hipaa.systems
Security Rule · 45 CFR 164.308(a)(1)(ii)(A), 164.308(a)(1)(ii)(B)

Security risk analysis

Every covered entity and business associate must document an accurate and thorough assessment of risks to the ePHI it holds — and then act on it. It is one of the most commonly missing pieces of HIPAA compliance, including in small practices.

Checked 2026-10-05Sources 4

Security risk analysis at a glance

A HIPAA security risk analysis is a required, documented assessment of the risks and vulnerabilities to the confidentiality, integrity and availability of the electronic protected health information an organization holds. Every covered entity and business associate must perform one under 45 CFR 164.308(a)(1)(ii)(A), then implement security measures that reduce those risks to a reasonable level. It is one of the most common gaps found in HHS audits.

RuleHIPAA Security Rule, 45 CFR 164.308(a)(1)(ii)(A)–(B)
StatusRequired
Applies toCovered entities and business associates
OutputWritten analysis of risks to ePHI plus a risk management plan
When to updateHIPAA sets no fixed interval; keep it current — we recommend yearly and whenever systems, vendors or locations change
Free toolHHS / ONC Security Risk Assessment Tool

Risk analysis is a required implementation specification: you must “conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability” of the electronic PHI you hold (164.308(a)(1)(ii)(A)). The next specification, risk management, requires you to then implement measures that reduce those risks to a reasonable and appropriate level.

Why it comes first

Almost every other Security Rule decision depends on it. Addressable safeguards such as encryption are decided in light of your risk analysis, and the rule’s flexibility — scaling measures to your size, complexity, technical capabilities and costs (164.306(b)) — only works if you have written down what your risks are.

In HHS audits, a missing or superficial risk analysis is one of the most common findings — in its 2016–2017 audits, OCR found most covered entities had not substantially met this requirement. Signing BAAs with all your vendors does not substitute for it.

What a usable risk analysis covers

There is no mandated format, but in practice it needs to:

  1. Inventory where ePHI lives and moves — EHR, email, file storage, messaging, laptops and phones, backups, vendors.
  2. Identify threats and vulnerabilities for each place — lost devices, phishing, misdirected email, weak passwords, a vendor outage.
  3. Record current safeguards and how well they work.
  4. Rate likelihood and impact, and assign a risk level.
  5. Document the result and a plan — who fixes what, by when.
  6. Keep it current when something changes (a new tool, a new office, an incident). The rule sets no fixed interval; we recommend reviewing it at least yearly.

What this means when choosing tools

Each new tool that touches PHI belongs in the inventory. The questions worth answering before you buy — does the vendor sign a BAA, is data encrypted, are there audit logs, can you enforce strong sign-in — are exactly the ones your risk analysis will ask afterwards.

Tools and services where this matters

Guides

Scenarios

Frequently asked questions

Is a HIPAA risk assessment the same as a risk analysis?

In practice the terms are used interchangeably. The Security Rule's term is risk analysis: an accurate and thorough assessment of risks to ePHI, followed by risk management.

How often do I need a HIPAA risk assessment?

The rule does not set a fixed frequency. It must be kept current: review it regularly and update it whenever you add systems or vendors, move offices, or have an incident.

Is there an official HIPAA risk assessment template?

There is no mandated format. HHS and ONC offer a free Security Risk Assessment Tool designed for small and medium providers.