Quick Answer: To be ready for a HIPAA Security Risk Analysis, you need: a complete ePHI system inventory, documented security policies, a list of workforce members with ePHI access, current network diagrams, executed BAAs with all vendors, and an IT contact who can answer technical questions. Most small practices can complete an SRA in 2-3 weeks with proper preparation.