Scope statement
The systems, workflows, locations, workforce roles, and business associates in scope — the environment the analysis actually covers.
Regulatory guide
Under 45 CFR §164.308(a)(1)(ii)(A), every covered entity and business associate must conduct “an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of” electronic protected health information. This is the risk analysis. It is the foundation of the Security Rule and the single most-cited failure in OCR enforcement.
45 CFR §164.308(a)(1)(ii)(A) · HHS Risk Analysis Guidance · NIST SP 800-30
What HIPAA actually requires
The Security Rule’s risk analysis standard sits at §164.308(a)(1)(ii)(A). It requires the covered entity (and, since the 2013 Omnibus Rule, the business associate) to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the electronic protected health information it creates, receives, maintains, or transmits.
The risk analysis does not stand alone. It exists to inform risk managementat §164.308(a)(1)(ii)(B), which requires the entity to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. The analysis is what identifies the work; risk management is the work. HHS treats both as ongoing obligations, not point-in-time events.
HHS’s official Guidance on Risk Analysis Requirements under the HIPAA Security Rule points to NIST Special Publication 800-30 as the reference methodology. NIST SP 800-30 is not itself a HIPAA requirement, but its framework — inventory, threats, vulnerabilities, likelihood, impact, controls, risk determination — is what OCR expects a defensible analysis to reflect.
Who needs one
Covered entities — health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically in connection with a HIPAA transaction — are subject to the risk analysis standard directly. The requirement applies regardless of size or specialty. A solo dental practice, a five-provider therapy group, and a twenty-office DSO carry the same standard.
Since the 2013 Omnibus Rule, business associates are subject to the Security Rule directly, including the risk analysis standard. If a practice’s vendors create, receive, maintain, or transmit ePHI on the practice’s behalf, those vendors are conducting their own risk analysis of the ePHI in their possession — not doing the practice’s.
Not sure whether your organization is a covered entity, a business associate, or a vendor that falls outside HIPAA entirely? The free Entity Determination Tool walks through the classification in about a minute.
How often
HHS Risk Analysis Guidance is explicit on this point: the rule does not specify how frequently to perform risk analysis. Frequency “will vary among covered entities.” Some organizations run it annually, some more often, some less often depending on the environment. What matters is that the analysis remains accurate and thorough — not that a specific calendar interval is met.
The trigger that always matters is a material change. Re-run or update the analysis when any of the following happens:
Annual has become a common working cadence in the industry. It is a reasonable operating default. It is not what the rule says.
What it should contain
The Security Rule does not prescribe a fixed template. HHS guidance describes what the analysis must accomplish; the elements below are the working structure of an analysis that reflects that guidance and holds up to OCR scrutiny.
The systems, workflows, locations, workforce roles, and business associates in scope — the environment the analysis actually covers.
Where ePHI is created, received, maintained, or transmitted. §164.316(b) requires this be documented; §164.308(a)(1)(ii)(A) requires the analysis be accurate and thorough about it.
The threat sources — human, environmental, technical — a covered entity would reasonably anticipate against its ePHI. HHS guidance references NIST SP 800-30 methodology.
The weaknesses in current administrative, physical, and technical safeguards that a threat could exploit. Concrete, per-system, not abstract.
For each threat/vulnerability pair, an assessment of how likely exploitation is and what the impact on ePHI would be if it occurred.
The safeguards already in place — technical, physical, administrative — and how each maps to the risks identified.
A defensible ordering of residual risk so risk management (§164.308(a)(1)(ii)(B)) can address the highest-impact gaps first.
The analysis itself and any subsequent action must be maintained in written or electronic form for six years from the date of creation or last effective date, per §164.316(b)(2)(i).
Working through the format in detail? The HIPAA Risk Assessment Template guide walks through each of these elements as a fillable structure, with references to the NIST SP 800-30 methodology.
The HHS SRA Tool
The Security Risk Assessment Tool is a free application developed by the Assistant Secretary for Technology Policy / Office of the National Coordinator (ASTP/ONC) in collaboration with OCR, aimed at small and medium-sized healthcare organizations. It is available as a desktop application (Windows and macOS) and, more recently, in a web version, and it walks a practice through a structured set of questions across administrative, physical, and technical safeguards.
Used honestly and completely, the SRA Tool can help a practice produce documentation that satisfies the analysis standard. It is genuinely free, it is aligned with the Security Rule structure, and for a first-time analysis at a small practice it is a reasonable starting point.
What it does not do: update itself as the practice changes; connect the risk determination to a risk-management task queue; maintain the six-year documentation retention required at §164.316(b)(2)(i) on the practice’s behalf; or reflect changes to the vendor set, workforce, or infrastructure between manual re-runs. The tool completes an event. Compliance is a state.
Extended analysis of the SRA Tool’s scope and limitations is in the companion post: The Free HHS SRA Tool Isn’t Enough.
How practices do the work
A free desktop and web questionnaire tool developed by ONC in collaboration with OCR, aimed at small and medium-sized practices. It walks through a structured set of questions and generates a report. It is a legitimate starting point — particularly for a first-time analysis — but it is a questionnaire, not an ongoing risk management program. See the extended analysis in the HHS SRA Tool guide below.
Some practices work through a written template or spreadsheet, either self-authored or based on a published framework (NIST SP 800-30 is the methodology HHS most consistently references). Defensibility depends on whether the analysis actually reflects the practice's environment.
A HIPAA consultant conducts interviews, reviews configurations and documentation, and delivers a written assessment. Costs vary widely; see the SRA cost breakdown for the honest pricing range. A one-time consultant analysis satisfies the requirement at a point in time; it does not continuously reflect the practice as it operates afterward.
Platforms like Patient Protect maintain the analysis continuously against the practice's current state — inventory changes, workforce changes, vendor changes, BAA status, training completions — so risk determinations reflect the environment as it is, not as it was at last review.
The cost profile of each approach — free tool through $25,000+ consultant engagement — is broken down in How Much Does a HIPAA Risk Assessment Cost?. The seven recurring failure patterns that turn a completed analysis into an OCR finding are catalogued in the seven common risk-assessment mistakes.
Patient Protect’s three assessment surfaces
Patient Protect offers three assessment surfaces. They are not interchangeable. Confusing them is a common source of buyer misalignment, so this section is explicit.
Free · No login · ~5 minutes
A five-minute exposure diagnostic that runs entirely in the browser (no PHI, no data transmitted to Patient Protect servers). Identifies likely gaps and produces an exposure rating, findings list, and defensibility percentage. It is a diagnostic, not the completed formal Security Risk Assessment the rule requires.
Run the diagnostic →In-platform · Included with subscription
The formal, guided Security Risk Assessment workflow inside the Patient Protect platform. Produces the documented analysis contemplated at §164.308(a)(1)(ii)(A), with the scope, ePHI inventory, threat/vulnerability enumeration, likelihood and impact ratings, and risk determination retained under the six-year documentation standard at §164.316(b)(2)(i).
How the platform runs it →Continuous · Included with subscription
The risk management standard at §164.308(a)(1)(ii)(B) is what happens after the analysis: implementing safeguards sufficient to reduce risks to a reasonable and appropriate level. Patient Protect maintains this continuously as the practice changes — new vendors, workforce, systems, or configured controls — so risk determinations reflect the practice as it is, not as it was.
How ongoing risk works →Deeper reading
The 12 sections every defensible SRA must include, mapped to the NIST 800-30 methodology.
Read →The full pricing spectrum — free tool through $25,000 consultant engagement — with what each tier actually buys.
Read →The scope, strengths, and limitations of the ONC/OCR tool for practices past their first analysis.
Read →The recurring failures that turn a completed analysis into an OCR finding — visible before any audit.
Read →Map every vendor, device, and workflow touching PHI. Feeds directly into the ePHI-inventory element of the analysis.
Read →The seven documents OCR requests in a typical audit — the risk analysis is #1.
Read →Risk analysis in actual OCR enforcement
Each summary reflects what OCR itself stated in its resolution agreement or press release. The pattern is consistent across two decades: risk analysis is the single most-cited Security Rule failure in published OCR enforcement.
OCR found that Anthem failed to conduct an enterprise-wide risk analysis, had insufficient procedures to regularly review information system activity, failed to identify and respond to a detected cyberattack in a timely manner, and failed to implement adequate minimum access controls. This is the largest HIPAA settlement in OCR history.
Corrective action: Two-year corrective action plan including risk analysis, risk management, and workforce training obligations.
OCR found that Excellus failed to conduct an enterprise-wide risk analysis, failed to implement risk management sufficient to reduce risks to a reasonable and appropriate level, failed to implement technical policies and procedures for access controls, and failed to implement procedures to regularly review information system activity records.
OCR found that Advocate failed to conduct an accurate and thorough risk analysis of all ePHI, failed to implement policies and procedures governing physical access and workstation use, and failed to obtain satisfactory assurances in the form of a written business associate agreement from a business associate that stored ePHI on its behalf.
Corrective action: Multi-year corrective action plan across risk analysis, BAA execution, and device/media controls.
OCR investigated five separate breach reports across FMCNA facilities and found that FMCNA failed to conduct an accurate and thorough risk analysis, failed to implement risk management adequate to address vulnerabilities, failed to implement policies to safeguard facilities from unauthorized access, failed to implement policies for the receipt/removal of hardware and media containing ePHI, and failed to implement encryption on ePHI where reasonable and appropriate.
Following an unauthorized network intrusion, OCR found that Athens Orthopedic Clinic had systemic non-compliance with the Security Rule including failure to conduct a risk analysis, failure to implement audit controls, failure to implement access controls, and failure to enter into BAAs with vendors.
Following breaches involving a lost unencrypted flash drive and a stolen unencrypted laptop, OCR found that URMC had failed to conduct an enterprise-wide risk analysis, failed to implement device and media controls, and failed to use encryption to safeguard ePHI on mobile devices.
Following two breaches exposing patient records to the internet, OCR found that Cottage Health failed to conduct an accurate and thorough risk analysis, failed to perform periodic technical and non-technical evaluations in response to environmental or operational changes, and failed to obtain a written business associate agreement from a vendor.
Following an incident in which ePHI of 6,800 patients became accessible on internet search engines, OCR found that both entities failed to conduct an accurate and thorough risk analysis, failed to implement processes for assessing and monitoring information system activity, and failed to implement adequate policies and procedures for authorizing access to their databases.
Following the theft of an unencrypted laptop containing research participant ePHI, OCR found that Feinstein had insufficient security management processes, an incomplete risk analysis, inadequate policies for granting/modifying access to ePHI, and inadequate policies for the receipt/removal of hardware and electronic media containing ePHI.
Each summary reflects what OCR itself stated in the resolution agreement or press release. Locate specific matters on the HHS resolution agreements index by entity name.
Common questions
Yes. 45 CFR §164.308(a)(1)(ii)(A) requires every covered entity and business associate to conduct "an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information" held by the entity. It is a Security Rule standard, not an addressable specification.
Every HIPAA-covered entity and every business associate. Covered entities are health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically in connection with a HIPAA transaction. Business associates are organizations that create, receive, maintain, or transmit PHI on behalf of a covered entity. Size, revenue, and practice specialty do not create an exemption.
The Security Rule does not specify a frequency. HHS Risk Analysis Guidance states that risk analysis should be an ongoing process and that the frequency will vary among covered entities depending on the environment — some perform it annually, some more often, some less often. What triggers a re-analysis is a material change: new vendor, EHR migration, new location, staff turnover in an access-holding role, adoption of new AI or communication tools, or any suspected incident. Annual is a common working cadence; it is not a HIPAA rule.
The risk analysis (§164.308(a)(1)(ii)(A)) is the assessment: identify the risks and rate their likelihood and impact. Risk management (§164.308(a)(1)(ii)(B)) is what the covered entity does about those risks — implementing security measures sufficient to reduce them to a reasonable and appropriate level. Both are required. Analysis without management is documentation without action; management without analysis is action without justification.
It can satisfy the analysis requirement if a practice actually works through it accurately and uses the output to drive risk management. It is a questionnaire, not an ongoing risk-management program, and it does not update as the practice changes. For a small practice conducting a first analysis, it is a reasonable starting point; for a practice that needs the analysis to keep pace with its environment, a continuous approach — platform, consultant retainer, or documented internal process — is what actually holds up in an OCR review.
A scope statement; a current ePHI inventory; a catalog of reasonably anticipated threats; identified vulnerabilities in current safeguards; a likelihood-and-impact assessment for each threat/vulnerability pair; the current control set; a defensible risk determination and prioritization; and documentation retained for six years per §164.316(b)(2)(i). HHS guidance points to NIST SP 800-30 as the reference methodology.
Next step
The formal risk analysis is the deliverable. The Patient Protect Score is the five-minute diagnostic that shows you the gaps a formal analysis would find — before you commit to the full workflow. Free, no login, no PHI transmitted.
Free tools stay free — no account needed. The 14-day platform trial asks for a card for identity verification; no charge before day 14, cancel any time.
Primary sources
Reviewed by Joseph A. Perrin, Patient Protect CTO. Last reviewed 2026-08-25. Corrections: submit a note.