A HIPAA risk assessment is the documented analysis of risks to electronic protected health information that 45 CFR 164.308 requires from every covered entity and business associate. Run it across all ePHI, score likelihood and impact, fix what it finds, and repeat at least annually and after material change.
In February 2024, the Change Healthcare ransomware attack exposed the records of 192.7 million people, the largest healthcare breach ever reported to HHS. Eight months later, OCR answered with a dedicated Risk Analysis Initiative: an enforcement program aimed at exactly one failure.
| HIPAA Risk Assessment: The Practitioner’s Cheat Sheet |
| A HIPAA risk assessment is required by 45 CFR 164.308(a)(1)(ii)(A): an accurate, thorough analysis of risks to all ePHI you create, receive, maintain, or transmit. No certification substitutes for it. |
| OCR launched a dedicated Risk Analysis Initiative in October 2024; roughly ten enforcement actions followed within months, and the common thread in every one was an insufficient or missing risk analysis. |
| 2024 was the worst breach year on record: 725 large breaches exposed data on more than 275 million people, with Change Healthcare’s 192.7 million alone dwarfing everything else. |
| Three assessment types cover the compliance surface: the Security Rule risk analysis, the four-factor breach risk assessment under 164.402, and the privacy assessment of uses and disclosures. |
| The proposed Security Rule update (published January 2025, final rule expected in 2026) would make risk analysis requirements explicit and prescriptive, with 240 days to comply after publication. |
| Run the nine OCR elements, document everything, and review at least annually and after every material change; an undocumented assessment is treated as no assessment at all. |
That failure is the missing or inadequate risk analysis, and OCR found it in roughly ten settlements within the initiative’s first months. Regardless of how each breach happened, the entity had not sufficiently assessed its own risks first. The assessment is no longer paperwork; it is the primary enforcement target.
What a HIPAA Risk Assessment Is and What the Rule Requires
The obligation lives in 45 CFR 164.308(a)(1)(ii)(A): conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. OCR’s risk analysis guidance interprets that one sentence into nine expected elements, covered below.
Scope is where most assessments fail before they start. The analysis must cover every system that creates, receives, maintains, or transmits ePHI, including the billing platform, the imaging archive, the email tenant, and the vendors handling data on your behalf. A partial inventory produces a partial assessment, which OCR reads as no assessment.
Method is flexible by design. NIST SP 800-66 Revision 2 maps the Security Rule to NIST’s cybersecurity practices, and the general risk assessment methodology playbook applies: identify assets and threats, judge likelihood and impact, and rank the results. HIPAA cares that the analysis is thorough and documented, not which framework badge it wears.
Three Assessment Types, Three Different Questions
HIPAA compliance actually runs on three distinct assessments, and conflating them is a persistent audit finding. Each answers a different question, on a different trigger, under a different rule section. The table separates them the way OCR’s enforcement team does.
| Assessment | Question it answers | When it runs |
| Security risk analysis (164.308) | What could compromise the confidentiality, integrity, or availability of our ePHI? | Ongoing risk analysis: at least annually and after material change |
| Breach risk assessment (164.402) | Is this specific incident reportable, or is there a low probability of compromise? | After every potential breach, using the four-factor test |
| Privacy assessment (Privacy Rule) | Do our uses and disclosures of PHI match the Privacy Rule and our notices? | On policy changes, new data flows, and periodic review |
The four-factor breach test deserves its own note because it decides notification duties. You weigh the nature of the PHI involved, who received or accessed it, whether it was actually acquired or viewed, and how far the risk has been mitigated. Document all four factors every time; the burden of proving low probability sits with you.
Why OCR Now Treats a Missing Analysis as the Root Violation
Enforcement doctrine shifted in October 2024. Rather than chasing each breach’s technical cause, OCR’s Risk Analysis Initiative asks whether the entity had assessed its risks at all, and settles on that answer. Roughly ten resolution agreements followed in the initiative’s first months, spanning wellness vendors, clinics, and business associates.
The logic is hard to argue with. An entity that never mapped its ePHI could not have chosen controls rationally, so every downstream safeguard failure traces back to the absent analysis. It is the same root-cause reasoning a compliance risk assessment applies anywhere else, now backed by settlement dollars and multi-year corrective action plans.

Figure 1. The HIPAA risk assessment enforcement clock: a 2013 baseline, a 2024 enforcement initiative, a 2025 proposed rule, and a 2026 finalization window.
The proposed Security Rule update, published January 6, 2025 at 125 pages, would harden this further: explicit asset inventories and network maps, prescriptive risk analysis content, and removal of the addressable-versus-required distinction that entities used to defer controls. HHS signaled a final rule for 2026, with 240 days to comply once it lands.
The Numbers Behind the Urgency
The breach ledger explains the regulatory mood. HIPAA Journal’s analysis of HHS breach portal data counted 725 large breaches in 2024 exposing more than 275 million individuals, a 60.5% jump in breached records over 2023. One incident accounted for most of it.

Figure 2. The 2024 ledger a HIPAA risk assessment is defending against: Change Healthcare’s 192.7 million records dwarfed the other 724 large breaches combined.
Cost pressure runs the same direction even as the averages ease. IBM’s Cost of a Data Breach research has ranked healthcare the most expensive breach industry for fourteen consecutive years: $10.93 million on average in 2023, $9.77 million in 2024, and $7.42 million in 2025. Falling, but still the worst seat in the room.

Figure 3. Healthcare’s average breach cost, per IBM: easing to $7.42 million in 2025, yet the costliest industry for the fourteenth straight year.
How to Conduct a HIPAA Risk Assessment: The Nine OCR Elements
OCR’s guidance breaks the required analysis into nine elements, and treating them as a checklist keeps the work audit-defensible. Small practices can run them with the free SRA Tool from ONC and OCR; larger organizations typically fold them into an enterprise information security risk program.

Figure 4. The nine elements OCR expects a HIPAA risk assessment to document, from full-scope ePHI inventory through periodic review.
Three of the nine elements carry most of the failure weight in OCR enforcement files, and none of them is technical. Scope, documentation, and periodic review are where assessments quietly rot, so build them as standing processes rather than annual heroics:
- Scope: inventory every ePHI location first, including shadow systems, backups, medical devices, and business associate flows
- Documentation: record methods, findings, risk ratings, and decisions; OCR treats an undocumented analysis as nonexistent
- Review: reassess at least annually, after every new system, merger, or incident, and on every material workflow change
Feed the output into a living risk register with owners and deadlines, then let the register drive the risk management plan the Security Rule separately requires at 164.308(a)(1)(ii)(B). The assessment finds; the treatment plan fixes. OCR’s corrective action plans check for both.
Covered Entities and Business Associates: Who Assesses What
Both covered entities and business associates carry the full risk analysis duty; the difference is scope and vantage point. A hospital assesses everything it touches, while a claims processor assesses the services and systems handling client ePHI. Neither can inherit the other’s assessment.
| Dimension | Covered entity | Business associate |
| Who | Providers, health plans, clearinghouses | Anyone handling ePHI for a covered entity, plus their subcontractors |
| Scope | All ePHI across clinical, billing, and administrative systems | The services, systems, and personnel touching client ePHI |
| Legal driver | Security Rule directly | Security Rule directly, plus business associate agreement terms |
| Typical resourcing | Internal security and compliance teams, external validation | Often external assessors; clients increasingly demand risk assessment evidence |
Vendor chains are where this breaks down in practice. Your business associate questionnaire should ask for the date and scope of the vendor’s last risk analysis, not just a signed agreement, because the Change Healthcare incident demonstrated how one associate’s gap becomes everyone’s breach. CISA’s healthcare sector guidance makes the same point from the infrastructure side.
A Working HIPAA Risk Assessment Template
A usable HIPAA risk assessment template is a scoring structure, not a form to initial. Anchor yours to the general template library, then rate each threat-vulnerability pair on likelihood and impact so the risk level falls out arithmetically rather than by feel. The bands below keep ratings defensible.
| Risk level | Definition | Response expectation |
| High | Likely occurrence with significant harm to ePHI or operations | Immediate remediation plan with owner and deadline |
| Medium | Plausible occurrence with moderate, recoverable harm | Scheduled remediation within the review cycle |
| Low | Unlikely occurrence with minimal harm | Accept and monitor; document the rationale |
| TBD | Insufficient information to rate | Investigate within 30 days; never leave TBD in a year-end risk assessment |
The checklist that accompanies the template covers the three safeguard families: administrative measures such as workforce training and contingency planning, physical measures such as facility access and device controls, and technical measures such as encryption, access control, and audit logging, per the Security Rule’s structure. Score coverage honestly; ISO 27001 alignment helps larger programs map both at once.
Common HIPAA Risk Assessment Questions Practitioners Ask
What is a HIPAA risk assessment?
It is the documented, organization-wide analysis of risks to electronic protected health information required by 45 CFR 164.308(a)(1)(ii)(A). The assessment identifies where ePHI lives, what threatens it, how likely and damaging each threat is, and which safeguards respond. It is the foundation every other Security Rule control builds on.
Who is responsible for conducting a HIPAA risk assessment?
The covered entity or business associate itself; the duty cannot be delegated away. Organizations may hire external assessors to perform the work, but accountability, documentation, and follow-through remain with the regulated entity. Security officers typically own the process, with executives on the hook for funding the fixes it identifies.
How often should a HIPAA risk assessment be done?
The rule says the analysis must be kept current rather than naming an interval, and OCR expects at least annual review in practice. Reassess immediately after material changes: new systems, mergers, breaches, or major workflow shifts. The proposed 2026 Security Rule update would make the annual expectation explicit.
What is the difference between a HIPAA risk assessment and a compliance assessment?
The risk assessment analyzes threats and vulnerabilities to ePHI and prioritizes safeguards; it looks outward at what could go wrong. A compliance assessment audits your policies, procedures, and practices against every Privacy, Security, and Breach Notification Rule requirement; it looks inward at whether you meet the standards. You need both.
Is the free SRA Tool enough for a HIPAA risk assessment?
For small and mid-sized practices, the ONC and OCR SRA Tool provides a legitimate, guided path through the required elements. Larger or more complex organizations outgrow it quickly because multi-site inventories, medical devices, and vendor chains need deeper treatment. Whatever tool you use, the documentation and follow-through determine defensibility.
Do business associates need their own HIPAA risk assessment?
Yes: business associates carry the Security Rule risk analysis duty directly, independent of their clients’ assessments, and several Risk Analysis Initiative settlements have named business associates specifically. Subcontractors inherit the same obligation downstream. Covered entities increasingly demand assessment evidence during vendor due diligence, so the document doubles as a sales asset.
What does a HIPAA risk assessment cost?
Small practices using the SRA Tool spend staff time rather than fees; external assessments for clinics commonly run four to five figures, and enterprise engagements more. Benchmark that against healthcare’s $7.42 million average breach cost in IBM’s 2025 research and the multi-year corrective action plans OCR attaches to settlements.
Where Assessments Fail OCR Scrutiny
| Pitfall | Root cause | Remedy |
| Partial ePHI inventory | Shadow systems, devices, and backups never mapped | Full data-flow mapping before any risk analysis scoring starts |
| Checklist without analysis | Template filled in; likelihood and impact never judged | Score every threat-vulnerability pair and rank results |
| No documentation trail | Work done verbally or in spreadsheets nobody kept | Versioned reports with methods, findings, and decisions |
| Assessment without treatment | Findings never became a funded remediation plan | Feed the risk register; track fixes to closure |
| One-and-done timing | Assessment aged past systems and staff changes | Annual cycle plus change-triggered reviews |
| Vendor blind spot | Business associates assumed compliant, never verified | Assessment evidence required in due diligence and renewals |
The 2026 Security Rule Reset and What to Do Before It Lands
Finalization of the Security Rule update is the event to plan around. The proposal removes the addressable escape hatch, mandates the inventory and mapping many entities skipped, and starts a 240-day compliance clock on publication. Entities that modernize their assessment process now will treat the final rule as confirmation rather than crisis.
Enforcement momentum will not wait for the rulemaking. The Risk Analysis Initiative continued under the new administration, and its settlement pattern tells you the first document requested after any breach report. Pair your assessment with the healthcare KRIs that show whether controls keep working between annual cycles.
Treat the assessment as the entry point to a wider healthcare risk management framework rather than a compliance island. The same inventory feeds data integrity work, incident response, and NIST CSF alignment, which is exactly the consolidation the proposed rule rewards. One dataset, four obligations served.
If your last analysis predates the Change Healthcare breach, that two-year gap is itself the audit finding now. We build OCR-defensible assessments, registers, and remediation plans for healthcare compliance teams; review our services and contact us before the 240-day clock starts running.

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.