Home › Guides
HIPAA Security Risk Analysis: What HHS Actually Requires
The Security Rule requires a documented risk analysis, not a certificate. Here's what HHS's own guidance says it must cover, how often, when the free SRA Tool is enough, and what OCR looks for.
Updated
The short answer: the HIPAA Security Rule requires every covered entity and business associate to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the electronic protected health information (ePHI) it holds — the risk analysis at 45 CFR §164.308(a)(1)(ii)(A) — and then to reduce those risks, which is risk management at §164.308(a)(1)(ii)(B).
Two things it is not:
- Not a certificate. HHS does not certify HIPAA compliance, and there is no official government HIPAA certification. HHS warns it does not certify any persons or products as "HIPAA compliant". Anyone selling you a certificate is selling a marketing badge.
- Not optional because you're small. The Security Rule applies to covered entities and business associates regardless of size. The rule is flexible and scalable (§164.306(b)) — a three-person practice's analysis looks different from a hospital's — but it isn't waived.
What HHS says a risk analysis must include
HHS's Guidance on Risk Analysis doesn't prescribe one method, but it lays out the elements a compliant analysis covers:
| # | HHS element | In plain terms |
|---|---|---|
| 1 | Scope of the analysis | All ePHI you create, receive, maintain or transmit — every system, device, vendor and location, not just the EHR |
| 2 | Data collection | Where that ePHI actually lives and moves, documented |
| 3 | Threats and vulnerabilities | What could reasonably go wrong, and the weaknesses that would let it |
| 4 | Current security measures | The safeguards you really have in place today, and whether they're configured and used properly |
| 5 | Likelihood of threat occurrence | How likely each threat is to occur |
| 6 | Potential impact | What happens to patients and the organization if it does |
| 7 | Level of risk | Likelihood and impact combined, so you know what to fix first |
| 8 | Finalize documentation | Written, dated, and retained |
| 9 | Periodic review and updates | Kept current as your environment changes |
Two rules that trip people up:
- "Addressable" doesn't mean optional. For an addressable implementation specification you must implement it if it's reasonable and appropriate — or document why it isn't and implement an equivalent alternative where that is (§164.306(d)(3)). Skipping it silently isn't one of the choices.
- Keep it for six years. Security Rule documentation must be retained for six years from creation or from when it was last in effect, whichever is later (§164.316(b)(2)(i)).
How often?
The rule requires the analysis to be kept current: reviewed periodically and updated as needed in response to environmental or operational changes (§164.306(e), §164.308(a)(8), §164.316(b)(2)(iii)) — a new EHR, a move to the cloud, a new vendor, an office move, a security incident.
It does not set a fixed interval. In HHS's own words, the Security Rule "does not specify how frequently to perform risk analysis," and "some covered entities may perform these processes annually or as needed (e.g., bi-annual or every 3 years) depending on circumstances of their environment." HHS also says the process "should be ongoing." Annual review is a common and easily defended practice, not a current legal requirement.
A change is proposed, not final. HHS published a proposed rule on January 6, 2025 that would require a written risk analysis reviewed at least every 12 months, along with a written technology asset inventory and network map. As of this writing it has been neither finalized nor withdrawn, and HHS's regulatory agenda targets final action for July 2027. Until then, the current standard above applies.
The free HHS SRA Tool: when it's enough, and when it isn't
HHS and ONC publish a free Security Risk Assessment (SRA) Tool, aimed at small and medium-sized providers.
It's a good fit when: you're a small practice with a simple environment, someone internal can answer its questions accurately, and you use its output to drive real fixes.
It isn't enough on its own when:
- Nobody knows the true answers. The tool is a questionnaire. It documents what you tell it; it doesn't look at your systems.
- Your ePHI extends beyond the obvious. Cloud apps, patient-messaging tools, billing vendors, backups, staff phones and email all hold ePHI and all belong in scope.
- You're a business associate — a med-tech vendor, billing company or MSP. The tool is built around provider workflows.
- You need to defend it. A completed questionnaire with no risk-management follow-through is exactly the pattern OCR settlements describe.
What OCR looks for
When OCR opens an investigation, one of the first documents it typically asks for is the risk analysis, followed by policies and evidence that the identified risks were managed. Failure to conduct an accurate and thorough risk analysis is among the most frequently cited problems in OCR enforcement actions.
OCR made it an explicit priority with its Risk Analysis Initiative, announced in October 2024 with a $90,000 settlement with Bryan County Ambulance Authority after a ransomware attack, where OCR found no compliant risk analysis had been done. Settlements under the initiative continued through 2025, including $350,000 with Northeast Radiology, P.C. (April 2025) and $175,000 with BST & Co. CPAs, LLP (August 2025) — a business associate — both citing failure to conduct an accurate and thorough risk analysis.
Business associates are covered too
If you create, receive, maintain or transmit ePHI on behalf of a covered entity — billing, IT support, SaaS, transcription, cloud hosting — you are a business associate. You're directly liable for Security Rule compliance, including your own risk analysis, and you need a signed Business Associate Agreement before you touch the data.
What it costs
| Option | Cost | What you get |
|---|---|---|
| HHS SRA Tool | Free | A self-assessment questionnaire and report |
| HIPAA Readiness Scan | $0 | High-level safeguards gap summary and a next-step recommendation, in 24 hours |
| Risk Analysis & Gap Assessment | $299–$750 fixed fee | Full §164.308 gap review, BAA inventory check, prioritized safeguards register, 30-minute walkthrough |
| Full Risk Analysis & Remediation | $2,500–$10,000+ project | Documented risk analysis, safeguards remediation, BAA drafting, and a breach response plan built to survive an OCR review |
Frequently asked questions
Is there a HIPAA certification for my business?
No. HHS does not certify HIPAA compliance and doesn't endorse private certifications. What regulators look for is a documented risk analysis, risk management that follows from it, policies, and evidence your safeguards work.
How much does a HIPAA risk assessment cost for a small practice?
The HHS SRA Tool is free. A professionally documented analysis for a small practice typically starts in the hundreds of dollars for a gap assessment and runs into the low thousands for a full, remediated analysis — depending mostly on how many systems and vendors hold ePHI.
Is a HIPAA risk analysis the same as a risk assessment?
The rule's term is risk analysis; people use "risk assessment" interchangeably. What matters is that it covers the elements HHS lists and is documented.
Does a penetration test or vulnerability scan count as a risk analysis?
No. Technical testing is a useful input for finding vulnerabilities, but the risk analysis also has to cover likelihood, impact, all locations of ePHI, and non-technical safeguards.
We're a small practice, not a hospital. Does this really apply?
Yes. The Security Rule applies to covered entities and business associates of every size. Smaller organizations get a proportionate analysis, not an exemption.
This page is general compliance information, not legal advice.
Sources
- HHS — Guidance on Risk Analysis
- eCFR — 45 CFR Part 164, Subpart C (Security Rule)
- Federal Register — HIPAA Security Rule proposed rule (Jan 6, 2025)
- HHS — HIPAA resolution agreements
- HealthIT.gov — Security Risk Assessment Tool