Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

How to Do a HIPAA Risk Assessment (Step by Step)

July 13, 2026

A HIPAA risk assessment is a mandatory evaluation of how your practice protects electronic patient data from security threats, unauthorized access, and catastrophic loss. It is the foundational requirement of your compliance program. It is also the very first document federal investigators ask to see during an audit.

If you run a healthcare practice, a billing company, or any vendor business that handles patient data, you cannot achieve compliance without completing and documenting this process.

The wrong assumption. Many practice owners treat compliance as a vague it problem or assume their software vendors handle it automatically. That assumption is dangerous. The government expects the leadership of your organization to understand exactly where patient data lives, what risks threaten that data, and what specific safeguards are in place to protect it. You must have a formal record proving you have done this work.

This guide walks you through the exact methodology required to evaluate your practice. We will cover the core federal requirements, the step-by-step process to identify your vulnerabilities, and what an auditor expects to see when they review your records.

What a HIPAA Risk Assessment Is (And Why OCR Asks for it First)

HIPAA is the Health Insurance Portability and Accountability Act, a 1996 US federal law enforced by the HHS Office for Civil Rights (OCR). The law relies on three main rules for compliance work.

  • The Privacy Rule governs how data is used and disclosed.
  • The Breach Notification Rule dictates what happens when data is exposed.
  • The Security Rule governs the actual safeguards you must implement for electronic protected health information (ePHI).

To know which safeguards you need under the HIPAA Security Rule explained, you first have to understand where your specific risks are. That is what a HIPAA security risk assessment does.

It is not a generic it audit or a quick software scan. A proper HIPAA security rule risk analysis is a formal, documented process that identifies your ePHI, evaluates the threats against it, and rates the likelihood and impact of those threats materializing.

Why OCR prioritizes this one document. The HHS Office for Civil Rights makes the risk analysis the absolute center of their enforcement strategy. When an auditor knocks on your door or sends a letter after a patient complaint, the risk analysis is the single most-requested document in the investigation.

The enforcement data proves this point clearly. OCR’s recent HIPAA settlements share a consistent pattern: enforcement actions keep tracing back to the same root failure — an organization with no proper risk analysis.

The government views a missing risk assessment as evidence of willful neglect, and federal civil penalties are tiered by culpability. Here is what that exposure looks like:

Penalty exposureRough dollar figure
Minimum per individual violationAbout $145
Maximum per individual violationUp to $73,011
Willful neglect, annual cap per violation categoryAbout $2.19 million

Current inflation-adjusted amounts per 45 CFR Part 102.

You cannot build a defensible compliance program without knowing your risks. The assessment is the blueprint that tells you exactly what it controls, policies, and training your specific practice needs to survive an audit and protect your patients.

Step-by-Step: How to Conduct a HIPAA risk assessment

The federal government does not mandate one specific software platform or proprietary framework for your assessment. However, they do require a thorough, accurate, and documented evaluation. Most compliance professionals and managed IT providers use a NIST-aligned security risk assessment methodology to ensure every federal requirement is met.

See where you stand before you build a massive compliance binder: evaluate your current baseline with a free 2-minute HIPAA Risk-Check.

Here is the full process at a glance. The rest of this section walks through each step in detail.

  • Inventory every location where your ePHI is created, received, maintained, or transmitted.
  • Identify the threats and vulnerabilities that could compromise that data.
  • Assess the administrative, physical, and technical safeguards you already have in place.
  • Rate the likelihood and impact of every risk you identified.
  • Document your findings, your decisions, and the date of the assessment.
  • Remediate your security gaps, starting with the highest-risk items.
  • Review the assessment after any significant change and at least annually.
7 step process

1. Inventory Where Your ePHI Lives

You cannot protect data if you do not know you have it. The first step in any HIPAA risk assessment for small practices or large hospital networks is mapping your electronic protected health information.

PHI is individually identifiable health information held or transmitted in any form. ePHI is the electronic subset of that data. HHS recognizes 18 specific identifiers that can make health information identifiable.

These include obvious items like names, addresses, dates of birth, and Social Security numbers, as well as phone numbers, email addresses, medical record numbers, and biometric identifiers. Removing all 18 of these identifiers achieves “safe harbor” and de-identifies the data, meaning it is no longer subject to HIPAA rules.

ePHI locations to inventory. You must track every location where ePHI is created, received, maintained, or transmitted. This inventory must be comprehensive. Look at your electronic health record (EHR) system, your email accounts, your local servers, your cloud storage drives, and your daily backups.

You must also account for physical hardware, including physician laptops, employee mobile devices, USB drives, and specialized medical equipment that stores patient data.

Business associates. Do not forget your external partners. HIPAA applies to covered entities (healthcare providers, health plans, and clearinghouses) and their business associates.

A business associate is any vendor that creates, receives, maintains, or transmits PHI on your behalf. This includes your IT providers, billing companies, EHR vendors, shredding services, and cloud hosts.

You must document these vendors in your inventory because you are required to have a Business Associate Agreement (BAA) with each of them. A missing or unsigned BAA is itself a violation, since federal law requires a written contract with every business associate that handles ePHI on your behalf.

2. Identify Threats and Vulnerabilities

Once you know exactly where your patient data sits, you must figure out what could compromise it. This step requires formal ePHI threat and vulnerability identification.

A threat is any event or actor that could trigger a breach, unauthorized access, or data loss. Threats fall into three main categories.

Intentional threats include hackers, ransomware syndicates, and rogue employees stealing data.

Unintentional threats include a doctor leaving an unencrypted laptop at a coffee shop, an employee falling for a phishing email, or accidental file deletion.

Natural threats include environmental disasters like floods, fires, or prolonged power outages that destroy local servers.

A vulnerability is a flaw or weakness in your IT systems or business processes that a threat could exploit.

Common technical vulnerabilities include unpatched server software, weak passwords, and a lack of multi-factor authentication.

Common physical vulnerabilities might include a server room door that is left propped open or backup hard drives sitting on a receptionist’s desk.

You must document all reasonable threats and vulnerabilities for every system in your inventory that holds ePHI. The scale of modern threats is massive. The 2024 Change Healthcare hack exposed a staggering volume of patient records, becoming the largest healthcare data breach in US history. While your practice is smaller, the automated threats scanning the internet for vulnerabilities will target your network just as aggressively.

3. Assess Your Current Safeguards

Next, you must evaluate the security measures you already have in place to protect against the threats you just listed. The Security Rule explicitly requires you to implement three categories of protections — administrative, physical, and technical safeguards. You must document your current posture across all three areas.

Administrative safeguards are the policies and procedures that manage your security program. This includes your documented risk analysis, your workforce training program, and your access management rules.

HIPAA also requires you to formally designate a Privacy Officer and a Security Officer. These are the named, accountable owners of your compliance program (existing staff may hold these roles).

Physical safeguards cover the physical access to your facilities and devices. You must document your facility access controls, your workstation security policies, and your procedures for proper media disposal when retiring old computers.

Technical safeguards involve the actual it controls protecting the data on your network. This includes access controls with unique user IDs, audit logging to track who views what data, secure authentication, and transmission security.

A critical technical safeguard is encryption. You must evaluate whether your ePHI is encrypted at rest (on your hard drives) and in transit (when sent via email or uploaded to a portal).

Properly encrypted data whose key was not compromised is generally not considered “unsecured PHI,” so its loss is usually not a reportable breach. You can review a complete breakdown of these it controls in the HIPAA it requirements checklist.

Document what you are currently doing right. If your IT provider already encrypts all practice laptops and enforces strict password policies, record those existing safeguards in your assessment.

4. Rate the Likelihood and Impact of Risks

With your threats, vulnerabilities, and current safeguards documented, you must now calculate the actual risk level for each scenario. Risk is a calculation of two factors: how likely is this event to happen, and how bad would the damage be if it did?

Likelihood rating. You must assign a likelihood rating to each threat. For example, a ransomware attack exploiting an unpatched server might be rated “High” likelihood if you do not have a managed IT provider regularly updating your systems. A flood destroying your second-floor server room might be rated “Low” likelihood.

Impact rating. Next, assign an impact rating. If a primary database crashes and destroys ePHI without a working backup, the impact to patient care and your business operations is “Severe.” If a single encrypted laptop is stolen from a car, the impact is “Low” because the encryption safeguard prevents the data from being exposed.

Combined risk score. Combine these two ratings to generate an overall risk score for every item on your list. A high-likelihood, high-impact threat requires immediate attention and resources. A low-likelihood, low-impact threat might simply require ongoing monitoring.

5. Document Your Decisions and Findings

HIPAA risk assessment requirements mandate strict, formal documentation. Discussing your IT security in a staff meeting or having your it guy assure you that “everything is secure” does not count. You must create a permanent record of your findings.

Your final documentation should clearly list your ePHI assets, the identified threats and vulnerabilities, the safeguards currently in place, the calculated risk scores, and the exact date the assessment was performed. This document is the evidence you will hand to an OCR investigator if your practice is audited.

Technical translation for documentation. Many practice owners struggle with this step because they lack the technical vocabulary to describe their IT environment accurately.

LeadingIT operates the technical half of HIPAA for Illinois practices, handling the access controls, MFA, encryption, logging, tested backups, and monitoring as part of managed it. A competent managed service provider will help you produce the exact documentation an auditor asks for, translating your technical it setup into the compliance paperwork the government demands.

6. Remediate by Priority

Identifying your security gaps is only the first half of the compliance equation. You must actually fix the problems you found. This step transitions your risk assessment into a risk management plan.

Start with your highest-risk vulnerabilities. If your assessment reveals that your daily backups are failing or your staff email accounts lack multi-factor authentication, you must fix those critical issues immediately. Lower-risk items can be scheduled for remediation over the coming months.

Keep a detailed record of what you fix and when you fix it. The Security Rule includes both “required” safeguards (which must be implemented exactly as stated) and “addressable” safeguards.

Addressable does not mean optional. If you decide not to implement a specific addressable safeguard because it is technically unfeasible for your environment, you must document a valid alternative measure that achieves the exact same security goal. You cannot simply ignore an addressable safeguard.

7. Review on Change and At Least Annually

Compliance is an ongoing state you maintain, not a certificate you buy or a project you finish once. Business owners frequently ask how often a HIPAA risk assessment should be done to stay compliant.

The industry standard best practice is to conduct a full review of your assessment at least annually. However, the law requires you to update your assessment whenever your environment changes significantly.

Triggers for a mid-year assessment update include:

  • Migrating to a new electronic health record system
  • Moving your practice to a new office location
  • Replacing your core IT infrastructure
  • Experiencing a security incident

Your risk analysis must evolve as your practice evolves. If an auditor investigates a breach and finds that your most recent risk assessment is three years old and ignores your current software systems, they will treat it as if you have no assessment at all.

Risk Analysis vs. Risk Management Plan

Many business owners confuse the initial evaluation with the ongoing work required to fix the problems they find. They are two separate documents with two separate jobs, and you must have both to survive an audit.

QuestionRisk analysisRisk management plan
What it isThe diagnostic stepThe treatment
What it documentsThe formal record that identifies your vulnerabilities, rates your threats, and scores your current safeguardsYour documented strategy and timeline for actually fixing those vulnerabilities
What a gap signals to investigatorsA missing risk analysis is viewed as evidence of willful neglectFailing to fix known security gaps pushes your practice toward the willful neglect penalty tiers

OCR enforcement actions frequently target organizations that completed a thorough risk analysis but failed to act on the results. If your assessment shows that you have unencrypted laptops or missing BAAs, you cannot simply file the report away.

You must execute your risk management plan to implement encryption and sign those vendor agreements. The government expects that plan to be an active, living process where leadership regularly reviews progress on outstanding security tasks.

What Auditors Expect Your Documentation to Look Like

OCR investigations are typically triggered by a patient or employee complaint or an OCR-initiated compliance review. This can follow a reported breach or a proactive audit of your practice.

Breaches affecting 500 or more individuals draw scrutiny automatically. They must be reported to HHS and prominent media outlets in the affected area within 60 days.

When an investigator opens a case, the process is mostly a documentation request. They will ask for your risk analysis, policies, training records, access logs, incident records, and BAAs.

What auditors reject. Verbal assurances and ad hoc documentation do not count. Auditors expect a formal, dated report that clearly defines the scope of your ePHI environment.

Who must be named. The document must show exactly who owns the compliance program. HIPAA requires formally designating a Privacy Officer and a Security Officer. These named individuals are accountable for the accuracy of your records and must be clearly identified in your paperwork.

How to map safeguards. Your documentation must explicitly link your technical safeguards to the risks they address. If you identify ransomware as a high-impact threat, your documentation must list your access controls, multi-factor authentication, and tested backups as the mitigating controls.

See Where You Stand

Before you build a massive compliance binder, evaluate your current baseline. Free 2-minute HIPAA Risk-Check: 8 plain-English questions, your audit-readiness level and the gaps to fix. No sign-up to see your result.

Free HIPAA compliance self-assessment

Frequently Asked Questions

Does HIPAA require a risk assessment?

Yes. The HIPAA Security Rule legally requires all covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to their electronic protected health information.

How often should a HIPAA risk assessment be done?

Industry best practice dictates performing a full review at least annually. However, the law explicitly requires you to update your assessment whenever your environment changes significantly, such as when you adopt new software, move offices, or experience a security incident.

Do you legally have to do a risk assessment?

Yes. Skipping this requirement is a direct violation of federal law and is the single most common failure cited in government enforcement actions. A missing risk analysis is typically viewed by federal investigators as evidence of willful neglect.

What are the 5 things a risk assessment should include?

A compliant assessment must include a full inventory of where patient data lives, a list of potential threats and vulnerabilities, an evaluation of your current security measures, a calculated rating of likelihood and impact for each risk, and formal documentation of your findings.

How to do a HIPAA risk analysis?

You must systematically map your electronic patient data, identify physical and technical vulnerabilities, and document the administrative, physical, and technical safeguards you currently use. Most practices partner with a managed IT provider to ensure the technical controls and documentation meet federal standards.

Protect Your Practice and Patient Data

There is no official certification status for a business or an IT vendor. Compliance is an ongoing state you maintain, and building a defensible program requires a reliable technology partner. LeadingIT is a Chicagoland managed it and cybersecurity provider that has helped Illinois practices meet HIPAA since 2010.

We serve roughly 200 organizations and over 2,500 users from our offices in Woodstock and Manteno. We deliver LeadingIT’s HIPAA compliance services by operating the technical half of the law, managing your access controls, multi-factor authentication, encryption, and tested backups while signing a BAA as standard.

If you are ready to secure your patient data and survive your next audit, book a call or contact us at 815-788-6041.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.