Get HIPAA Audit →

How to Conduct a HIPAA Security Risk Assessment (SRA)

Quick Answer

A HIPAA Security Risk Assessment (SRA) is a comprehensive evaluation of your organization's systems, processes, and controls to identify threats and vulnerabilities to electronic protected health information (ePHI). The OCR requires covered entities to conduct an SRA initially and periodically thereafter to identify security gaps, evaluate the effectiveness of existing controls, and document a plan to address vulnerabilities. A thorough SRA examines asset inventory, threat sources, vulnerabilities, current safeguards, risk determination, and remediation planning.

What Is a HIPAA Security Risk Assessment?

The HIPAA Security Rule requires covered entities to conduct a comprehensive risk analysis as part of their security management process. This analysis must evaluate potential threats and vulnerabilities to the confidentiality, integrity, and availability of ePHI maintained by the organization.

A Security Risk Assessment is not a compliance checkbox—it's a foundational document that informs all of your security decisions. A quality SRA identifies which assets are critical, what threats target those assets, which vulnerabilities exist that threats could exploit, what safeguards you've implemented to mitigate risk, and what additional safeguards you need to reduce risk to acceptable levels.

The SRA serves several critical purposes:

OCR Requirements for Risk Assessments

The Office for Civil Rights expects SRAs to meet specific requirements. During audits, OCR evaluates whether organizations have conducted assessments that are:

The OCR recognizes that you may lack resources to address all identified risks immediately. What matters for compliance is that you identify risks, document your findings, and systematically work toward mitigation based on risk priority.

Step-by-Step Risk Assessment Process

Step 1: Define Assessment Scope

Determine which systems, locations, and workforce members your assessment will cover. Most organizations should assess:

Step 2: Create an Asset Inventory

Document all systems, equipment, and data repositories that create, receive, maintain, or transmit ePHI. For each asset, record:

This inventory becomes the foundation of your assessment. Comprehensive asset documentation is one of the most common weaknesses the OCR identifies—many organizations discover they don't actually know all the systems storing patient data.

Step 3: Identify Threat Sources

Determine what threats could compromise your ePHI. Threats generally fall into categories:

Don't limit yourself to theoretical threats—research actual threats in healthcare. Ransomware is rampant, phishing attacks target healthcare staff, and data theft by insiders remains common.

Step 4: Assess Vulnerabilities

For each asset and threat source, identify vulnerabilities that could be exploited. Examples include:

Vulnerability assessment should include both technical evaluation (system configuration review, penetration testing) and operational assessment (policy review, staff interviews).

Step 5: Evaluate Current Safeguards

Document what security measures you've already implemented for each identified vulnerability. For example:

Honest assessment of current state is critical. Many organizations overestimate their security posture—they assume things are secure without verifying. Conduct actual testing and verification rather than relying on assumptions.

Step 6: Determine Risk for Each Vulnerability

For each vulnerability, assess the risk by considering:

Use this risk rating to prioritize remediation—address high-risk vulnerabilities first.

Step 7: Develop Remediation Plan

For each identified vulnerability and risk, determine what safeguards you need to implement. Your remediation plan should include:

A realistic remediation plan considers your budget and resource constraints. You don't need to fix everything immediately, but you need a documented plan showing how you'll systematically address vulnerabilities.

Step 8: Document and Retain the Assessment

Maintain thorough documentation of your entire assessment including:

Retain documentation for at least 6 years. When OCR conducts audits, they'll want to see this documentation.

Ongoing Risk Assessment and Updates

Risk assessment is not a one-time project. HIPAA requires periodic updates to your assessment. Update your SRA when:

Common Risk Assessment Weaknesses

The OCR frequently identifies these weaknesses in assessments:

Frequently Asked Questions

How often must I conduct a risk assessment?
HIPAA requires conducting an initial risk assessment and periodically updating it. There's no specific required frequency, but best practice is annually at minimum. More frequent assessments (quarterly or semi-annually) are advisable for organizations with dynamic IT environments or recent security incidents.
Can I use an external consultant to conduct the SRA?
Yes. Many organizations use external security consultants or firms specializing in HIPAA assessments. However, your organization remains responsible for the assessment's accuracy and completeness. Even with external help, staff should be involved to ensure all systems and processes are included.
What if I identify vulnerabilities I cannot immediately fix due to budget constraints?
Document the vulnerability and your plan to address it. Include timelines and responsible parties. If remediation timeline is reasonable and you're making progress, OCR will view this favorably. What matters is demonstrating that you've identified risks and are systematically working to mitigate them, not that you have unlimited resources.
Should the risk assessment include business associates?
Yes. Your SRA should evaluate risks from business associate systems and processes. If vendors process ePHI, evaluate whether they have adequate safeguards. Include their systems in your threat and vulnerability assessment.
What framework or methodology should I use?
NIST has published risk assessment guidance (especially NIST Special Publications on security) that many healthcare organizations follow. Other recognized frameworks include the HITRUST CSF (Common Security Framework) or ISO 27001. Use any recognized methodology—what matters is that you're systematic and thorough.
Who should be involved in conducting the SRA?
Involve your Security Officer, IT leadership, system owners, clinical leadership, and workforce members who understand how ePHI is actually used. Multiple perspectives ensure comprehensive identification of vulnerabilities.
How detailed should my asset inventory be?
Detailed enough that someone unfamiliar with your systems could understand what you have, where it is, what data it stores, and who has access. Include system name, location, owner, function, ePHI sensitivity level, and current safeguards.
Should I conduct penetration testing as part of the SRA?
Penetration testing (ethical hacking) can be valuable to identify actual vulnerabilities that theoretical assessment might miss. It's not required by HIPAA but is increasingly recommended best practice, especially for organizations processing high volumes of sensitive data.

Conduct a Comprehensive Risk Assessment

A thorough security risk assessment is foundational to HIPAA compliance and provides the basis for all your security decisions. Medcurity helps healthcare organizations conduct detailed assessments identifying vulnerabilities, evaluating current safeguards, and developing prioritized remediation plans aligned with your budget and resources.

Start Your SRA →