Blog Post

HIPAA Risk Assessment: A Step-by-Step Guide for Healthcare Organizations

Richard P. Kusserow | August 2026

The Department of Health and Human Services Office for Civil Rights’ (OCR) enforcement record shows a consistent pattern: a missing or outdated risk analysis is the most frequently cited finding across HIPAA resolution agreements, ahead of any other Security Rule violation. While many organizations already have a risk assessment on file, far fewer can say with confidence that it would hold up if the OCR requested it tomorrow.

This guide sets out the six steps required under the current HIPAA Security Rule, what the resulting file needs to contain, and how often the process needs to repeat.

What Is a HIPAA Risk Assessment?

A HIPAA risk assessment is a documented evaluation of risk to the confidentiality, integrity, and availability of electronic protected health information (ePHI), required under 45 CFR § 164.308(a)(1).

The process identifies every location where ePHI is created, received, maintained, or transmitted; catalogs the threats and vulnerabilities facing each one; and measures existing safeguards against those threats. The OCR uses “risk assessment” and “risk analysis” interchangeably. Both terms refer to the same required process.

Does HIPAA Require a Risk Assessment?

Yes. The Security Rule requires a risk assessment of every covered entity and business associate that creates, receives, maintains, or transmits ePHI, not only organizations running an electronic health record (EHR) system. This requirement sits alongside the broader set of Security Rule safeguards, and it is the one the rest are built on.

Business associates carry the same obligation as covered entities. Vendor status does not reduce the requirement.

[insert visual CTA: Interested in going deeper with HIPAA Compliance? Get the HIPAA Compliance Checklist.]

The Six Steps of a HIPAA Risk Assessment

1. Define the Scope: Map Every System That Touches ePHI

The first step is an inventory: every device, application, vendor, and cloud service that creates, receives, stores, or transmits ePHI, not just the primary EHR. That includes email, backup systems, remote access tools, mobile devices, and third-party billing platforms.

If anything is missing from this, it will undermine everything that follows. An assessment that covers the EHR but ignores the rest of the environment will not hold up under review, because the OCR evaluates the full scope of where ePHI lives, not the scope an organization assumed was relevant.

2. Identify Threats and Vulnerabilities

This step catalogs external threats, including ransomware, phishing, and unauthorized access, alongside internal ones, including misconfigured permissions, unpatched systems, and untrained staff. The HIPAA Cybersecurity Framework breaks down the technical side of this step for IT and security leads.

3. Assess Current Security Measures

Step three inventories the administrative, physical, and technical safeguards already in place, from access controls to workforce training to facility security, and measures them against the practices NIST SP 800-66 Rev. 2 recommends for the Security Rule. This is where an organization sees the gap between what it believes is protecting ePHI and what is actually in place.

4. Rate Each Risk by Likelihood and Impact

Every identified risk gets scored on how likely it is to occur and how severe the consequences would be. That likelihood-times-impact rating is what turns a list of vulnerabilities into a prioritized plan, so remediation resources go to the risks that carry the most exposure first, rather than the ones that are easiest to fix. This step connects to the organization’s broader risk management program.

5. Document Findings and a Remediation Plan

The file needs to show the methodology used, the systems reviewed, the risks identified, their ratings, and a remediation plan with named owners and target dates. A risk analysis without a documented remediation plan is incomplete in the eyes of the OCR. Identifying a risk and doing nothing with that finding carries its own exposure.

6. Review and Update on an Ongoing Basis

Rather than a file to close out and revisit only when the next audit cycle comes around, a risk assessment is a living document. Tie the review cadence to the organization’s auditing and monitoring process so the two run on the same schedule.

How Often Should a Risk Assessment Be Done?

The OCR does not mandate a fixed annual deadline. The requirement is ongoing: the assessment gets updated whenever something changes, instead of on a fixed calendar. Common triggers for an update include a new EHR or vendor, a security incident, a merger or acquisition, or an expansion into telehealth or remote work. Organizations that wait for a set date to roll around, rather than updating in response to these triggers, are the ones most likely to have a stale assessment on file when the OCR comes asking.

Is the Free HHS SRA Tool Enough?

The Security Risk Assessment (SRA) Tool from HHS and ONC walks organizations through the process at no cost, with both a desktop application and an Excel workbook version. HHS built the tool for small and medium providers. Larger organizations, or those with more complex ePHI environments across multiple systems and vendors, typically need an assessment scoped beyond what the tool covers.

The SRA Tool is a starting point an organization can build from, not a substitute for a scoped, organization-specific assessment.

What Must a HIPAA Risk Assessment Document?

A complete risk assessment clearly documents:

  • Scope of the assessment and the systems reviewed
  • Threats and vulnerabilities identified for each system
  • Likelihood and impact ratings for each identified risk
  • Existing security measures and where they fall short
  • A remediation plan with named owners and target dates
  • Sign-off and a scheduled review date

Missing any one of these turns a completed assessment into an incomplete one in the OCR’s view, regardless of how thorough the underlying analysis was.

What Happens Without a Documented Risk Assessment?

A missing or incomplete risk analysis shows up repeatedly across the OCR’s resolution agreements, often as the first finding cited before any other violation.

The exposure extends beyond the assessment itself. Every other Security Rule safeguard, from access controls to incident response, is meant to be built on what the risk analysis identifies. Without it, the rest of the compliance program has no foundation to stand on, no matter how strong those other safeguards appear on paper.

Get Help With Your HIPAA Risk Assessment

Building a risk assessment from scratch, or having an existing one independently validated before the OCR asks for it, connects to our healthcare risk assessment services. For organizations that need risk management built into the broader compliance program rather than handled as a one-time project, compliance advisory services extend that support further.

If you’re interested in learning more about these services, speak with a HIPAA expert.

Subscribe to blog