Skip to content

Resource

HIPAA Security Risk Analysis: What It Requires (and Why "We'll Get to It" Isn't a Plan)

A HIPAA Security Risk Analysis is a documented assessment of where the practice's ePHI lives, what could threaten it, what protections are in place, and what risk remains. It is required under the HIPAA Security Rule for every covered entity and business associate, regardless of size.

Many practices skip it, buy a generic template and call it done, or treat it as a box to check at insurance renewal. None of those approaches produce what OCR expects, and the gap tends to surface at the worst possible moment: after a breach, or during an investigation.

Dawn SizerDawn Sizer · CEO and Co-Founder, 3rd Element Consulting ·

What a credible analysis covers

  • Scope. Every place ePHI is created, received, stored, or sent, including the EHR, email, cloud storage, laptops, phones, and backups.
  • Data flow.
  • Threats and vulnerabilities. Realistic ones for your environment, not a generic list.
  • Current safeguards. The protections already in place, documented clearly.
  • Likelihood and impact. How likely each threat is and what would happen if it occurred.
  • Level of risk. A clear rating for each risk.
  • Documentation. The analysis written down in a form you could hand to an auditor.

What doesn't count on its own

A template, the EHR vendor, an insurance questionnaire, or a general HIPAA checklist does not count as a Security Risk Analysis on its own.

HHS offers a free Security Risk Assessment Tool for small and mid-sized practices. It is a reasonable starting point, though many practices still need help turning the results into a remediation plan.

How often it needs updating

The Security Rule does not set a fixed schedule, but the analysis has to stay accurate. Annually and after any significant change is the accepted baseline. That includes a new EHR, a new location, a new cloud service, or a security incident.

The analysis is the start, not the finish

Risk management means acting on what the analysis finds. That may mean adding a control, scheduling a fix with a deadline, or documenting a decision to accept a specific risk. An analysis that sits in a folder leaves most of the exposure in place.

Why this matters now

OCR has made risk analysis a formal enforcement priority. Actions have included small organizations and settlements in the tens of thousands, and every settlement comes with a corrective action plan that runs for years.

The Security Rule update is delayed, but the expectations aren't

HHS proposed the most significant update to the Security Rule in more than a decade, and the target for a final rule is July 2027. Read what the delay means for your practice. Until then, the existing Security Rule is in effect, but in active investigations OCR already looks at whether a practice's cybersecurity holds up against today's threats, not just whether a risk analysis document exists. A risk analysis that ignores ransomware, phishing, or unprotected remote access is not accurate and thorough.

Since 2021, OCR must consider whether an organization had recognized security practices in place for the previous 12 months, such as the NIST Cybersecurity Framework, when determining penalties and audit outcomes. Controls like MFA, encryption, tested backups, and access reviews can directly affect how an investigation turns out.

The practical takeaway is to build to the standard regulators are already applying, so the final rule becomes a documentation exercise instead of a scramble.

Worksheet

Download the HIPAA Security Risk Analysis Worksheet

A structured worksheet organized by the Security Rule's administrative, physical, and technical safeguards, with a risk register and sign-off section.

The controls behind a good analysis are the same foundational ones covered in our guide to CIS Controls and NIST CSF.

Common questions

Questions leadership usually asks first.

Next step

Not sure where your practice stands?

Schedule an IT Environment Review.