How to Conduct a HIPAA Security Risk Assessment (SRA)
Quick Answer
A HIPAA Security Risk Assessment (SRA) is a comprehensive evaluation of your organization's systems, processes, and controls to identify threats and vulnerabilities to electronic protected health information (ePHI). The OCR requires covered entities to conduct an SRA initially and periodically thereafter to identify security gaps, evaluate the effectiveness of existing controls, and document a plan to address vulnerabilities. A thorough SRA examines asset inventory, threat sources, vulnerabilities, current safeguards, risk determination, and remediation planning.
What Is a HIPAA Security Risk Assessment?
The HIPAA Security Rule requires covered entities to conduct a comprehensive risk analysis as part of their security management process. This analysis must evaluate potential threats and vulnerabilities to the confidentiality, integrity, and availability of ePHI maintained by the organization.
A Security Risk Assessment is not a compliance checkbox—it's a foundational document that informs all of your security decisions. A quality SRA identifies which assets are critical, what threats target those assets, which vulnerabilities exist that threats could exploit, what safeguards you've implemented to mitigate risk, and what additional safeguards you need to reduce risk to acceptable levels.
The SRA serves several critical purposes:
- Demonstrates to OCR that you've identified and understood your security vulnerabilities
- Documents the basis for your security safeguard decisions
- Guides resource allocation toward the most critical security needs
- Provides evidence of due diligence that can mitigate penalties if breaches occur
- Creates a roadmap for systematic security improvements
OCR Requirements for Risk Assessments
The Office for Civil Rights expects SRAs to meet specific requirements. During audits, OCR evaluates whether organizations have conducted assessments that are:
- Comprehensive: Covering all systems, locations, and processes that handle ePHI, not just critical ones.
- Documented: Thoroughly documented with findings, methodology, and conclusions clearly recorded and retained for audit purposes.
- Current: Updated periodically (at minimum annually) and whenever significant system changes occur.
- Based on sound methodology: Using recognized risk assessment frameworks and methodologies, such as NIST guidelines or industry standards.
- Addressing all required elements: Covering asset inventory, threat identification, vulnerability assessment, current controls evaluation, risk determination, and remediation planning.
- Actionable: Resulting in clear remediation plans with timelines and responsible parties.
The OCR recognizes that you may lack resources to address all identified risks immediately. What matters for compliance is that you identify risks, document your findings, and systematically work toward mitigation based on risk priority.
Step-by-Step Risk Assessment Process
Determine which systems, locations, and workforce members your assessment will cover. Most organizations should assess:
- All electronic systems storing or processing ePHI (EHR, billing systems, databases)
- Network infrastructure (servers, routers, firewalls)
- Workstations and mobile devices accessing ePHI
- Backup and disaster recovery systems
- All physical locations where ePHI is processed or stored
- Cloud-based systems and business associate systems accessing ePHI
- Telehealth and remote access systems
Document all systems, equipment, and data repositories that create, receive, maintain, or transmit ePHI. For each asset, record:
- Asset name and description
- Location (physical address or logical location for systems)
- Owner/manager responsible for the asset
- Type and sensitivity of ePHI stored or processed
- Users/workforce with access
- Current safeguards protecting the asset
- Criticality to business operations
This inventory becomes the foundation of your assessment. Comprehensive asset documentation is one of the most common weaknesses the OCR identifies—many organizations discover they don't actually know all the systems storing patient data.
Determine what threats could compromise your ePHI. Threats generally fall into categories:
- External threats: Hackers, ransomware operators, competitors, identity thieves
- Internal threats: Rogue employees, negligent staff, terminated employees with lingering access
- Environmental threats: Natural disasters, power outages, hardware failures
- Business threats: Business associate breaches, third-party vendor vulnerabilities
- Physical threats: Theft of devices, unauthorized physical access, environmental damage
Don't limit yourself to theoretical threats—research actual threats in healthcare. Ransomware is rampant, phishing attacks target healthcare staff, and data theft by insiders remains common.
For each asset and threat source, identify vulnerabilities that could be exploited. Examples include:
- Unencrypted ePHI in transit or at rest
- Weak or default passwords
- No multi-factor authentication
- Outdated software lacking security patches
- Inadequate access controls allowing unnecessary access
- No audit logging of ePHI access
- Unsecured remote access capabilities
- Lack of visitor controls at physical locations
- Unencrypted portable devices (laptops, USB drives)
- No Business Associate Agreements or inadequate BAAs
Vulnerability assessment should include both technical evaluation (system configuration review, penetration testing) and operational assessment (policy review, staff interviews).
Document what security measures you've already implemented for each identified vulnerability. For example:
- What encryption is in place and what's its strength?
- How do you currently control access to ePHI?
- What audit logging and monitoring do you have?
- What staff training on information security occurs?
- How do you enforce access termination when employees leave?
- What physical security measures protect your facilities?
- How do you handle device disposal?
Honest assessment of current state is critical. Many organizations overestimate their security posture—they assume things are secure without verifying. Conduct actual testing and verification rather than relying on assumptions.
For each vulnerability, assess the risk by considering:
- Likelihood of exploitation: How likely is it that a threat actor would discover and exploit this vulnerability? Unencrypted ePHI is high likelihood if exposed. A security feature that requires access to locked equipment might be low likelihood.
- Potential impact if exploited: How many patients would be affected? What type of data would be exposed? Vulnerabilities allowing access to all patient records have higher impact than those exposing limited data.
- Overall risk rating: Combine likelihood and impact to determine whether risk is low, medium, or high.
Use this risk rating to prioritize remediation—address high-risk vulnerabilities first.
For each identified vulnerability and risk, determine what safeguards you need to implement. Your remediation plan should include:
- Specific safeguard or control to be implemented
- Whether implementation is required (mandatory HIPAA standard) or addressable (your organization determined it's appropriate)
- Priority level (high-risk vulnerabilities addressed first)
- Responsible party or department
- Timeline for implementation
- Estimated cost
- Success criteria (how you'll verify the safeguard works)
A realistic remediation plan considers your budget and resource constraints. You don't need to fix everything immediately, but you need a documented plan showing how you'll systematically address vulnerabilities.
Maintain thorough documentation of your entire assessment including:
- Assessment methodology and framework used
- Assessment scope and dates
- Complete asset inventory
- Identified threats and vulnerabilities
- Risk ratings and justifications
- Current safeguards evaluation
- Remediation plan with timelines
- Evidence of implementation and completion of planned safeguards
- Updates to the assessment reflecting completed improvements
Retain documentation for at least 6 years. When OCR conducts audits, they'll want to see this documentation.
Ongoing Risk Assessment and Updates
Risk assessment is not a one-time project. HIPAA requires periodic updates to your assessment. Update your SRA when:
- At least annually (best practice quarterly or semi-annually)
- Implementing new systems or major technology changes
- Deploying new software or operating system versions
- Changing workflows or business processes affecting ePHI access
- Expanding facilities or adding new locations
- Adding new business associates or changing existing relationships
- Experiencing security incidents or near-misses
- Learning of new threat trends relevant to healthcare
Common Risk Assessment Weaknesses
The OCR frequently identifies these weaknesses in assessments:
- Incomplete asset inventory: Failing to identify all systems storing ePHI, especially older legacy systems or systems added recently.
- Vague vulnerability descriptions: Identifying vulnerabilities at high level without specific details about which systems are vulnerable and why.
- No risk rating or prioritization: Identifying vulnerabilities but not assessing their actual risk, leading to unfocused remediation efforts.
- Outdated assessments: Failing to update assessments as systems change, rendering the assessment irrelevant to current infrastructure.
- No implementation evidence: Creating a remediation plan but failing to implement or verify completion of planned safeguards.
- Inadequate supporting documentation: Relying on assessment summary without detailed supporting data that shows how conclusions were reached.
- Insufficient detail on current safeguards: Failing to honestly assess the effectiveness of current safeguards, overestimating their adequacy.
Frequently Asked Questions
Conduct a Comprehensive Risk Assessment
A thorough security risk assessment is foundational to HIPAA compliance and provides the basis for all your security decisions. Medcurity helps healthcare organizations conduct detailed assessments identifying vulnerabilities, evaluating current safeguards, and developing prioritized remediation plans aligned with your budget and resources.
Start Your SRA →