Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
Compliance Operations

HIPAA Risk Assessment Template (2026): What It Must Contain

The 12 sections every defensible HIPAA risk assessment must include, the NIST 800-30 methodology OCR expects, and the free template format independent practices can actually fill out and defend.

Share
HIPAA risk assessment template format and required sections for independent healthcare practices

HIPAA Risk Assessment Template (2026): What It Must Contain

The HIPAA risk assessment is the foundational document of a compliance program. Every other policy, control, and remediation activity references it. Doing it wrong is not a technicality — it cascades into everything else.

The good news: the regulation does not specify a template. The bad news: most free templates available online are inadequate, and OCR investigators can tell which ones came from where. This guide names the 12 sections a defensible risk assessment must contain, the methodology that produces defensible content, and the format independent practices can adapt without paying for a $15,000 consultant engagement.

What the Regulation Requires

§164.308(a)(1)(ii)(A) requires a covered entity to "conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity."

The implementation specification at §164.308(a)(1)(ii)(B) requires the covered entity to "implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level."

Together, these mean the risk assessment is not a one-time deliverable. It is the input to the risk management process — the document that drives which controls the practice implements, in which order, with what priority. A risk assessment that is not connected to a risk management plan is incomplete.

The Methodology Question

OCR has not mandated a specific methodology, but it has signaled clear preferences. The most-cited methodology in OCR-published guidance and consent agreements is NIST 800-30 (Guide for Conducting Risk Assessments), supplemented by NIST 800-66 (HIPAA Security Rule implementation guide for small and medium-sized providers).

NIST 800-30 defines a structured approach: identify threat sources, identify threat events, identify vulnerabilities, determine likelihood, determine impact, calculate risk. Each step has specific outputs that feed the next.

A risk assessment that cites NIST 800-30 and follows the methodology is defensible. A risk assessment that uses a different methodology must explicitly document what methodology it used and why. A risk assessment with no documented methodology is an unstructured opinion.

This is the single biggest gap in most free templates. They produce a risk register but not the methodology trail that explains how the register was generated.

The 12 Required Sections

A defensible HIPAA risk assessment for an independent practice has 12 sections. The numbering below matches the typical NIST 800-30 flow.

Section 1: Scope and Boundary

What is in scope. Specifically: which entity, which locations, which business functions, which information systems, which data flows. The boundary statement should be explicit enough that a reader can determine whether a specific system or function was assessed.

Section 2: Assessment Methodology

Citation to the methodology used (NIST 800-30 typically), explanation of any deviations, identification of the assessor (named person and credentials), and the date the assessment was performed.

Section 3: Asset Inventory

Every system, application, device, and vendor that creates, receives, maintains, or transmits ePHI. Most practices significantly underestimate this on first attempt. The inventory should include: name, owner, criticality, sensitivity, and BAA status (for vendors).

Section 4: Threat Source Identification

The categories of actors and events that could compromise the practice's ePHI. NIST organizes these as adversarial (insiders, external attackers, hacktivists), accidental (human error), structural (system failure, equipment failure), and environmental (fire, flood, natural disaster).

Section 5: Threat Event Catalog

Specific threat events relevant to the practice. For independent practices, the typical catalog includes ransomware infection, credential phishing, lost or stolen device, unauthorized employee access, accidental disclosure, business associate breach, and physical break-in.

Section 6: Vulnerability Identification

Where the practice's current controls are insufficient against the threats catalogued. Vulnerabilities are organized by safeguard category — administrative (training gaps, policy gaps), physical (facility access, device control), and technical (encryption gaps, access control weaknesses).

Section 7: Current Control Documentation

What the practice already does that mitigates risk. This is the section most templates omit and the section OCR investigators most appreciate. Practices generally have more controls than they document; undocumented controls are read as nonexistent in audit.

Section 8: Likelihood Determination

For each threat-vulnerability pairing, the assessed likelihood that the event would occur. NIST 800-30 uses a low/moderate/high scale; some assessments use numeric scoring. The methodology used should be documented.

Section 9: Impact Determination

For each threat-vulnerability pairing, the assessed impact if the event did occur. Considerations include patient harm, financial cost, regulatory exposure, reputational damage, and operational disruption.

Section 10: Risk Calculation

Likelihood × impact for each pairing, producing a prioritized risk register. The output should be a list of identified risks ranked by composite score, with the methodology for ranking documented.

Section 11: Risk Treatment Recommendations

For each risk above the practice's risk tolerance threshold, the recommended treatment. NIST uses four treatment categories: mitigate (implement additional controls), accept (acknowledge the risk and proceed), transfer (insurance, contractual transfer), or avoid (discontinue the activity).

Section 12: Management Approval

Signature of the practice's leadership accepting the assessment and the recommended treatments. Date of approval. Date of next required review.

A risk assessment missing any of sections 7, 11, or 12 is incomplete by OCR's standard. Most free templates omit at least one.

What Free Templates Get Wrong

After watching practices use various free templates, four specific gaps recur:

Generic threat catalog. Templates list threats that apply to a hospital ("foreign nation-state actor," "advanced persistent threat") and miss threats specific to an independent practice ("former employee retains laptop with cached PHI," "front-desk staff member uses personal email for patient communication"). The threat catalog should be tailored to the actual practice's risk model.

No current control documentation. Templates jump from vulnerabilities to risk calculations without acknowledging the controls already in place. The result is an assessment that overstates risk and produces remediation recommendations the practice has already implemented.

No methodology citation. Templates that don't cite NIST 800-30 or another recognized framework leave the assessor exposed during investigation — the methodology is the defense against a finding that the assessment was "not accurate and thorough."

No risk register output. Templates produce a narrative document but not a structured risk register. The risk register is what feeds the risk management plan; without it, the assessment is descriptive but not actionable.

How to Conduct the Assessment (Not Just Document It)

The template is the artifact. The assessment is the process that produces it. Four practical steps:

Step 1: Inventory walkthrough. Walk every workstation, server, mobile device, and vendor connection. Most asset inventories are missing 30-50% of actual assets on first attempt. Physical walkthrough catches what desk surveys miss.

Step 2: Interview each workforce role. Front desk, clinical, billing, IT. Each has a different view of how ePHI flows and where the practice's controls have gaps. A risk assessment based only on management's view is incomplete.

Step 3: Document the assessment as you go. Notes during the assessment become the basis of the risk register. Trying to reconstruct the assessment from memory at the end produces gaps.

Step 4: Engage the practice owner in the risk treatment decisions. Risk treatment requires business judgment — what to mitigate, what to accept, what to insure. These decisions cannot be delegated to a consultant or to compliance software; they require the practice's leadership.

Where to Find a Starter Template

Several sources publish HIPAA risk assessment templates that are usable starting points:

HHS Office for Civil Rights publishes the SRA Tool, which is closer to a guided questionnaire than a template. Output is a risk register but generic.

NIST publishes Special Publication 800-66 with example methodology and worksheets. Closer to a template than the SRA tool. Free.

State medical associations publish state-specific templates that include state-law overlay (particularly relevant for behavioral health and dental).

Patient Protect's free-tools page publishes a starter template specifically designed for independent practices, sized to the 12 sections above. Available at patient-protect.com/free-tools.

Compliance consultants publish templates as lead-generation. Functional starting points; verify the methodology cited.

How Patient Protect Helps

Patient Protect treats the risk assessment as an ongoing data structure, not a point-in-time document. The platform maintains your asset inventory continuously, monitors your control configurations, surfaces vulnerabilities as they appear, and produces the documented risk register that satisfies §164.308(a)(1) at any point in time — not just on the day a consultant ran the assessment.

For independent practices that have downloaded templates and not finished them — or finished them once two years ago and not updated since — the platform turns a static artifact into a living function.

The right risk assessment template is the one whose output you can actually defend in an investigation. The 12 sections above are the format. The methodology citation is the defense. The ongoing maintenance is the discipline.

Was this useful? Share it.

Share

Next step

What would an OCR investigator find on your website?

Free 30-second scan — tracking pixels, security gaps, missing policies. See what’s visible before they do.

Stay informed

Get HIPAA Pulse delivered.

Breach alerts, enforcement updates, and compliance intelligence — every two weeks.

© 2026 Patient Protect LLC. All rights reserved. Content may not be reproduced, scraped, or used to train AI models without written permission. Terms · DMCA