

OCR Ready HIPAA Risk Assessment for Small U.S. Practices in 90 Days
A written, accurate, and thorough HIPAA risk analysis is required under 45 C.F.R. § 164.308(a)(1)(ii)(A). If you have not started one, or your last version predates a system change, begin now: inventory every location that touches electronic protected health information, rate the threats against it, and assign a named owner and deadline to each fix. That inventory, the risk ratings, and the remediation plan are the minimum deliverables OCR expects to see.
TL;DR:
- An accurate HIPAA risk analysis must cover every system and vendor that handles electronic protected health information, including cloud storage and mobile devices.
- The analysis should identify specific threats, document existing controls with evidence, and provide rated risks with clear rationales, not just checklist answers.
- A thorough assessment requires named assets, detailed control evidence, and a documented remediation plan with assigned owners, deadlines, and verification steps.
- Using the HHS/ONC SRA tool aids organization but should be supplemented with external evidence, named systems, and site-specific vulnerabilities beyond the questionnaire.
- Fast progress involves quick technical fixes within 30 days, completing inventory and evidence by 60 days, and closing high and medium risks by 90 days, with ongoing annual reviews.
Table of Contents
Table of Contents
- What the Law Requires for a HIPAA Risk Assessment
- How to Conduct a HIPAA Risk Assessment Step by Step
- Using the HHS/ONC SRA Tool the Right Way
- What Documents Does OCR Ask to See in an Audit?
- Where HIPAA Risk Assessments Fail Under OCR Review
- Turning Risk Findings Into a Remediation Program
- Your 30/60/90-Day HIPAA Compliance Checklist
- The tekRESCUE Perspective on Audit-Ready Risk Analysis
- How tekRESCUE Helps You Close the Compliance Gap
- Where to Verify the Rules Yourself
- Sources
- FAQ
What the Law Requires for a HIPAA Risk Assessment
The regulation itself is short. It requires covered entities and business associates to “conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability” of electronic protected health information. Two words carry the weight of that sentence: accurate and thorough. HHS guidance makes clear those words are not decorative. They set a standard that a checklist alone rarely satisfies.
Scope is where most practices trip first. An accurate risk analysis covers all ePHI, not just the electronic health record. That means the EHR platform, backup targets, cloud storage buckets, billing software, practice management systems, mobile devices used by staff, and every vendor with access to patient data through an integration or a support contract. Miss one data flow, and the analysis is incomplete by definition, regardless of how detailed the rest of it is.

When OCR reviews a risk analysis during an investigation or the Risk Analysis Initiative, it applies a consistent set of evaluation criteria: does the analysis cover the full scope of ePHI, does it identify realistic threats and vulnerabilities, does it document existing controls, and does it assign a defensible likelihood and impact rating to each risk with a rationale behind it? Auditors are not grading effort. They are checking whether the document could stand up to a claim that a breach was foreseeable and preventable.
That enforcement emphasis has shifted in recent years toward the quality of the documentation itself rather than whether a risk analysis merely exists on paper. A five-page generic template with no named systems will not satisfy an OCR reviewer the way a document naming your specific EHR vendor, backup provider, and remediation dates will.
How to Conduct a HIPAA Risk Assessment Step by Step
A HIPAA security risk assessment is a process, not a form. Here is the sequence that maps directly to what OCR checks for.
- Define scope and build the asset inventory. List every system, device, and vendor that creates, stores, transmits, or receives ePHI. Name them specifically: “Epic EHR, version 2025,” “Datto backup appliance,” “Verkada camera system,” not “clinical software” or “cloud storage.”
- Identify threats and vulnerabilities. Work through categories systematically: ransomware and phishing, lost or stolen devices, misconfigured cloud storage permissions, unpatched software, insider error, and third-party vendor exposure.
- Document current controls. For each asset, record what is actually in place, multifactor authentication, encryption at rest and in transit, firewall rules, monitoring, backup frequency, and attach evidence, not a claim that a control “exists.”
- Assess likelihood and impact. Rate each threat-vulnerability pairing using either a qualitative scale (low, medium, high) or a quantitative scoring model. Either is acceptable to HHS as long as the rationale behind each rating is written down.
- Build the risk register and remediation plan. Every identified risk needs an owner, a deadline, and a verification step confirming the fix actually happened.
- Set your reassessment cadence. Annual review is the floor. New EHR modules, a new vendor, a ransomware incident, or a staffing change in IT should each trigger an interim update.
The threats worth documenting fall into a few recurring buckets:
- Ransomware delivered through phishing emails or unpatched remote access software
- Lost or stolen laptops and phones that were not encrypted
- Misconfigured cloud storage or EHR access permissions granting broader access than a role requires
- Insider error, such as emailing patient records to the wrong recipient
- Vendor and business associate risk, where a third party’s weak security becomes your breach
Likelihood and impact ratings only hold up under review if the rationale is written, not implied. “High likelihood” needs a sentence explaining why, prior incidents, industry threat data, or a known unpatched vulnerability, and the same goes for impact.
Pro Tip: Assign risk ratings as a team, not solo. A single administrator’s gut-check rating looks arbitrary to an auditor; a rating discussed with your IT lead and documented with two or three sentences of rationale looks defensible.
Using the HHS/ONC SRA Tool the Right Way
The Security Risk Assessment Tool, built jointly by HHS and the Office of the National Coordinator for Health Information Technology, is a free, Windows-based application designed specifically for small and medium-sized providers who need structure for a first risk assessment. It walks you through a wizard-style questionnaire, generates section summaries, stores everything locally on your machine, and includes a remediation plan area to track fixes.

It is a genuinely useful starting scaffold. It is not, on its own, proof of compliance. ONC states plainly that the tool is informational and does not guarantee that your organization meets HIPAA Security Rule requirements. The SRA Tool User Guide goes further, warning that the tool may not capture every site-specific threat and instructing users to document any unaccounted-for vulnerabilities outside the built-in questionnaire.
Use it to organize your thinking, then supplement it with:
- Named asset lists (specific EHR version, backup vendor, cloud storage provider) rather than the tool’s generic category labels
- Vulnerability scan results or configuration screenshots attached as external documents, which the tool’s User Guide explains how to link into each section
- Dated evidence showing when a control was verified, not just that it was selected on a questionnaire
The SRA Tool receives periodic updates, so confirm you are working from the current version before you start rather than a copy downloaded years ago.
What Documents Does OCR Ask to See in an Audit?
If OCR opens an investigation or audit, it requests a specific stack of artifacts, not a verbal summary of your compliance posture. Have these assembled and current:
- The written risk analysis itself, dated and version-controlled
- The risk register showing each identified risk, its rating, and its remediation status
- The remediation plan with owners and deadlines
- The full asset inventory, named specifically
- Signed Business Associate Agreements for every vendor with ePHI access
- Staff training logs showing dates and topics covered
- Audit log reviews and incident logs
Present evidence the way you would for a compliance officer sitting across the table: dated screenshots of configuration settings, ticket numbers showing when a patch was applied, and a signed cover page listing the preparer’s name and role. Retain every version for a minimum of six years, and keep dated copies rather than overwriting the prior year’s file. A history of updated analyses shows an evolving compliance posture; a single undated document looks static and unconvincing.
Where HIPAA Risk Assessments Fail Under OCR Review
The failures OCR cites most often are not exotic. They are the same handful of gaps repeated across enforcement actions.
- Generic asset labels. “Cloud storage” and “clinical software” instead of the actual vendor, product, and version name
- Questionnaire answers with no technical backup. Marking “encryption: yes” with nothing showing how or when it was verified
- No linkage between a risk and an action. A risk register that lists problems but never assigns an owner, deadline, or resolution
- Thin control evidence. Claiming multifactor authentication is enforced without a configuration screenshot or policy document to back it
- Stale assessments. An analysis that has not been touched since a new EHR module or vendor was added
Pro Tip: Before you file your risk analysis away, ask one question of every line item: could a stranger reading this in twelve months tell exactly what system it refers to and what was done about it? If not, name the system and finish the sentence.
Turning Risk Findings Into a Remediation Program
An assessment that never converts into action is a liability, not a shield. Once your risk register is built, operationalize it.
- Prioritize by combining impact, likelihood, and cost. Fix the high-impact, high-likelihood, low-cost items first, encrypting a laptop fleet or enabling multifactor authentication usually beats a six-month infrastructure overhaul in return on effort.
- Assign an owner, a budget line, and a deadline to every risk. A risk with no name attached to it will not get fixed.
- Require verification evidence before closing a risk, a screenshot, a signed ticket, or a scan result confirming the fix took effect.
- Fold vendor risk into your Business Associate Agreements. If a vendor’s weak security created the risk, the remediation plan should include a documented conversation with that vendor, not just an internal fix.
- Set a monitoring cadence for log reviews, patch cycles, and control effectiveness checks so the same risk does not silently reappear next year.
Your 30/60/90-Day HIPAA Compliance Checklist
Small practices without a dedicated compliance department make faster progress with quick technical wins first, then close documentation gaps behind them.
- First 30 days: Enable multifactor authentication everywhere it is missing, confirm device encryption on every laptop and mobile device, and verify backups actually restore
- Days 31 to 60: Complete the named asset inventory, collect configuration evidence for existing controls, and confirm signed Business Associate Agreements are on file for every vendor
- Days 61 to 90: Finish remediation for every high and medium risk, and document the verification evidence for each
- Ongoing: Reassess annually at minimum, and immediately after any new system, vendor, or security incident
| Timeframe | Focus | Example action |
|---|---|---|
| 30 days | Quick technical wins | Enable MFA, verify backup restores |
| 60 days | Inventory and evidence | Name every asset, collect config screenshots |
| 90 days | Remediation | Close high and medium risks with verification |
| Ongoing | Reassessment | Annual review plus event-triggered updates |
The tekRESCUE Perspective on Audit-Ready Risk Analysis
Most practices do not fail a HIPAA risk assessment because they skipped it. They fail because the questionnaire got completed and nobody went back to name the systems, attach the evidence, or close the loop on remediation. That gap between “we did an assessment” and “we can prove it” is where OCR findings live.
A technology partner earns its place by doing the unglamorous work: building the real asset inventory instead of a generic one, pulling configuration evidence from your actual systems, and running the remediation project so risks do not sit open for a year. Handle the assessment in-house if you have the staff time and the technical depth to document controls properly. Bring in a partner when the gap is bandwidth, not intent. tekrescue’s work in HIPAA-focused cybersecurity and compliance support for small and medium providers is built around exactly that gap.
— Randy Bryan
How tekRESCUE Helps You Close the Compliance Gap
Assembling a defensible HIPAA risk analysis takes more than filling out a questionnaire once a year. tekrescue works with small and medium healthcare providers, CPA firms, and other regulated businesses across Central Texas to build the named asset inventories, collect the configuration evidence, and manage the remediation timeline that OCR actually looks for, rather than leaving that work half-finished after the SRA Tool is closed. Where a generic template stalls at “we identified the risk,” tekrescue’s managed IT and cybersecurity services carry that risk through to a documented, verified fix with an owner and a deadline attached. If your last risk analysis is more than a year old, or you have never completed one with named systems and real evidence, start with tekrescue’s cybersecurity risk assessment checklist and request a consult to see exactly where your documentation stands before an auditor asks.
Where to Verify the Rules Yourself
Consult the primary sources directly rather than relying on secondhand summaries. HHS’s guidance on risk analysis explains the required elements in full, the ONC Security Risk Assessment Tool page hosts the current download, and its User Guide covers operational details section by section.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
FAQ
Is a Risk Assessment Required Under HIPAA?
Yes. The HIPAA Security Rule requires every covered entity and business associate to conduct an accurate and thorough written risk analysis under 45 C.F.R. § 164.308(a)(1)(ii)(A), with no exception for practice size.
How Often Does HIPAA Require a Risk Assessment?
HHS treats annual review as the minimum, but a new EHR system, a new vendor with ePHI access, or a security incident should each trigger an updated assessment immediately rather than waiting for the next annual cycle.
What Does an Effective HIPAA Risk Assessment Look Like?
An effective assessment names specific systems and vendors instead of generic categories, documents evidence for every control claimed, and assigns a rated risk to a named owner with a deadline and a verification step, not just a checklist marked complete.
Does the HHS SRA Tool Guarantee HIPAA Compliance?
No. ONC states the SRA Tool is informational and helps structure an assessment for small and medium providers, but it must be supplemented with site-specific documentation and evidence to meet the “accurate and thorough” standard.
Should a Small Practice Handle a Risk Assessment In-House or Hire Help?
In-house works when staff have the time and technical depth to document controls with real evidence; a partner like tekrescue helps most when the gap is bandwidth or when past assessments lacked named assets and remediation follow-through.
Recommended
Table of Contents









