HIPAA Risk Assessment: What Is It and How to Conduct One (2026 Guide)
- Home
- HIPAA Compliance Software
- HIPAA Risk Assessment: What Is It and How to Conduct One (2026 Guide)
If you treat patients, you hold some of the most personal information a person can share. Names, diagnoses, therapy notes, payment details, and contact information all pass through your practice every day. One lost laptop or one phishing email can put that data at risk.
A HIPAA risk assessment is how you find those weak spots before someone else does. It is also the law. The HIPAA Security Rule requires it, and it sits at the center of every good data protection program.
This guide breaks the process down into simple steps. You will learn what a HIPAA risk assessment is, who needs to do one, how to run it, and the mistakes that get practices in trouble. Whether you are a solo therapist or part of a larger health system, you will finish with a clear picture of what to do next.
Ready to Simplify HIPAA Compliance?
What Is a HIPAA Risk Assessment?
A HIPAA risk assessment is a careful review of how your practice protects patient data. It looks at where health information lives, what could go wrong, and how well your current protections hold up.
The focus is on protected health information, often shortened to PHI. When that information is stored or sent electronically, it is called ePHI. A HIPAA risk assessment checks the safety of this data across your systems, devices, and daily routines.
The goal is to spot risks to the privacy, accuracy, and availability of patient data. Once you find those risks, you can fix them. This review is not a one-time task. It works best as a habit you repeat as your practice changes.
HIPAA Risk Assessment vs. Risk Analysis vs. Gap Assessment
People often use these three terms as if they mean the same thing. They are related, but they are not identical.
- Risk assessment: The broad review that finds risks to patient data. Many people use this term as a catch-all for the whole process.
- Risk analysis: The step where you rate each risk by how likely it is and how much damage it could cause.
- Gap assessment: A check that measures your current practices against a set list of controls or rules. It shows you what is missing, but it does not rate risk on its own.
In plain terms, a risk assessment finds the problems, a risk analysis ranks them, and a gap assessment shows where you fall short of a standard. A strong program uses all three ideas together.
Why a HIPAA Risk Assessment Matters
A HIPAA risk assessment is more than paperwork. It protects your patients, your finances, and your reputation. Here is why it deserves your attention.
Regulatory Compliance
The HIPAA Security Rule requires covered entities and their business associates to review risks to patient data. This is not optional. Skipping it puts you out of step with federal law.
The review is also the foundation for the rest of your security work. You cannot pick the right protections until you know what you are protecting against. Every other safeguard decision flows from this first step.
Breach Prevention and Data Protection
Most data breaches trace back to a weak spot that was never found or fixed. A HIPAA risk assessment surfaces those weak spots on your terms, not during a crisis.
Say your front-desk email accepts patient intake forms but has no second layer of sign-in protection. A review would flag that gap so you can add multi-factor authentication, a method that asks for a second form of proof at login. Finding it early is far cheaper than cleaning up after a breach.
Financial and Legal Liability
The cost of skipping a risk assessment can be steep. OCR can issue penalties that reach into the millions, depending on how serious the violation is. In many enforcement cases, OCR found that the organization never performed a proper risk analysis.
Beyond fines, a breach brings other costs. You may face lawsuits, credit monitoring bills for affected patients, and the expense of a forced cleanup. A solid risk assessment helps you avoid these outcomes and shows you acted in good faith.
Reputation and Patient Trust
Patients share private details because they trust you to guard them. That trust is fragile. A single breach can send people to another provider and keep new patients from ever walking in.
This matters even more in fields like therapy and behavioral health, where records hold deeply personal information. Protecting that data is part of protecting the care relationship itself. A HIPAA risk assessment shows patients and regulators that you take that duty seriously.
Is a HIPAA Risk Assessment Required? Rules and Types Explained
Yes. HIPAA calls for a risk assessment in more than one place. There are also broader reviews that smart practices run even when the rules do not force them to. Here are the main types.
The Security Rule Requirement (Security Risk Assessment)
The most well-known requirement comes from the HIPAA Security Rule. Under 45 CFR 164.308(a)(1), you must conduct an accurate and thorough review of the risks to the privacy, accuracy, and availability of the ePHI you hold.
This applies to both covered entities and business associates. It covers all electronic patient data you create, receive, store, or send. This is the security risk assessment most people picture when they hear the term.
The Breach Notification Rule Requirement (Breach Risk Assessment)
A second review appears in the HIPAA Breach Notification Rule at 45 CFR 164.402. This one kicks in after something goes wrong, such as sending a record to the wrong person.
Under this rule, any exposure of unsecured PHI is treated as a breach unless you can show a low chance that the data was compromised. To prove that, you weigh four factors:
Factor to weigh | Question to ask |
Type of data involved | What PHI was exposed, and how easily could someone be identified? |
Who accessed it | Who received or used the information? |
Whether it was seen | Was the data actually viewed or taken, or just exposed? |
How it was contained | What did you do to limit the damage afterward? |
A fax sent to a nearby clinic that shreds it is very different from a hacker copying a full patient database. The breach risk assessment helps you tell the two apart and decide if you must notify patients and HHS.
The Privacy Risk Assessment
The Security Rule covers electronic data. But risks to patient privacy also exist on paper, over the phone, and in conversation. A privacy risk assessment looks at those wider risks.
This review often covers patients’ rights to see their own records, your agreements with vendors, and how staff handles information day to day. HIPAA does not name it as a single required task, the way it does the security review. Running one is still a wise move, because privacy problems can be just as damaging as electronic ones.
How Often Should You Conduct a HIPAA Risk Assessment?
HHS does not set a fixed schedule. The Security Rule expects an ongoing effort rather than a single event on a calendar. HHS guidance notes that timing varies by organization. Some review their risks each year, while others do so every two or three years, based on their situation.
Many practices still choose to review at least once a year, since a lot can change in that time. You should also run a review after any major change, such as:
- Adopting a new electronic health record system or app.
- Moving to a new office or adding a location.
- A merger, sale, or big change in leadership.
- A security incident or breach.
Between these reviews, keep an eye on your systems so you can catch new risks as they appear.
Who Needs to Conduct a HIPAA Risk Assessment?
The duty to review risks reaches further than many people expect. If patient data touches your organization, this likely applies to you.
Covered Entities
Covered entities are the groups HIPAA was written for. This includes health care providers who send data electronically, health plans, and health care clearinghouses that process claims.
Providers of every size fall here. A large hospital and a solo counseling practice both qualify. Size does not remove the duty. It only changes how much ground the review must cover.
Business Associates and Subcontractors
A business associate is any outside party that handles PHI on your behalf. This covers a lot of the vendors that a modern practice relies on.
- Billing and coding companies.
- Cloud-based electronic health record providers.
- IT support and data storage firms.
- Answering services and transcription vendors.
These partners must run their own HIPAA risk assessments. They sign a Business Associate Agreement, or BAA, a contract that commits them to protect the data and follow HIPAA. Their subcontractors carry the same duty. A weak vendor can expose your patients even when your own systems are sound.
In-House Teams vs. Third-Party Consultants
Larger organizations often have internal compliance or security staff to lead the review. That works well when the team has the time and the right skills.
Smaller practices may not have that in-house help. Bringing in an outside consultant or using purpose-built software can fill the gap. Either way, the review must be just as careful. A solo therapist and a hospital are held to the same standard for thoroughness and record-keeping.
The Three Safeguards a HIPAA Risk Assessment Evaluates
The HIPAA Security Rule sorts protections into three groups. A HIPAA risk assessment checks all three. Some protections are labeled “required,” and others are “addressable,” which means you either put them in place or document why you chose an equal alternative that fits your practice.
Safeguard type | What it protects | Examples |
Administrative | How your team handles data | Security officer, policies, staff training, backups |
Physical | Places and devices where data lives | Locks, badges, secure disposal, device tracking |
Technical | Systems and how data moves | Unique logins, encryption, audit logs, secure transmission |
Administrative Safeguards
Administrative safeguards are the policies and management steps that guide how your team handles data. They set the tone for everything else.
- Name a security officer to lead your efforts.
- Written policies for access, incidents, and backups.
- Staff training on threats such as phishing.
- A contingency plan so you can recover data after a disaster.
These are often the safeguards OCR finds missing, so they deserve close attention.
Physical Safeguards
Physical safeguards protect the places and devices where data lives. They keep the wrong people away from your systems and records.
- Locks, badges, and controls on server rooms and offices.
- Rules for how workstations are placed and used.
- Secure disposal of old drives and paper files.
- Tracking of laptops, tablets, and other portable devices.
A locked door and a wiped hard drive are simple steps, but they stop many common problems.
Technical Safeguards
Technical safeguards are the tools and settings inside your systems. They control who can access data and keep it safe as it moves.
- Unique logins and strong sign-in methods for each user.
- Encryption, which scrambles data so only authorized people can read it.
- Audit logs that record who accessed what and when.
- Protection for data sent by email or across networks.
Together, these three groups form the backbone of your defenses. Your review measures how well each one holds up.
How to Conduct a HIPAA Risk Assessment: Step by Step
This process follows the approach laid out in HHS guidance and in NIST publications. NIST, the National Institute of Standards and Technology, provides methods that the health sector widely accepts. Here are the steps in order.
Step 1 – Identify and Locate ePHI and Set Scope
Start by finding every place patient data lives. You cannot protect what you have not mapped.
Take a small therapy clinic. Its ePHI might sit in an electronic health record, in appointment reminder texts, in billing software, on laptops used for telehealth, and in a cloud backup. List all of it. Include devices, apps, remote staff, and vendors. Anything left off this list becomes a blind spot in the rest of your review.
Step 2 – Identify Threats
Next, list what could put that data at risk. Threats fall into three broad groups: natural, human, and environmental.
- Natural: Floods, fires, and storms that damage systems.
- Human: Phishing, ransomware, insider misuse, and simple mistakes like sending a record to the wrong person.
- Environmental: Power failures, leaks, and equipment breakdowns.
Human error and cyberattacks tend to be the most common. Do not stop at hackers. A staff member who loses a phone or mistypes an email address is a real threat, too.
Step 3 – Identify Vulnerabilities
A vulnerability is a weak spot that a threat could use. These come in technical and non-technical forms.
- Outdated software that no longer gets security fixes.
- Weak passwords or no second sign-in step.
- Data stored without encryption.
- Staff who have not been trained on HIPAA basics.
- No plan for handling a security incident.
Pair each vulnerability with the threats that could exploit it. An unencrypted laptop, for instance, becomes a serious problem the moment it is stolen.
Step 4 – Assess Current Safeguards
Now look at the protections you already have. Review your administrative, physical, and technical safeguards, using the three groups covered earlier in this guide.
Ask whether each safeguard is actually in place, set up correctly, and used as intended. A firewall that is installed but misconfigured offers little help. Write down what is working and what is not. This honest snapshot shapes every step that follows.
Step 5 – Determine the Likelihood of Each Threat
For every threat and vulnerability pair, judge how likely it is to happen. A simple scale works well, such as low, medium, or high.
Phishing against a busy front desk might rate high, since these attacks are constant. A major earthquake might rate low in most regions. Base your ratings on your real environment, not on guesswork. Your history and your setup are the best guides.
Step 6 – Determine the Potential Impact
Next, judge how much harm each event would cause. Use the same kind of scale: low, medium, or high.
Think about patient privacy, your ability to keep working, financial cost, and damage to trust. Exposed therapy notes carry a high impact because the information is so sensitive. A brief system slowdown might carry a low impact. Rating both likelihood and impact sets up the final risk score.
Step 7 – Determine the Overall Risk Level
Combine likelihood and impact to set the overall risk level for each item. A common method assigns a level based on both scores together. For example, a high-likelihood, high-impact risk sits at the top of your list.
This gives you a ranked view of your risks. The result should be a documented list of risk levels along with the corrective actions each one calls for.
Step 8 – Document the Assessment
Write everything down. Your records should show what data you hold, the risks you found, your ratings, and the actions you plan to take.
HHS does not demand a set format, but it does expect clear proof that you did the work. Date your records and share them with leadership. Good documentation is your best defense if OCR ever comes knocking.
Turning Findings into Action: Risk Management and Ongoing Review
A HIPAA risk assessment only helps if you act on what it finds. This stage turns your list of risks into real protection and keeps it working over time.
Prioritizing Risks and Building a Remediation Roadmap
Use your risk ratings to decide what to fix first. Start with the high-risk items that are both likely and damaging.
Build a written plan that lists each risk, the fix, the person responsible, and a target date. Tackling the top risks first gives you the biggest safety gain for your effort. Lower risks can follow on a set schedule.
Implementing Safeguards, Policies, and Procedures
Next, put the fixes in place. This might mean adding encryption, turning on multi-factor authentication, or writing clearer policies.
OCR often finds that practices fail because they lack written policies, or their policies are too thin. Back up each change with a clear, written procedure so staff know exactly what to do. Rules that live only in someone’s head do not hold up.
Workforce Training as Risk Mitigation
Your staff is your first line of defense. They are also a common source of mistakes. Training closes that gap.
Teach your team to spot phishing, handle records with care, and report problems quickly. Well-trained staff make fewer errors and catch threats sooner. Treat training as an active protection, not a box to check once a year.
Continuous Risk Management and Reassessment
Risk management is a habit, not a single project. New threats appear, and your practice keeps changing.
Review your safeguards on a regular basis and update them as needed. Run a fresh assessment after major changes, and check that your fixes are still working. This steady rhythm keeps your protections strong long after the first review ends.
HIPAA Risk Assessment Checklist
A checklist keeps your review on track and makes sure nothing slips through. Use these steps as a working guide.
- Find and list every place ePHI is created, received, stored, or sent.
- Set the scope, including devices, apps, remote staff, and vendors.
- List the threats to that data.
- Identify the vulnerabilities a threat could use.
- Review your current administrative, physical, and technical safeguards.
- Rate the likelihood of each threat.
- Rate the impact of each threat.
- Assign an overall risk level to each item.
- Write down the fixes needed for each risk.
- Document the full review, then set a date to repeat it.
Why a Checklist Improves Audit-Readiness
A checklist brings order to a process with many moving parts. It helps you cover each area the same way every time.
- Consistency: Nothing gets skipped from one review to the next.
- Accountability: Tasks have clear owners.
- Proof of effort: Your completed checklist shows OCR that you did the work.
- Training aid: It helps new staff learn the process quickly.
When an audit comes, an organized record of your work saves stress and time.
Why There’s No Universal HIPAA Risk Assessment Template
Many people search for a single template that does the job for every practice. It does not exist, and for good reason.
Every organization differs in size, systems, and the data it holds. A template built for a large hospital would miss the details of a small counseling office, and the reverse is just as true. If you use a template you find online, treat it as a starting point only. Adjust it to match your own systems, or it may leave real risks uncovered.
Software and Frameworks for a HIPAA Risk Assessment
You do not have to start from a blank page. Several trusted software and frameworks can guide your review. Here are the ones worth knowing.
NIST Frameworks (SP 800-30, SP 800-66, and the Cybersecurity Framework)
NIST publishes free guides that the health sector treats as trusted references. Three stand out for HIPAA work.
- SP 800-30: A guide for conducting risk assessments, including how to rate likelihood and impact.
- SP 800-66: A resource guide for putting the HIPAA Security Rule into practice.
- The NIST Cybersecurity Framework: A broad model for managing security risk across five functions, from identifying assets to recovering from incidents.
These documents are not HIPAA rules themselves. They offer proven methods that fit HIPAA’s goals well.
ISO 27005 and ISO 27001 Alignment
Some organizations align their reviews with international standards. Two ISO standards apply here.
- ISO 27001 sets out how to build and run an information security management system.
- ISO 27005 focuses on managing information security risk.
These standards are not required for HIPAA. They can add structure and credibility, especially for larger organizations that already follow other ISO practices.
Manual Spreadsheets vs. GRC Software
Many practices start their reviews in a spreadsheet. It is cheap and familiar, but it has limits. Spreadsheets are easy to misplace, hard to update, and tough to track over time.
Purpose-built GRC software offers a better path as you grow. GRC stands for governance, risk, and compliance. This kind of software keeps your risks, controls, and records in one place, updates easily, and creates the audit trail OCR expects. For a growing practice, it saves time and reduces the chance of errors.
Common Reasons HIPAA Risk Assessments Fail (and What OCR Looks For)
Not every review holds up under scrutiny. In fact, a weak or missing risk analysis is the single most common problem OCR finds in its investigations. OCR has also said its current round of HIPAA audits focuses closely on the risk analysis and risk management requirements. Here are the mistakes that trip practices up and how to avoid them.
Assessing Only at the Control Level
Some reviews only check whether a control exists, such as a firewall or a policy. They stop there. That surface-level check misses risks hiding inside specific systems and devices.
A stronger approach ties risks to your actual assets, such as a particular server, laptop, or app. This asset-level view catches problems a simple checklist would skip. It also gives you real data you can act on.
Incomplete Scope
A review is only as good as its scope. Leave out a device, a vendor, or a remote worker, and you leave out the risks that come with them.
A common mistake is forgetting personal phones used for work or a backup service that quietly stores patient data. Map everything before you begin. A gap in scope becomes a gap in your defenses.
Treating It as a One-Time Event
Some practices run one review, file it away, and move on. Then years pass with no update. Meanwhile, new systems appear, and new threats emerge.
The Security Rule expects an ongoing effort. Set a regular schedule, and refresh your review after any major change. A stale assessment offers little protection and little defense during an audit.
Think Documentation and No Remediation Follow-Through
Finding risks is only half the job. Some practices document their findings poorly, or they never fix what they found.
OCR wants to see both the review and the action that followed. Keep clear, dated records of your findings and your fixes. A list of risks with no follow-up can look worse than no review at all, because it shows you knew and did nothing.
Excluding Business Associates
Your patients’ data often flows to vendors. If your review ignores them, you miss a large share of your real risk.
Track your business associates, confirm they have signed BAAs, and make sure they run their own reviews. A breach at a billing company or cloud provider can expose your patients just as easily as a breach in your own office. Their risk is your risk.
How ComplyAssistant Simplifies HIPAA Risk Assessments
Running a HIPAA risk assessment by hand takes time, and small mistakes are easy to make. ComplyAssistant is software built for health care organizations that brings your risks, records, and vendors into one place. Its main features include the following:
- A central risk register. Rate each threat by how likely it is and how much harm it could cause, and the tool calculates the residual risk level for you. Choose how to handle each risk (avoid, control, accept, or transfer), use ready-made controls or add your own, and see your remaining risk at a glance.
- HIPAA and audit management. Manage HIPAA and related rules, such as NIST Cybersecurity Framework 2.0, with dashboards and alerts that keep your status current. Audit-ready reports and stored records give you the proof OCR expects.
- Policy management. Write, store, and update the written procedures that back up your safeguards so your records stay ready for an audit.
- Vendor and third-party tracking. Track your business associates and their agreements, confirm each has a signed BAA, and set reminders for contract renewals.
- Framework mapping. Map your risks to standards such as HIPAA and NIST to keep your review organized and easy to defend.
- Expert support. Get HIPAA audits, expert consultants, and virtual CISO services when you do not have a full security team in-house, with findings and a clear action plan delivered inside the portal.
Ready to make your next HIPAA risk assessment simpler? Contact our professional team to see how ComplyAssistant fits your organization.
Conclusion
A HIPAA risk assessment is one of the most useful steps you can take to protect patient data. It shows you where your risks are, helps you fix them, and proves to regulators that you take security seriously.
The core process is steady and repeatable. Find your data, list your threats and weak spots, rate each risk, act on the top ones first, and keep the review going over time. Do this well, and you protect not just your records but the trust your patients place in you.
You do not have to do it alone. ComplyAssistant’s software and expert team can guide your review, track your vendors, and keep you audit-ready. Contact the ComplyAssistant team to see how they can support your practice.
Frequently Asked Questions
How often should a HIPAA risk assessment be conducted?
HHS does not set a required frequency. Its guidance says the timing varies by organization. Some review their risks each year, while others do so every two or three years. Many practices still choose a yearly review to stay safe. You should also run one after any major change, such as new software, a new location, or a security incident.
What’s the difference between a HIPAA risk assessment and a risk analysis?
A risk assessment is the broad review that finds risks to patient data. A risk analysis is the step where you rate each risk by how likely it is and how much harm it could cause. HHS uses the term “risk analysis” in the Security Rule, and many people use both terms to describe the same overall process.
Who is responsible for conducting a HIPAA risk assessment?
The duty falls on the organization that holds the data. In larger groups, an internal compliance or security officer often leads the work. Smaller practices may use an outside consultant or software. Whoever runs it, the review must be thorough and well documented.
Do the requirements apply to business associates?
Yes. Any vendor that handles PHI on your behalf must run its own HIPAA risk assessment. This includes billing companies, cloud providers, IT firms, and their subcontractors. They also sign a Business Associate Agreement that commits them to protect the data.
Is there a HIPAA risk assessment template?
There is no single template that fits every profile, because organizations differ in size, systems, and the data they hold. You can use a template as a starting point, but you must adjust it to match your own setup. A generic form may leave real risks uncovered.
How long does a HIPAA risk assessment take?
Timing depends on your size and complexity. A small practice might finish in a few days, while a large health system may need months. Good software and a clear checklist can shorten the process. Rushing it, though, tends to leave gaps.
What happens if you don’t conduct one?
Skipping a risk assessment puts you out of step with HIPAA and raises your chance of a breach. It is also the problem OCR flags most often. If a breach or audit occurs, the lack of a review can lead to larger fines, since it suggests you failed a basic duty.
What is a “reasonably anticipated threat”?
A reasonably anticipated threat is any danger to patient data that you could foresee. This covers outside attacks like hacking and inside risks like human error or a lack of training. HIPAA expects you to plan for these foreseeable threats, which is why a full view of your operations matters so much.
Can software help with a HIPAA risk assessment?
Yes. Doing a HIPAA risk assessment by hand often means juggling spreadsheets, and that is where mistakes slip in. Software built for health care, such as ComplyAssistant, keeps your risks, records, and vendors in one place. It rates each risk for you, tracks your fixes, and stores the records OCR expects, which makes each review faster and easier to defend.