The HIPAA Security Risk Assessment Checklist Every Practice Should Follow

A practical HIPAA security risk assessment checklist for medical practices: the required elements, what OCR expects, and how to stay audit-ready.
August 08, 2026
PolySec
Share article
Date
August 08, 2026
Category
HIPAA Information
Reading time
8 Minutes

If your practice handles electronic protected health information, a documented security risk assessment isn't optional paperwork. It's the single requirement OCR investigators ask for first after a breach, and the one small practices most often get wrong. Conducting a risk analysis is the first step in identifying and implementing safeguards that comply with the standards and implementation specifications in the Security Rule. A risk analysis is foundational, and must be understood in detail.

This checklist walks through exactly what a compliant HIPAA security risk assessment includes, the elements HHS expects to see, and the gaps that get practices penalized. Whether you run a two-provider dental office or a multi-site specialty group, the core requirements are the same.

What a HIPAA security risk assessment actually is

A security risk assessment (sometimes called a risk analysis) is a written evaluation of every place your practice creates, receives, stores, or transmits electronic PHI, and the threats and vulnerabilities that could compromise that data. It's required under the HIPAA Security Rule at § 164.308(a)(1)(ii)(A).

Two things trip people up. First, a risk assessment is not the same as buying antivirus software or signing a checklist your IT vendor emailed you. It's an analysis of risk, meaning you have to identify what could go wrong, how likely it is, and how bad the impact would be. Second, it's not a one-time project. HIPAA does not mandate a fixed interval, but regulators expect a documented, enterprise-wide security risk analysis performed periodically and updated after changes. Most organizations conduct a full assessment annually, supplemented by more frequent, risk-based reviews.

The Security Rule organizes protections into three categories, and your assessment needs to touch all of them. The Security Rule requires regulated entities to implement reasonable and appropriate administrative, physical, and technical safeguards for protecting ePHI.

The core checklist: what your assessment must cover

HHS doesn't dictate a specific format, but it does expect certain elements in every risk analysis. Use these as your master checklist.

1. Define the scope. List every system, device, and location where ePHI lives: your EHR, billing software, patient portal, email, imaging systems, laptops, phones, backup drives, and any cloud service. If it touches patient data, it's in scope. Missing systems is the most common way an assessment fails an audit.

2. Collect and document your data flows. Map how ePHI enters, moves through, and leaves your practice. Where is it stored? Who has access? What third parties (labs, billing companies, cloud vendors) receive it? Write this down. HHS requires the analysis in writing.

3. Identify threats and vulnerabilities. Catalog the realistic threats to each system: ransomware, phishing, lost or stolen devices, insider misuse, unpatched software, weak passwords, and physical break-ins. A vulnerability is any weakness a threat could exploit, like an unencrypted laptop or a shared login.

4. Assess your current security measures. Document the controls you already have in place, encryption, access controls, firewalls, audit logging, and evaluate whether they're actually configured and working, not just installed.

5. Determine the likelihood of each threat. Take account of the probability of potential risks to ePHI; in combination with the potential threats and vulnerabilities, this assessment allows for estimates on the likelihood of ePHI breaches.

6. Determine the potential impact. Using either qualitative or quantitative methods, assess the maximum impact of a data threat to your organization. How many people could be affected? What extent of private data could be exposed, just medical records, or both health information and billing information combined?

7. Assign a risk level. HHS suggests taking the average of the assigned likelihood and impact levels to determine the level of risk. A common approach is to score likelihood and impact each on a 1-to-5 scale and multiply them, then sort results into low, medium, high, or critical. One of the simplest ways to determine risk levels is to assign the likelihood of a risk occurring a number between 1 and 5 and the impact the event would have a number between 1 and 5, then multiply the two numbers together.

8. Finalize documentation with corrective actions. Documented risk levels should be accompanied by a list of corrective actions that would be performed to mitigate risk. HHS doesn't specify any format, but they do require the analysis in writing. This written record is your remediation roadmap and your proof of compliance.

9. Review and update periodically. Repeat the assessment on a schedule and after any significant change. Run additional, focused assessments when conditions shift, such as new or substantially changed systems like EHR modules, imaging, patient portals, or telehealth. Event-driven reviews keep your posture aligned with reality and your risk register current.

Safeguard-by-safeguard checklist

Within your assessment, evaluate specific controls across the three safeguard categories.

Administrative safeguards - A named security officer responsible for policies and procedures - Workforce security and access management (who can see what, and why) - Regular security awareness training, including phishing recognition - A written incident response and breach notification plan - Signed Business Associate Agreements with every vendor that touches ePHI - Sanction policies for staff who violate procedures

Physical safeguards - Facility access controls (locked server rooms, restricted areas) - Workstation security and positioning so screens aren't visible to patients - Device and media controls covering disposal, reuse, and off-site movement - An inventory of hardware that stores ePHI

Technical safeguards - Unique user IDs and strong authentication (ideally multi-factor) - Encryption of ePHI at rest and in transit - Automatic logoff on unattended workstations - Audit controls and log review to detect unusual access - Data backup and a tested disaster recovery plan

The gaps that get practices penalized

The failures OCR flags most often aren't exotic. They're basic and repeated. The biggest is having no risk analysis at all, or one that only covers part of the practice's systems. A close second is treating the assessment as a document you file and forget rather than a process you act on.

Two related mistakes cost real money: skipping Business Associate Agreements with vendors, and running an assessment but never remediating the risks it uncovered. An assessment that identifies a critical vulnerability and then sits in a drawer can actually make things worse, because it proves you knew and did nothing.

The financial stakes are concrete. HIPAA penalties come from four tiers: lack of knowledge, reasonable cause, willful neglect corrected within 30 days, and willful neglect not corrected. For 2025, penalties range from a minimum of $145 per violation at the lowest tier up to $2,190,294 per violation for willful neglect that is not corrected. The published annual penalty cap per identical provision is $2,190,294. The encouraging part: real-world settlements often fall below those caps when organizations cooperate, self-report, and remediate quickly.

Where to get help

HHS and ONC publish a free assessment aid worth knowing about. The Office of the National Coordinator for Health Information Technology, in collaboration with OCR, developed the HIPAA Security Risk Assessment Tool. The tool is useful in assisting small and medium-sized health care practices and business associates in complying with the HIPAA Security Rule.

The free tool is a solid starting point, but it assumes you can accurately identify your own vulnerabilities, and that's exactly where clinical teams without security expertise tend to struggle. You can't score the likelihood of a threat you didn't know existed, and self-assessments routinely miss misconfigured firewalls, unpatched systems, and network weaknesses that only surface with actual scanning.

This is where an outside assessment earns its keep. PolySec performs in-person HIPAA security risk assessments built specifically for healthcare practices, on-site vulnerability and network scanning, policy and BAA review, and an audit-ready findings report with a prioritized remediation roadmap. The point is to let clinical staff focus on patients while the technical and compliance work is handled by people who do it full time, including support through remediation rather than just handing you a report.

HIPAA security risk assessment FAQ

How often do I need to do a HIPAA risk assessment? There's no legally fixed interval, but the practical standard is at least once a year plus a fresh review whenever something significant changes, like a new EHR, a telehealth rollout, or a merger. Regulators expect a documented analysis performed periodically and updated after changes, and most organizations conduct a full assessment annually.

Does my IT company's security setup count as a risk assessment? No. Installing security tools is remediation, not analysis. A compliant assessment identifies and documents risks, rates them, and maps corrective actions. HHS specifically requires the analysis to be in writing.

What's the difference between a risk assessment and a risk analysis? In practice the terms are used interchangeably for the Security Rule requirement. Note that a broader HIPAA compliance review can be even wider. A risk assessment for all elements of HIPAA compliance should include the Privacy, Security, and Breach Notification Rules.

What happens if I've never done one? Operating without a documented risk analysis is one of the most commonly cited HIPAA failures, and after a breach it's the first thing OCR requests. Given that fines start at $145 and reach into the millions for uncorrected willful neglect, the cost of doing an assessment is trivial next to the cost of not having one.

Do small practices really get audited? Enforcement isn't limited to hospitals. Small practices face the same rules and are frequent targets for ransomware and phishing precisely because they tend to have weaker defenses. The size of your practice doesn't reduce your obligation.

The bottom line

A HIPAA security risk assessment comes down to a simple loop: find where your ePHI lives, figure out what could go wrong, rate how serious each risk is, fix the worst ones first, write it all down, and revisit it regularly. Do that consistently and you're not just checking a compliance box, you're genuinely reducing the odds of a breach that could damage patient trust and your practice's finances.

If you haven't run an assessment in the past year, or you're not confident the last one covered every system, that's the place to start. Book one, act on the findings, and keep the documentation current.