The HIPAA Security Rule requires a documented, periodic risk analysis and a risk management plan at 45 CFR 164.308(a)(1)(ii)(A) and (B). Both covered entities and business associates must comply since the 2013 Omnibus Rule (Source: HHS OCR HIPAA Security Rule, 2026). The assessment must cover all ePHI systems, vendors, and workflows, and feed into a remediation plan with implementation timelines. Most healthcare organizations conduct a full assessment annually with quarterly reviews on high-risk systems.
Last verified: Sep 14, 2026.
At a glance
- HIPAA Security Rule mandates risk analysis + risk management plan
- Three safeguard categories: Administrative, Physical, Technical
- Covers covered entities and business associates since 2013 Omnibus
- Annual full assessment + quarterly high-risk system reviews typical
- HHS OCR audit protocol checks for completeness across ePHI scope
The HIPAA risk assessment template
A HIPAA risk assessment has five core sections that map to the Security Rule's structure. Most templates combine NIST SP 800-66 Rev 2 methodology with HHS OCR's audit protocol to produce a deliverable that satisfies both regulatory and audit requirements.
| Section | Content | Source |
|---|---|---|
| 1. Scope definition | Systems, locations, vendors, workflows that handle ePHI | HIPAA Security Rule §164.308(a)(1)(ii)(A) |
| 2. Asset inventory | All hardware, software, data stores, services that create, receive, maintain, or transmit ePHI | HHS OCR audit protocol §C.01 |
| 3. Threat catalog | Reasonably anticipated threats: ransomware, insider threat, phishing, equipment loss, vendor breach | NIST SP 800-66 Rev 2 |
| 4. Vulnerability assessment | Unpatched systems, weak authentication, missing encryption, inadequate training | NIST SP 800-66 Rev 2 |
| 5. Risk rating & treatment | Likelihood × impact matrix, residual risk after controls, treatment plan | HIPAA Security Rule §164.308(a)(1)(ii)(B) |
Source: HHS OCR HIPAA audit protocol and NIST SP 800-66 Rev 2, 2026.
HIPAA safeguard categories and required controls
The HIPAA Security Rule organizes safeguards into three categories with required and addressable specifications. Required means you must implement the specification. Addressable means you must either implement it or document why an alternative approach is reasonable and appropriate.
| Category | Examples | Required or Addressable |
|---|---|---|
| Administrative | Security management process, workforce security, training, contingency planning, evaluation | Mixed (security management and training are required) |
| Physical | Facility access controls, workstation use, workstation security, device and media controls | Mixed |
| Technical | Access control, audit controls, integrity, person authentication, transmission security | Mixed (access control and audit controls are required) |
Source: 45 CFR 164.308-164.312, 2026.
How to conduct the assessment
A HIPAA risk assessment has six iterative phases. Skip phases or treat them as one-off exercises and the assessment fails HHS OCR's completeness check. Plan for 4 to 8 weeks of effort for a mid-size healthcare organization with 5 to 20 ePHI systems.
| Phase | Activities | Duration |
|---|---|---|
| 1. Planning | Define scope, assemble team, secure executive sponsorship | 1 week |
| 2. Data collection | Inventory systems, interview workforce, collect documentation | 1-2 weeks |
| 3. Threat & vulnerability analysis | Map threats to assets, identify vulnerabilities, score likelihood × impact | 1-2 weeks |
| 4. Risk evaluation | Determine risk levels, prioritize by residual risk, identify gaps | 1 week |
| 5. Risk treatment | Document mitigation strategies, assign owners, set timelines | 1 week |
| 6. Reporting | Compile risk register, executive summary, management presentation | 1 week |
Source: NIST SP 800-66 Rev 2 implementation guidance, 2026.
Common gaps in HIPAA risk assessments
HHS OCR audit findings most often cite these gaps. Use the list to pressure-test your assessment before OCR does.
| Gap | Why OCR Cites It |
|---|---|
| Incomplete ePHI inventory | Missing cloud services, vendors, or workflows where ePHI is handled |
| No risk tolerance documented | Risk ratings without organizational risk tolerance context |
| Vendor risk not assessed | Business associates handling ePHI without documented risk review |
| Encryption not addressed | Addressable specification addressed by saying 'not reasonable and appropriate' without justification |
| Workforce training gaps | Annual training not refreshed or completion not tracked |
| Missing risk management plan | Risk assessment exists but no implementation timeline or owner |
Source: HHS OCR enforcement actions and audit findings, 2026.
Internal links
See related compliance guides: HIPAA compliance cost, SOC 2 audit prep, and GDPR DPO hire cost.
FAQs
See FAQ section above for HIPAA risk assessment requirements, safeguard categories, business associate obligations, and HHS OCR audit protocol guidance.
HHS OCR audit protocol and findings patterns
HHS Office for Civil Rights publishes an audit protocol that specifies what auditors look for. Understanding the protocol helps prioritize remediation effort.
| Audit Area | Common Findings | Severity |
|---|---|---|
| Risk analysis completeness | Missing systems, vendors, use cases | Critical |
| Risk management plan | No implementation timeline or owner | Critical |
| Access controls | Missing access reviews, no emergency access procedures | Critical |
| Audit controls | Insufficient log retention, no log review | High |
| Integrity controls | No mechanism to verify ePHI integrity | High |
| Transmission security | Unencrypted email, weak TLS configurations | High |
| Workforce training | Annual training not refreshed | Moderate |
Source: HHS OCR HIPAA audit protocol and enforcement actions, 2026.
FAQ expansion
Q: What is the difference between required and addressable specifications? HIPAA Security Rule uses "required" (must implement) and "addressable" (must implement or document why an alternative is reasonable and appropriate). Addressable does not mean optional — it means the implementation decision requires documented analysis.
Q: How long does a HIPAA risk assessment take? A complete HIPAA risk assessment typically takes 6-12 weeks for a mid-size healthcare organization. The schedule driver is data collection and stakeholder interviews. Phased approaches (initial scope, then expand) can compress timelines.
Q: Does the risk assessment need to cover all business associates? Yes. The HIPAA risk assessment must include all systems, vendors, and workflows where ePHI is created, received, maintained, or transmitted. This includes business associate relationships, cloud services, mobile devices, and remote access scenarios.






