HIPAA Security Risk Assessment
If you run a medical practice, an EMS agency, a healthcare clinic, or any organization that handles patient health information, you have probably heard the phrase HIPAA security risk assessment. You may have wondered exactly what it means, whether you actually need one, and what happens if you don’t have it.
This article answers those questions directly. No filler. No scare tactics. Just what a HIPAA security risk assessment actually is, what it covers, who it applies to, and what to do about it.
What Is a HIPAA Security Risk Assessment?
A HIPAA security risk assessment is a formal evaluation of how an organization creates, stores, accesses, transmits, and protects electronic protected health information, commonly called ePHI. The assessment identifies where ePHI exists in your organization, what threats and vulnerabilities are present, what controls you have in place, and where your gaps are.
The output is a written document that demonstrates you have assessed your risk. That document is not just for internal use. It is evidence that you have done what the law requires, and it is what auditors, insurers, hospital partners, and the Office for Civil Rights expect to see when they ask whether you are HIPAA compliant.
According to the HHS Office for Civil Rights, the HIPAA security risk assessment is one of the most frequently cited areas of noncompliance in HIPAA enforcement actions. Organizations that cannot produce a current, documented risk assessment are considered out of compliance regardless of what other safeguards they have in place.
Is a HIPAA Security Risk Assessment Required?
Yes. The HIPAA Security Rule, specifically 45 CFR 164.308(a)(1), requires every covered entity and business associate to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI they hold.
This is not a suggestion. It is a required implementation specification. There is no exemption for small organizations, no minimum size threshold, and no exception for organizations that have not had a breach. If you create, receive, maintain, or transmit ePHI electronically, you are required to have a current HIPAA security risk assessment on file.
The word current matters. A risk assessment completed several years ago that has not been reviewed since does not satisfy the requirement if your organization’s systems, vendors, workforce, or operations have changed. OCR has cited outdated assessments as violations in enforcement actions.
Who Needs a HIPAA Security Risk Assessment?
Any organization that qualifies as a covered entity or business associate under HIPAA needs a HIPAA security risk assessment. That includes:
Covered Entities
Covered entities are healthcare providers who transmit health information electronically, health plans, and healthcare clearinghouses. In practical terms, this includes:
- Medical practices of any size
- Hospitals and health systems
- EMS agencies and ambulance services
- Dental offices
- Mental health providers
- Pharmacies
- Urgent care centers
- Home health agencies
- Federally qualified health centers
- Health insurance companies and plans
Business Associates
Business associates are vendors and contractors who create, receive, maintain, or transmit ePHI on behalf of a covered entity. This includes billing companies, ePCR vendors, medical transcription services, IT managed service providers that support healthcare systems, cloud storage providers used for patient records, and any other third party with access to PHI.
Business associates are directly subject to the HIPAA Security Rule and must conduct their own HIPAA security risk assessment. It is not sufficient to rely on the covered entity’s assessment.
What Does a HIPAA Security Risk Assessment Cover?
A complete HIPAA security risk assessment addresses the following:
Scope of ePHI
Where does ePHI exist in your organization? This includes electronic health records, billing systems, ePCR platforms, email that contains patient information, portable devices used to access or transmit patient data, and any other system where patient information lives or passes through. The assessment starts by identifying and documenting all of these locations.
Threat and Vulnerability Identification
What could go wrong? Threats include things like ransomware, phishing, unauthorized access, lost or stolen devices, and natural disasters. Vulnerabilities are the weaknesses that make those threats more likely to succeed. Weak passwords, shared accounts, unencrypted devices, lack of audit logs, and missing business associate agreements are all examples of vulnerabilities a HIPAA security risk assessment is designed to surface.
Current Controls Assessment
What do you already have in place? Encryption, access controls, workforce training, audit logs, automatic logoff, remote wipe capability, and documented policies are all examples of controls. The assessment evaluates whether the controls you have are actually adequate for the risks you face, not just whether they exist on paper.
Risk Likelihood and Impact
For each identified threat and vulnerability combination, the assessment documents the likelihood that the threat will occur and the potential impact if it does. This creates a risk level for each item, which then informs the remediation priority.
Remediation Plan
A HIPAA security risk assessment is not just a list of problems. It should include a documented plan for addressing the gaps identified. Each gap should have a clear remediation step, a responsible owner, and a timeline. The remediation plan is what turns the assessment from a compliance document into something that actually improves your security posture.
What Happens If You Don’t Have One?
If OCR investigates your organization, whether because of a breach, a complaint, or a random audit, one of the first things they will ask for is your most recent HIPAA security risk assessment. If you cannot produce one, that is a violation on its own, regardless of whether a breach has occurred.
OCR has assessed civil monetary penalties ranging from tens of thousands to millions of dollars against organizations that failed to conduct or properly document a risk assessment. Small practices are not exempt. OCR has taken enforcement action against single-provider practices and small clinics.
Beyond OCR, the absence of a completed HIPAA security risk assessment can affect your ability to obtain or renew cyber liability insurance, enter into new business associate agreements, pass due diligence by hospital partners or health systems, and demonstrate compliance to your medical director or governing board.
How Often Does a HIPAA Security Risk Assessment Need to Be Updated?
HIPAA does not specify a fixed frequency for reassessment, but it requires that the assessment be kept current. In practice, most compliance guidance recommends reviewing and updating the assessment at least annually and whenever significant changes occur to your organization.
Significant changes that should trigger a reassessment include:
- Adding new software or technology that accesses or stores ePHI
- Changing ePCR vendors, billing companies, or other business associates
- Moving to a new facility or expanding your physical location
- Experiencing a security incident or breach
- Significant changes in workforce size or structure
- Adding new services that involve patient data
- Moving data to cloud storage or new platforms
What a HIPAA Security Risk Assessment Is Not
A HIPAA security risk assessment is not the same as a penetration test. It is not an IT audit. It is not a policy review on its own. And it is not a one-time checkbox that you complete once and never revisit.
Many organizations confuse these. A penetration test evaluates whether your technical systems can be breached. A HIPAA security risk assessment is broader. It evaluates your entire environment for risk to ePHI, including administrative and physical safeguards, not just technical ones. An organization can pass a penetration test and still have significant HIPAA security risk assessment gaps.
How to Get a HIPAA Security Risk Assessment Done
There are three realistic options:
Do It Yourself
HHS provides a free Security Risk Assessment tool at HealthIT.gov designed for small and medium healthcare practices. It walks you through the assessment process and produces a report. The tool is legitimate and the output is acceptable to OCR. The challenge is that it requires time, attention to detail, and a solid understanding of your technical environment to complete accurately.
Work With a Consultant
A HIPAA compliance consultant conducts the assessment with you, asking the right questions about your environment, identifying gaps you may not recognize on your own, and producing a written deliverable you can stand behind. This is the best option for organizations that want a thorough, defensible assessment without investing the internal time to do it themselves.
The cost of a professional HIPAA security risk assessment varies based on the size and complexity of the organization. For small to mid-size practices and EMS agencies, the range typically runs from $1,500 to $5,000. That is significantly less than the cost of an OCR enforcement action or a denied insurance claim.
Use a Policy Package as a Starting Point
If you need to close gaps quickly and have the internal capacity to implement, a pre-built HIPAA policy package gives you the documentation framework you need to get started. This works best as a supplement to a completed risk assessment, not a substitute for one.
The Bottom Line
A HIPAA security risk assessment is not optional, not something only large health systems need to worry about, and not something you can defer indefinitely. If you handle patient information electronically and do not have a current, documented assessment on file, you are out of compliance right now.
The good news is that getting compliant is not as complicated as the regulation makes it sound. It requires working through your environment systematically, documenting what you find, and building a plan to address the gaps. That process is manageable with the right support.
Forward Security Labs provides HIPAA security risk assessments, compliance consulting, and GRC documentation for healthcare organizations, EMS agencies, and business associates. Based in Wolcott, Connecticut. Founded by a U.S. Army combat veteran and paramedic supervisor with 20+ years in emergency healthcare. SDVOSB pending. SAM.gov registered. CAGE: 1AFL4.
