Pillar Guide

Last reviewed: September 15, 2026

HIPAA Risk Analysis for Small Practices: A Step-by-Step Guide

A comprehensive guide to identifying ePHI threats and vulnerabilities, conducting an accurate and thorough HIPAA security risk analysis, and building an audit-ready risk management plan.

A HIPAA security risk analysis can sound like something designed for hospitals with cybersecurity departments, compliance teams, and large IT budgets.

It isn't.

The HIPAA Security Rule requires covered entities and business associates to perform an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI). HHS describes risk analysis as a foundational part of Security Rule compliance because the risks you identify help determine which safeguards are reasonable and appropriate for your organization.

For a small medical or dental practice, the process does not need to look like an enterprise cybersecurity program. HHS specifically recognizes that smaller organizations have different environments and may need different security measures than larger organizations. HHS and the Office for Civil Rights (OCR) also provide a Security Risk Assessment Tool intended to help small and medium-sized healthcare practices and business associates perform an assessment.

What matters is that your practice can demonstrate that it has identified where its ePHI exists, considered realistic threats and vulnerabilities, evaluated its existing protections, identified meaningful risks, and taken appropriate steps to manage those risks.

A HIPAA risk analysis identifies where your practice's electronic protected health information (ePHI) exists, the threats and vulnerabilities that could affect it, the safeguards already in place, and the risks that require additional action.

A risk analysis is not simply another document to keep in your HIPAA binder. It informs much of the rest of your security program.

What Is a HIPAA Risk Analysis?

Under 45 CFR § 164.308(a)(1)(ii)(A), a HIPAA risk analysis is the foundational implementation specification of the Security Management Process standard. Its purpose is to systematically evaluate how your practice handles electronic protected health information across its entire operational footprint.

For example, imagine a five-person practice discovers during its assessment that patient information is stored in its EHR, transmitted through secure email, accessible from several laptops, backed up by a cloud provider, and occasionally accessed remotely.

The practice might then identify risks such as:

  • an employee account being compromised through phishing;
  • a laptop containing or accessing ePHI being lost or stolen;
  • an unsupported computer remaining connected to the practice network;
  • a former employee retaining system access;
  • inadequate backups preventing recovery after ransomware;
  • a vendor accessing ePHI without appropriate safeguards.

Those findings give the practice something concrete to address.

Why Is a HIPAA Risk Analysis Required?

That connection between risk analysis and risk management is important. The Security Rule requires both an assessment of risks and vulnerabilities and implementation of security measures sufficient to reduce identified risks and vulnerabilities to a reasonable and appropriate level.

OCR continues to enforce this requirement actively across organizations of all sizes.

In July 2026, OCR announced a $552,250 settlement with OSF Healthcare System following a ransomware investigation involving PHI belonging to 53,907 individuals. Among the potential violations identified by OCR was failure to conduct an accurate and thorough risk analysis. The corrective action plan requires OSF to conduct such an analysis and develop and implement a risk-management plan addressing the risks and vulnerabilities it identifies.

The lesson for a small practice isn't that it needs the cybersecurity resources of a large health system.

It's that identifying a problem is only the beginning. Your compliance process should connect identified risks with the work performed to reduce them. Demonstrating compliance during an investigation or audit requires showing how identified vulnerabilities lead to operational safeguards.

How to Conduct a HIPAA Risk Analysis

Conducting a thorough HIPAA security risk analysis does not require specialized consulting software. It requires a structured, step-by-step methodology that systematically accounts for your practice's data, systems, vulnerabilities, and safeguards.

Step 1: Identify Where Your ePHI Exists

Before you can evaluate risk, you need to understand what you are protecting.

Start by identifying the systems, devices, services, and locations that create, receive, maintain, or transmit electronic protected health information.

Depending on your practice, these might include:

  • electronic health record systems;
  • practice-management and billing systems;
  • desktop and laptop computers;
  • mobile devices;
  • email systems;
  • patient portals;
  • cloud storage and backup services;
  • imaging systems;
  • telehealth platforms;
  • electronic fax services;
  • connected medical or dental equipment;
  • third-party applications integrated with your EHR;
  • business associates that maintain ePHI on your behalf.

Don't limit the exercise to equipment physically located inside the office.

If a cloud provider, billing company, EHR vendor, backup service, or other business associate maintains your practice's ePHI, that information still belongs within the scope of your security analysis. Practices must ensure they maintain executed Business Associate Agreements (BAAs) with every vendor handling protected data.

A useful question is:

“If we needed to determine everywhere our electronic patient information exists or travels, could we do it?”

If the answer is no, inventory is the place to start.

Step 2: Identify Threats and Vulnerabilities

Next, consider what could reasonably threaten the confidentiality, integrity, or availability of that ePHI.

HHS guidance calls for organizations to identify and document reasonably anticipated threats as well as vulnerabilities that could be triggered or exploited by those threats.

A threat is something capable of causing harm.

A vulnerability is a weakness that could allow the threat to cause that harm.

For example:

Scenario 1: Account Takeover

Threat: An attacker steals an employee's password through phishing.

Vulnerability: The employee's account does not use multi-factor authentication.


Scenario 2: Device Theft

Threat: A laptop is stolen from an employee vehicle or office.

Vulnerability: Sensitive information on the device is not adequately protected with full-disk encryption.


Scenario 3: System Extortion

Threat: Ransomware makes the practice's clinical systems unavailable.

Vulnerability: Backups are incomplete, inaccessible, or have never been tested for restoration.

The objective isn't to imagine every theoretical cyberattack. Focus on threats that are reasonably relevant to your actual environment.

Step 3: Review Existing Safeguards

A risk analysis shouldn't assume your practice has no protections.

Document what is already in place. That could include:

  • unique user accounts;
  • multi-factor authentication;
  • encryption;
  • automatic screen locking;
  • endpoint protection;
  • software updates and patching;
  • backups;
  • access termination procedures;
  • workforce security training;
  • physical access controls;
  • incident-response procedures;
  • business associate agreements.

HHS guidance specifically calls for assessing existing security measures and considering whether those measures are properly configured and actually being used.

That last part matters:

  • Having an MFA feature available isn't the same as having MFA enabled.
  • Having backups isn't the same as knowing they can be restored.
  • Having an employee-termination policy isn't the same as documenting that access was actually removed when someone left.

Verifying that operational safeguards are active connects directly to your overall HIPAA Administrative Safeguards and regular workforce training.

Step 4: Determine Likelihood and Impact

Not every risk deserves the same priority.

For each meaningful threat-and-vulnerability combination, consider two basic questions:

• How likely is this to happen?

• How serious would the consequences be if it did?

HHS guidance expects organizations to consider both the probability of potential risks and their potential impact on the confidentiality, integrity, and availability of ePHI. Organizations may use qualitative or quantitative approaches.

A small practice does not necessarily need an elaborate mathematical model.

A practical rating such as Low / Medium / High likelihood combined with Low / Medium / High impact can help establish priorities if the methodology is applied consistently and documented.

For example, an unused computer isolated in storage might represent a different level of concern from an internet-accessible employee account without appropriate protection.

The point is to make a reasoned assessment—not simply label everything “high risk.”

Step 5: Document the Results

A risk analysis should produce documentation.

Your records should make it possible to understand:

  • what systems and ePHI were considered;
  • what threats were identified;
  • what vulnerabilities were identified;
  • what safeguards were already in place;
  • how likelihood was assessed;
  • how potential impact was assessed;
  • what resulting risk level was assigned;
  • what issues require further action.

This documentation matters because HIPAA compliance needs to be demonstrable.

OCR's audit protocol, for example, calls for auditors evaluating the risk-analysis requirement to obtain and review relevant documentation and evaluate its contents against the requirement for an accurate assessment of risks and vulnerabilities to ePHI. Reviewing our guide to HIPAA audit preparation can help your team understand how regulators inspect this documentation.

Step 6: Create a Risk Management Plan

One of the biggest mistakes a practice can make is treating completion of the assessment as completion of the work.

Suppose your analysis identifies five meaningful problems:

  1. Former employee accounts aren't consistently disabled.
  2. MFA isn't enabled for remote access.
  3. One office computer is running unsupported software.
  4. Backup restoration hasn't been tested.
  5. The practice cannot locate the BAA for a cloud vendor.

Those findings should become manageable remediation activities.

For each issue, consider documenting:

  • the risk;
  • the planned mitigation;
  • who is responsible;
  • target completion date;
  • current status;
  • completion evidence.

Some issues may require immediate action. Others may reasonably take time.

What matters is that identified risks don't simply disappear into a completed assessment.

The July 2026 OSF corrective action illustrates this relationship clearly: OCR required both an accurate and thorough risk analysis and a risk-management plan designed to address and mitigate the risks and vulnerabilities identified through that analysis.

Risk Analysis vs. Risk Management

Risk AnalysisRisk Management
Identifies risks and vulnerabilitiesDetermines how risks will be addressed
Evaluates likelihood and impactImplements reasonable safeguards
Produces documented findingsProduces remediation actions
Prioritizes risksAssigns owners, due dates, and mitigation activities
Answers “What could go wrong?”Answers “What are we going to do about it?”

Risk analysis and risk management are distinct but connected specifications within the HIPAA Security Management Process standard (45 CFR § 164.308(a)(1)). While risk analysis focuses on identifying and assessing potential threats and vulnerabilities to ePHI, risk management requires implementing security measures sufficient to reduce those risks to a reasonable and appropriate level. Completing the analysis alone does not satisfy your compliance obligations under the Security Rule; the findings must drive ongoing, documented operational safeguards.

Turn identified risks into trackable compliance work.

HIPAA Assistant helps small practices organize compliance tasks, document completed work, and maintain evidence for audit readiness.

Step 7: Keep Evidence of Remediation

If the practice replaces an unsupported computer, retain appropriate evidence.

If MFA is enabled, document the change.

If workforce access is reviewed, retain the review.

If a policy is revised, preserve the updated policy and its history (learn more about maintaining current HIPAA Policies and Procedures).

If backup restoration is tested, document the test and result.

This changes the compliance story from:

“We identified this risk.”

to:

“We identified this risk, assigned corrective action, addressed it, and can demonstrate what we did.”

That distinction becomes particularly important if the practice later experiences an incident or is asked to demonstrate its security practices. Keeping thorough evidence is essential for regulatory review—consult our HIPAA Audit Evidence Checklist for documentation retention guidelines.

HIPAA Security Rule documentation requirements generally require specified documentation to be maintained for six years after the later of its creation date or the date it was last in effect (45 CFR § 164.316(b)(2)(i)). HHS also emphasizes periodic review and updating when environmental or organizational changes affect ePHI security.

Step 8: Reassess Risk When Your Practice Changes

A risk analysis should not be treated as a document that is completed once and forgotten.

Your security environment changes. You might:

  • replace your EHR;
  • add a cloud service;
  • begin using an AI medical scribe;
  • open another location;
  • hire remote employees;
  • change your IT provider;
  • introduce new medical equipment;
  • suffer a security incident;
  • discover a new vulnerability.

HHS states that regulated entities must periodically evaluate security measures, modify them as necessary, and regularly reevaluate potential risks to ePHI.

That means risk analysis should function as part of an ongoing security-management process rather than an annual paperwork exercise disconnected from the rest of the practice. Small practices can maintain ongoing evaluation by utilizing a HIPAA internal audit checklist to catch operational changes early.

How Often Should a HIPAA Risk Analysis Be Performed?

The current HIPAA Security Rule does not establish a blanket requirement that every regulated entity perform a risk analysis once every 12 months.

HHS guidance describes risk analysis as an ongoing process and states that the Security Rule does not specify a fixed frequency. The appropriate frequency depends on the circumstances of the covered entity or business associate and changes to its operating environment.

While many healthcare organizations establish an annual reassessment schedule as an operational baseline, HIPAA requires an assessment whenever environmental or organizational changes occur that could affect the security of ePHI.

Relying solely on an annual calendar reminder does not fulfill HIPAA requirements if significant changes—such as adopting new telehealth software, switching IT vendors, or experiencing a ransomware scare—occur mid-year without a corresponding risk review.

Does HIPAA Require a Specific Risk Analysis Template?

No single template works for every organization.

HHS explicitly says its risk-analysis guidance is not intended to provide a one-size-fits-all compliance blueprint. Organizations should determine an appropriate approach based on their characteristics, technical capabilities, and operational environment.

That flexibility is particularly important for small practices.

A two-provider dental office and a 500-bed hospital should not be expected to have identical security programs.

They are, however, expected to take the requirement seriously and perform an assessment appropriate to their circumstances. HHS and the Assistant Secretary for Technology Policy / Office of the National Coordinator for Health Information Technology (ASTP/ONC) provide a downloadable Security Risk Assessment (SRA) Tool designed to help small and medium-sized providers evaluate their environment. Using that specific tool is voluntary, but your practice must be able to demonstrate an accurate and thorough assessment regardless of format.

What About the Proposed HIPAA Security Rule?

HHS has proposed substantial changes to strengthen the HIPAA Security Rule through a Notice of Proposed Rulemaking (NPRM).

These proposed changes contemplate more prescriptive cybersecurity requirements, including formalized annual risk analysis cadences, explicit asset inventories and network mapping, multi-factor authentication across expanded access points, data encryption standards, regular vulnerability scanning, and periodic penetration testing.

Important distinction: These proposed changes are part of an ongoing rulemaking process and are not the Security Rule currently in effect. They must not be confused with binding current law.

For today's compliance work, practices should focus on meeting existing requirements under 45 CFR Part 164 while following the rulemaking process and preparing for reasonable security improvements where appropriate.

HIPAA Risk Analysis Checklist

Before considering your risk-analysis process complete, make sure you can answer these questions:

  • Have we identified the systems, devices, applications, and vendors that create, receive, maintain, or transmit our ePHI?
  • Have we identified reasonably anticipated threats?
  • Have we identified vulnerabilities that could expose our ePHI to those threats?
  • Have we documented the safeguards currently in place?
  • Have we evaluated whether those safeguards are actually implemented and working?
  • Have we considered both likelihood and potential impact?
  • Have we documented our findings?
  • Have identified risks been assigned mitigation actions?
  • Can we demonstrate when remediation work was completed?
  • Do we have a process for reassessing risk when our environment changes?

If several of those answers are “no” or “I'm not sure,” the practice likely has more work to do.

What Happens After the Risk Analysis?

Small practices have limited people, time, and budgets. HIPAA's risk-analysis requirement does not change that reality.

The goal is not to predict every possible security incident or eliminate every conceivable risk.

The goal is to understand your actual environment, identify meaningful risks to your patients' electronic health information, make reasonable decisions about those risks, document those decisions, and follow through.

A strong compliance process therefore doesn't end with a completed risk assessment.

It creates a repeatable chain:

Understand your ePHI → identify risks → prioritize them → mitigate them → retain evidence → reassess when things change.

That is what turns a HIPAA risk analysis from a compliance document into an operational security process. Coupling risk management with ongoing audit log reviews and an organized HIPAA compliance checklist ensures your practice stays prepared throughout the year.

Frequently Asked Questions

Is a HIPAA risk analysis required?

Yes. Conducting an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) is a mandatory implementation specification under the HIPAA Security Rule (45 CFR § 164.308(a)(1)(ii)(A)) for all covered entities and business associates.

How often should a HIPAA risk analysis be performed?

The current HIPAA Security Rule does not establish a blanket requirement that every regulated entity conduct a risk analysis once every 12 months. HHS guidance emphasizes that risk analysis is an ongoing process. Reassessment is required periodically and whenever environmental or operational changes occur that could affect ePHI security—such as implementing new software, changing cloud vendors, upgrading hardware, or experiencing a security incident.

Is a HIPAA risk assessment the same as a risk analysis?

Yes. In healthcare operations and compliance conversations, the terms risk assessment and risk analysis are commonly used interchangeably. However, the official statutory and regulatory language in the HIPAA Security Rule specifically designates this process as a risk analysis.

What should a HIPAA risk analysis include?

A comprehensive HIPAA risk analysis must identify all locations where ePHI is created, received, maintained, or transmitted; identify reasonably anticipated physical, environmental, and human threats; identify technical and non-technical vulnerabilities; evaluate existing safeguards; assess the likelihood and potential impact of threats; assign prioritized risk levels; document findings; and feed directly into an actionable risk management plan.

Does HHS provide a Security Risk Assessment Tool?

Yes. The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR), in collaboration with the Assistant Secretary for Technology Policy / Office of the National Coordinator for Health Information Technology (ASTP/ONC), provides a downloadable Security Risk Assessment (SRA) Tool. The tool is designed to help small and medium-sized healthcare providers navigate Security Rule requirements, though its use is voluntary rather than legally mandatory.

Is a HIPAA risk analysis the same as a risk management plan?

No. A risk analysis identifies, prioritizes, and documents potential vulnerabilities and threats to ePHI (answering 'What could go wrong?'). A risk management plan is a separate required specification under 45 CFR § 164.308(a)(1)(ii)(B) that details the security measures, assigned owners, timelines, and corrective actions taken to mitigate those identified risks (answering 'What are we going to do about it?'). Both components are required.


Related resources

Make HIPAA compliance easier to manage

HIPAA Assistant helps small practices turn HIPAA requirements into guided workflows, documented activities, and audit-ready evidence.