How to Do a HIPAA Security Risk Assessment (Step-by-Step)

A practical, step-by-step guide to conducting a HIPAA security risk assessment that satisfies OCR, protects ePHI, and holds up in an audit.
August 06, 2026
PolySec
Share article
Date
August 06, 2026
Category
HIPAA Information
Reading time
9 Minutes

How to Do a HIPAA Security Risk Assessment (Step-by-Step)

A HIPAA security risk assessment is a written, dated evaluation of every threat and vulnerability to the electronic protected health information (ePHI) your practice creates, receives, maintains, or transmits. Do it well and you get a prioritized list of what to fix and proof that you took security seriously. Skip it or do it superficially, and you hand federal regulators an easy finding if you're ever breached or audited.

This guide walks through the assessment the way the HHS Office for Civil Rights (OCR) actually expects it to be done, the same elements that show up in enforcement actions when they're missing. It's written for practice owners, office managers, and compliance leads who need to get this right without a security background.

Why this matters more than it used to

The risk analysis has been a legal requirement since the HIPAA Security Rule took effect, but the stakes climbed sharply over the past two years. In the fall of 2024, OCR announced the first enforcement action in its "Risk Analysis Initiative," and a total of seven enforcement actions were announced within the first six months. Those weren't paperwork nitpicks. A ransomware attack affecting 14,273 patients led to a $90,000 settlement when the entity had not conducted a risk analysis.

The pattern accelerated through 2025. By the third quarter of 2025, 17 of 19 enforcement actions (89%) in the nine months ending September 30, 2025, were related to ransomware or other cyber incidents. Larger penalties followed bigger breaches: PIH Health settled for $600,000 with a two-year corrective plan after a phishing attack compromised nearly 190,000 records.

Two things drive this. First, healthcare is a top target for attackers because patient records are valuable and often poorly protected. Second, when OCR investigates a breach, the first thing it asks for is your risk analysis, and a conversation about security isn't evidence. You need written records showing what systems you looked at, what data you found, what threats you considered, and what you decided to do about them.

What a HIPAA risk assessment is (and isn't)

A risk assessment is not a firewall, an antivirus subscription, or a checklist your IT vendor signed once. It's an analytical process. A HIPAA risk assessment is the systematic process of identifying where ePHI exists, evaluating threats and vulnerabilities that could compromise that information, determining the likelihood and impact of potential security incidents, and documenting the results.

It also isn't the same as a security evaluation or a gap analysis, even though vendors often blur the terms. A gap analysis compares your controls against a checklist of requirements. A true risk analysis goes further: it looks at your specific environment and asks how ePHI could actually be exposed, how likely each scenario is, and how bad it would be.

OCR has published guidance describing the elements every risk analysis must contain regardless of the method or tool you use. The steps below map to that guidance.

Step 1: Define the scope

Scope is where most weak assessments fall apart. The rule is broad on purpose. The scope of risk analysis includes the potential risks and vulnerabilities to the confidentiality, availability and integrity of all e-PHI that an organization creates, receives, maintains, or transmits.

That means all electronic media, in every location. The scope must include all ePHI in all forms of electronic media. Examples include portable devices such as thumb drives, laptops, and mobile phones as well as individual desktops, email accounts, fax machines, and printers.

Write down the boundaries before you start: which locations, which systems, which vendors, and which workflows are in play. A practice that "forgets" its backup drive, a legacy billing system, or a physician's personal phone used for scheduling has already created the gap an auditor will find.

Step 2: Build an ePHI inventory and map the data flows

You can't protect what you haven't located. Document every place ePHI lives and every path it travels: your EHR, practice management software, email, cloud backups, imaging systems, patient portals, and every vendor that touches patient data.

For each asset, record where the data comes from, where it's stored, who has access, and where it goes. The scope and asset inventory should cover every system, device, application, and vendor that creates, receives, maintains, or transmits ePHI, plus a map of how ePHI flows between them. This map becomes the backbone of everything that follows, because you'll evaluate threats asset by asset.

While you're at it, pull your business associate agreements (BAAs). Every vendor with access to ePHI needs a signed BAA, and a missing or outdated one is its own compliance problem.

Step 3: Identify threats and vulnerabilities

With your inventory in hand, list what could go wrong for each asset. A threat is a potential source of harm; a vulnerability is a weakness that a threat could exploit. Once scope is defined, you must identify potential threats (sources of harm) and vulnerabilities (weaknesses that could be exploited) relevant to your environment.

Be specific and be complete. OCR guidance notes that risk analysis should consider all reasonably anticipated threats. Threats fall into a few buckets:

  • Human and malicious: phishing, ransomware, stolen credentials, a departing employee copying records.
  • Technical: unpatched software, weak or shared passwords, unencrypted laptops, misconfigured cloud storage.
  • Environmental and physical: fire, flood, power loss, an unlocked server closet, a laptop left in a car.

Generic categories aren't enough. Tie named threats to specific assets. "Ransomware encrypting the on-premise EHR server that lacks offline backups" is a finding an auditor can respect. "Cybersecurity risks" is not.

Step 4: Assess your current safeguards

For each threat and vulnerability, document the controls you already have in place and whether they actually work. HIPAA groups safeguards into three families: administrative (policies, training, access management), physical (locks, facility access, device controls), and technical (encryption, audit logs, authentication).

The key word is evidence. The current safeguard evaluation covers the administrative, physical, and technical controls already in place, with evidence. Saying you have "security awareness training" means little without records of who was trained and when. Encryption on paper means nothing if half the laptops aren't actually encrypted.

Step 5: Determine likelihood and impact

This is the analytical heart of the assessment and what separates a real risk analysis from a checklist. For every threat-vulnerability pair, you estimate two things: how likely it is to happen and how much damage it would cause.

The level of risk is determined by analyzing the values assigned to the likelihood of threat occurrence and the resulting impact of threat occurrence. Risk is a function of the likelihood of a given threat exploiting a specific vulnerability and the resulting impact.

A simple, defensible approach is a rating scale, low/medium/high for both likelihood and impact, combined into an overall risk level. An unencrypted laptop holding thousands of records is high impact; if it leaves the building daily, it's also high likelihood, which puts it near the top of your list. Document your scoring method so a reviewer can follow your logic.

Step 6: Assign risk levels and prioritize

Combine likelihood and impact into a risk rating for each item, then rank them. This should produce a documented scoring method that yields a prioritized risk level for each risk. The output is a risk register: a ranked list that tells you, and any auditor, exactly where your worst exposures are and which to tackle first.

Prioritization matters because no practice can fix everything at once. Regulators don't expect perfection; they expect you to identify your highest risks and address them in a reasonable order.

Step 7: Document everything

If it isn't written down, it didn't happen, as far as OCR is concerned. Your assessment needs to capture what you reviewed, what patient data you found, what threats you considered, what controls existed, how you rated each risk, and what you decided to prioritize. Weak documentation is often the deciding factor in enforcement: it's nearly impossible to convince regulators you cared about security if you can't show what you actually examined and what you did about it.

Date it, and have it signed by whoever is accountable. A written, dated, signed assessment scoped to your specific environment, with documented likelihood and impact for each risk and a linked remediation plan, is exactly what a regulator wants to see.

Step 8: Build a risk management plan and remediate

The assessment identifies risks. The risk management plan is where you actually reduce them, and OCR now scrutinizes both. OCR has made the risk analysis provision an enforcement priority, and that initiative is being extended to include risk management; if a breach is reported, OCR will require evidence that risks have been managed in a timely manner.

For each significant risk, decide on an action, assign an owner, and set a deadline. Encrypt the laptops. Turn on multifactor authentication. Move backups offline. Update the BAAs. Then track it to completion and keep the records, because "we identified the risk" without "we fixed it" is precisely the gap that turns a breach into a penalty.

How often should you do this?

There's a persistent myth that a risk assessment is a once-a-year checkbox. The truth is more demanding. The HIPAA Security Rule requires an ongoing risk analysis process rather than a fixed calendar interval. You need a cadence that reflects your systems, threats, and regulatory requirements.

In practice, that means a comprehensive assessment at least annually, plus an update whenever something meaningful changes: While HIPAA does not specify an exact frequency, OCR guidance and industry best practice recommend conducting a risk assessment at least annually, and assessments should be updated whenever significant changes occur. New EHR, new office, a new vendor, a merger, or a security incident all trigger a fresh look. Treat it as a living process, not an annual event you can forget about for twelve months.

Common mistakes that lead to fines

  • Scoping too narrowly. Leaving out email, mobile devices, backups, or a vendor system. If ePHI touches it, it's in scope.
  • Confusing a gap analysis for a risk analysis. A checklist against requirements isn't the same as analyzing likelihood and impact in your actual environment.
  • Generic threats. Listing "cyber threats" instead of naming specific threats tied to specific assets.
  • No documentation. Verbal assurances and undated notes don't survive an OCR investigation.
  • Identifying risks but never fixing them. OCR's recent actions repeatedly cite entities that had findings but no evidence of timely remediation.
  • Set-and-forget. Doing one assessment years ago and never updating it after new systems or incidents.

When to bring in outside help

A small practice with a simple setup can complete a credible assessment internally using free resources like the ONC/OCR Security Risk Assessment (SRA) Tool. But the process demands real security knowledge to do well, especially identifying technical vulnerabilities, running vulnerability and network scans, and judging likelihood accurately. Many practices don't have that expertise in-house, and a superficial self-assessment can create false confidence that's worse than knowing where you stand.

This is where an in-person assessment pays off. PolySec (polysec.tech) performs on-site HIPAA security risk assessments built for healthcare practices: vulnerability and network scanning, policy and BAA review, an audit-ready findings report, a prioritized remediation roadmap, and ongoing support to actually close the gaps. The idea is simple, your team focuses on patients while the security and compliance work is handled by people who do it every day. Given that healthcare breaches now average around $7 million and that more than 350 million individuals were affected by healthcare data breaches across 2024 and 2025, a thorough, personalized assessment is cheap insurance.

Frequently asked questions

Is a HIPAA risk assessment legally required? Yes. It's a required implementation specification under the Security Rule's administrative safeguards. Every covered entity and business associate that handles ePHI must conduct one, and OCR asks for it first when investigating a breach.

Is a risk assessment the same as becoming HIPAA compliant? No. The assessment is a foundational step, but compliance also requires implementing safeguards, training staff, signing BAAs, maintaining policies, and remediating the risks you find.

Can I use a free tool to do it myself? For a simple practice, yes, the government's SRA Tool is a reasonable starting point. Just be honest about whether you have the technical skill to identify vulnerabilities and rate risk accurately. A checked box isn't the same as a thorough analysis.

How long does an assessment take? For a small practice, a focused assessment can be completed in a few weeks depending on how complex your systems and vendor relationships are. Larger or multi-location organizations take longer.

What happens if I don't have one and get breached? OCR will ask for your risk analysis during the investigation. Not having one, or having an inadequate one, has directly driven settlements ranging from tens of thousands to hundreds of thousands of dollars, plus multi-year corrective action plans.

The bottom line

A HIPAA security risk assessment isn't paperwork for its own sake. It's the map that tells you where patient data is exposed and what to fix first, and it's the single most important document OCR will ask for if things go wrong. Scope it broadly, inventory every place ePHI lives, analyze real threats against real assets, rate the risk, write it all down, and then actually remediate. Do that on a regular cadence and you protect your patients, your practice, and your license to operate.

If you'd rather not shoulder the technical work alone, an on-site assessment from a healthcare-focused partner like polysec.tech can take you from "we should probably do this" to an audit-ready report and a clear plan.