Security risk analysis
Every covered entity and business associate must document an accurate and thorough assessment of risks to the ePHI it holds — and then act on it. It is one of the most commonly missing pieces of HIPAA compliance, including in small practices.
Security risk analysis at a glance
A HIPAA security risk analysis is a required, documented assessment of the risks and vulnerabilities to the confidentiality, integrity and availability of the electronic protected health information an organization holds. Every covered entity and business associate must perform one under 45 CFR 164.308(a)(1)(ii)(A), then implement security measures that reduce those risks to a reasonable level. It is one of the most common gaps found in HHS audits.
| Rule | HIPAA Security Rule, 45 CFR 164.308(a)(1)(ii)(A)–(B) |
|---|---|
| Status | Required |
| Applies to | Covered entities and business associates |
| Output | Written analysis of risks to ePHI plus a risk management plan |
| When to update | HIPAA sets no fixed interval; keep it current — we recommend yearly and whenever systems, vendors or locations change |
| Free tool | HHS / ONC Security Risk Assessment Tool |
Risk analysis is a required implementation specification: you must “conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability” of the electronic PHI you hold (164.308(a)(1)(ii)(A)). The next specification, risk management, requires you to then implement measures that reduce those risks to a reasonable and appropriate level.
Why it comes first
Almost every other Security Rule decision depends on it. Addressable safeguards such as encryption are decided in light of your risk analysis, and the rule’s flexibility — scaling measures to your size, complexity, technical capabilities and costs (164.306(b)) — only works if you have written down what your risks are.
In HHS audits, a missing or superficial risk analysis is one of the most common findings — in its 2016–2017 audits, OCR found most covered entities had not substantially met this requirement. Signing BAAs with all your vendors does not substitute for it.
What a usable risk analysis covers
There is no mandated format, but in practice it needs to:
- Inventory where ePHI lives and moves — EHR, email, file storage, messaging, laptops and phones, backups, vendors.
- Identify threats and vulnerabilities for each place — lost devices, phishing, misdirected email, weak passwords, a vendor outage.
- Record current safeguards and how well they work.
- Rate likelihood and impact, and assign a risk level.
- Document the result and a plan — who fixes what, by when.
- Keep it current when something changes (a new tool, a new office, an incident). The rule sets no fixed interval; we recommend reviewing it at least yearly.
What this means when choosing tools
Each new tool that touches PHI belongs in the inventory. The questions worth answering before you buy — does the vendor sign a BAA, is data encrypted, are there audit logs, can you enforce strong sign-in — are exactly the ones your risk analysis will ask afterwards.
Tools and services where this matters
- AI models and chat assistants →Tool
- HIPAA compliance software →Tool
- HIPAA hosting and cloud platforms →Tool
Guides
- HIPAA compliance →What HIPAA compliance actually means for a small practice or health tech company, what it consists of, and what it is not.
- HIPAA compliance certification for organizations →Can an organization or product be HIPAA certified? What the rule requires instead, what third-party assessments prove, and how to read a vendor's "HIPAA certified" badge.
- HIPAA compliance checklist →A practical HIPAA checklist for small practices and business associates, with each item linked to the rule behind it — not a list of things to buy.
- HIPAA penalties →Current HIPAA civil penalty amounts by tier after the 2025 inflation adjustment, annual caps, criminal penalties, and what determines the amount.
- HIPAA violation →What counts as a HIPAA violation, common examples in small practices and health tech companies, how violations differ from breaches, and what happens next.
Scenarios
Related requirements
- Encryption of ePHI →§ 164.312(a)(2)(iv)
- Access control and sign-in →§ 164.312(a)(1)
- Audit controls and activity logs →§ 164.312(b)
Frequently asked questions
Is a HIPAA risk assessment the same as a risk analysis?
In practice the terms are used interchangeably. The Security Rule's term is risk analysis: an accurate and thorough assessment of risks to ePHI, followed by risk management.
How often do I need a HIPAA risk assessment?
The rule does not set a fixed frequency. It must be kept current: review it regularly and update it whenever you add systems or vendors, move offices, or have an incident.
Is there an official HIPAA risk assessment template?
There is no mandated format. HHS and ONC offer a free Security Risk Assessment Tool designed for small and medium providers.