 CFR 164.316: policies, procedures and documentation (b)(2) | Required |
The full list of standards, each marked required or addressable, is the Appendix A to Subpart C of Part 164: Security Standards Matrix (eCFR); our checklist reproduces it with a question for each.
What the requirement does not say
- It doesn't prescribe a method, a template or a tool. HHS doesn't approve or certify risk assessment tools.
- It doesn't set a number of months between assessments today; see how often.
- It doesn't exempt small practices; it lets them choose proportionate safeguards.
What the proposed rule would change
The January 2025 proposed rule (Federal Register, 6 January 2025: HIPAA Security Rule proposed rule (90 FR 898)) would, among other things, spell out what a risk analysis must contain and require a written technology asset inventory and network map. It is not final; the current rule applies. See the rule status page.
Find your gaps and build a risk register in about 15 minutes: Start the free HIPAA risk assessment
Questions
What is the main purpose of a HIPAA risk assessment?
To identify the risks and vulnerabilities to the confidentiality, integrity and availability of the ePHI an organization holds, so it can choose and document safeguards that reduce those risks to a reasonable and appropriate level.
Does HHS require a specific risk assessment tool?
No. The Security Rule doesn't prescribe a method or tool, and HHS doesn't endorse commercial tools. HHS's own SRA Tool says using it isn't required by law and is no guarantee of compliance.
Not legal advice. This is a free self-assessment aid, not an audit, a certification or legal advice, and it isn't affiliated with or endorsed by HHS. A quick check is not a full risk analysis: HHS expects an accurate and thorough assessment of the risks to all the ePHI you hold.
Sources
- 45 CFR 164.308: administrative safeguards
- 45 CFR 164.306: general rules, including addressable specifications
- 45 CFR 164.316: policies, procedures and documentation
- Appendix A to Subpart C of Part 164: Security Standards Matrix (eCFR)
- HHS Office for Civil Rights: Guidance on Risk Analysis
- Federal Register, 6 January 2025: HIPAA Security Rule proposed rule (90 FR 898)
- Checked 1 October 2026.