Start Free Assessment

Annual HIPAA Risk Assessment: When & How to Conduct

HIPAA requires a current, documented, and thorough Security Risk Analysis, updated after any significant change to your environment. It does not set an annual deadline (45 CFR 164.308(a)(1)(ii)(A)). Reviewing annually is a common best practice, and MIPS attestation runs on the calendar year.

This guide walks you through when to conduct your assessment, what must be included, how to gather data, analyze risks, and implement remediation. Learn the HIPAA requirements and best practices for maintaining a defensible compliance program.

HIPAA Risk Assessment Requirement

HIPAA's Security Rule (45 CFR § 164.308(a)(1)) requires covered entities to conduct a security risk assessment that documents the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. This assessment must be:

  • Documented in writing
  • Comprehensive and thorough
  • Updated as needed and redone periodically
  • Used to guide risk mitigation efforts

Organizations must maintain detailed documentation of the risk assessment process, findings, and any actions taken to address identified risks.

When to Conduct Annual Risk Assessments

Q1
Jan-Mar

Optimal Timing: January-February

Begin your comprehensive annual risk assessment in January or early February. This timing allows you to identify risks early in the year, develop mitigation plans, and complete remediation before year-end audits.

4-12
Weeks

Assessment Duration

Typical assessments require 4-12 weeks depending on organization size, system complexity, and number of locations. Smaller organizations may complete in 4-6 weeks, while larger healthcare systems may need 12+ weeks.

Plus
Ongoing

Continuous Review

Beyond the annual comprehensive assessment, conduct informal reviews quarterly and update the formal risk register whenever significant changes occur (new systems, breaches, regulatory changes).

Key Areas for Annual Risk Assessment

1Systems & Technology

Electronic health record systems, practice management software, databases, servers, workstations, mobile devices, and cloud services storing or processing PHI.

2Physical Security

Facility access controls, server room security, device storage, visitor management, and physical safeguards for areas containing PHI.

3Access Controls

User authentication, password policies, role-based access control, principle of least privilege, and monitoring of user access to systems.

4Data Protection

Encryption in transit and at rest, data classification, handling procedures, disposal methods, and backup security.

5Vendor Management

Business associate agreements, third-party security assessments, vendor audit rights, and ongoing vendor risk monitoring.

6Workforce Security

Training programs, background checks, performance monitoring, termination procedures, and documented authorization records.

7Incident Response

Breach notification procedures, documentation processes, containment capabilities, and recovery procedures.

8Audit Logging

System audit logs, access logs, change logs, integrity checking mechanisms, and log retention policies.

9Business Continuity

Disaster recovery plans, business continuity procedures, backup systems, alternate processing sites, and testing frequency.

Step-by-Step Risk Assessment Process

Step 1: Planning & Scope Definition

Define the scope of your assessment and gather the assessment team. Include leadership, IT personnel, security staff, clinical staff, and potentially external consultants. Document the assessment methodology and timeline.

Identify all systems and data flows handling PHI
Assemble assessment team with diverse expertise
Define assessment methodology and criteria
Create project timeline and milestones

Step 2: Data Gathering & Inventory

Create a comprehensive inventory of all systems, databases, applications, and physical locations handling PHI. Document configurations, ownership, and data flows.

Conduct system inventory of all IT assets
Document data flow diagrams for PHI
Map all locations where PHI is stored or processed
Review existing security policies and procedures

Step 3: Threat & Vulnerability Identification

Identify potential threats to ePHI including external attacks, internal threats, natural disasters, and human error. Match threats against identified vulnerabilities in systems and processes.

Document potential threats (cyber attacks, theft, disasters)
Conduct vulnerability scanning of systems
Interview staff about current practices and gaps
Identify outdated or unsupported systems

Step 4: Risk Analysis & Prioritization

Analyze the likelihood and potential impact of identified risks. Prioritize risks based on severity to focus mitigation efforts on highest-impact areas first.

Score each risk for likelihood and impact
Determine overall risk score or rating
Prioritize risks by severity and impact
Identify critical, high, medium, and low risks

Step 5: Mitigation Planning

Develop risk mitigation strategies for identified risks. For each significant risk, document the planned remediation, responsible party, timeline, and estimated cost.

Develop remediation plan for each major risk
Assign ownership and accountability
Set realistic timelines for remediation
Estimate costs and resource requirements

Step 6: Documentation & Reporting

Prepare comprehensive risk assessment report documenting methodology, findings, prioritized risks, and mitigation plans. Present to leadership and obtain sign-off.

Create comprehensive assessment report
Include executive summary and detailed findings
Present recommendations to leadership
Obtain executive approval and resource allocation

Step 7: Implementation & Monitoring

Execute risk mitigation plans, track progress, and monitor effectiveness. Update risk register regularly and verify that remediation efforts achieve desired outcomes.

Track implementation progress of mitigation plans
Verify effectiveness of implemented controls
Update risk register with resolved items
Schedule follow-up verification assessments

Risk Assessment Documentation Requirements

HIPAA requires documented evidence of your risk assessment. Your documentation should include:

  • Assessment Methodology: How you identified risks, vulnerabilities, and threats
  • System Inventory: Complete list of all systems processing PHI with descriptions
  • Data Flow Diagrams: Visual representation of how PHI moves through your systems
  • Risk Register: Detailed listing of identified risks with threat descriptions and vulnerabilities
  • Risk Scoring: Methodology for rating likelihood and impact of each risk
  • Prioritized Risk List: Risks ranked by severity from critical to low
  • Mitigation Plan: Detailed remediation steps with owners and timelines
  • Executive Summary: High-level overview of findings for leadership
  • Assessment Date & Signatures: Documentation of when assessment was completed and who conducted it

Common Risk Assessment Mistakes to Avoid

1. Superficial Assessment

Avoid high-level assessments that don't adequately examine systems and processes. Ensure assessment goes deep into each area and identifies actual vulnerabilities.

2. Outdated Methodologies

Use current risk assessment frameworks aligned with latest HIPAA guidance and security standards (NIST, HHS Office for Civil Rights guidance).

3. Lack of Documentation

Document every step of your assessment process. OCR audits look for evidence of a thorough, documented risk assessment process.

4. No Implementation Follow-Through

Identify risks but fail to remediate them. Document mitigation efforts and track completion or explain why risks are accepted.

5. Irregular Assessment Schedule

Some organizations only assess when an incident occurs or during audit preparation. Conduct regular annual assessments to maintain current risk awareness.

6. Insufficient Team Involvement

Include diverse perspectives including IT security, clinical staff, physical security, and operations. Different groups identify different vulnerabilities.

When to Conduct Additional Risk Assessments

Beyond your annual comprehensive assessment, conduct updates or targeted assessments when:

  • Implementing new systems or significant system changes
  • After a security breach or incident
  • When expanding to new locations or entering new markets
  • Major organizational restructuring or mergers/acquisitions
  • Significant technology changes (cloud migration, major upgrades)
  • Regulatory changes affecting your compliance requirements
  • Following failed audit findings or compliance gaps
  • After major infrastructure or security control updates

Frequently Asked Questions

When should you conduct your annual HIPAA risk assessment?
HIPAA requires a current, documented, and thorough Security Risk Analysis, updated after any significant change to your environment; it does not set an annual deadline (45 CFR 164.308(a)(1)(ii)(A)). Best practice is to conduct in January-February to identify risks early in the year and allow time for remediation before year-end audit. However, the timing can be adjusted to fit your organization's fiscal year or operational schedule.
What must be included in a HIPAA risk assessment?
Risk assessments must cover all aspects of your information security program: systems and data flows, physical security, access controls, encryption, disaster recovery, vendor security, workforce training, and incident response procedures. The assessment must be comprehensive and documented in writing.
Can we conduct our risk assessment internally or should we hire an external consultant?
Either approach is acceptable. Internal assessments are less expensive and use staff knowledge, but may lack objectivity. External consultants provide independent assessment and HIPAA expertise. Many organizations combine approaches with external consultants conducting the assessment and internal staff providing information.
What should we do if we identify risks we can't immediately fix?
Document the risk, your mitigation plan, and timeline for remediation. If remediation will take time, implement interim controls to reduce risk. Document your risk acceptance decision and management approval. Never simply ignore identified risks.

Schedule Your Annual Risk Assessment

Get expert guidance on conducting a comprehensive HIPAA risk assessment for your organization.

Start Your Risk Assessment