Small Practice Security

How to do a HIPAA security risk analysis for a small practice

Updated October 2026 · Small Practice Security

Every HIPAA covered entity and business associate must conduct "an accurate and thorough assessment of the potential risks and vulnerabilities" to the electronic protected health information (ePHI) it holds. That requirement sits at 45 CFR 164.308(a)(1)(ii)(A), and it is the foundation of the whole Security Rule.

It is also the document OCR asks for first after a breach report or complaint. A missing or superficial risk analysis is one of the most common findings in OCR settlements, and OCR has run a dedicated Risk Analysis Initiative focused on exactly this gap.

What a risk analysis must include

ElementWhat it means in practice
ScopeAll ePHI you create, receive, maintain or transmit: every location, system, device and vendor.
Data collectionWhere ePHI lives and how it moves.
Threats and vulnerabilitiesRealistic threats and the specific weaknesses they could exploit at your practice.
Current safeguardsWhat you already have in place.
Likelihood and impactHow likely each threat is, and how bad it would be.
Risk levelLikelihood combined with impact.
Documentation and reviewWritten results, kept six years, updated regularly and after major changes.

The six steps

1. Define the scope

Record locations, workforce size, core systems and who is doing the assessment. The default expectation is all locations and all systems; write down anything you exclude and why.

2. Build an asset inventory

List every application, device, cloud service and vendor that touches ePHI: EHR, practice management, clearinghouse, patient portal, email, file shares, laptops, phones, copiers with hard drives, backups, and your IT provider. Most practices underestimate this list.

3. Check the safeguards

Rate each Security Rule implementation specification as implemented, partially implemented, not implemented, or not applicable, with evidence. Remember that "addressable" does not mean optional: you must implement it, use a reasonable alternative, or document why neither is appropriate.

4. Score the risks

For each important asset, pick the threats that realistically apply: phishing, ransomware, lost devices, vendor breaches, misdirected email, staff using unapproved AI tools. Describe the vulnerability as it actually exists ("front desk shares one EHR login", not "weak access control"), then score likelihood and impact from 1 to 5.

5. Plan remediation

Every high and critical risk needs an action, an owner, a due date and a status. This plan is your risk management documentation under 164.308(a)(1)(ii)(B), and OCR expects to see that you acted on what you found.

6. Sign off and schedule the next one

Record approval, save a dated copy, and set the next review. Review annually and after major changes such as a new EHR, a new location, a merger or a security incident.

Ten mistakes to avoid

  1. Treating a vendor's checklist or EHR attestation as your risk analysis.
  2. Leaving out laptops, phones, locations or vendors.
  3. Copying generic vulnerabilities from a template.
  4. Scoring everything "medium".
  5. No remediation plan, or one with no owners or dates.
  6. Marking addressable specifications N/A without a reason.
  7. Doing it once and never again.
  8. "Implemented" with no evidence behind it.
  9. Missing business associate agreements.
  10. Not keeping prior years' versions for six years.

Free official resources

The HHS/ONC SRA Tool (healthit.gov), HHS guidance on risk analysis (hhs.gov/hipaa), the HHS 405(d) Health Industry Cybersecurity Practices (405d.hhs.gov), and NIST SP 800-66 Rev. 2.

Want a head start?

The HIPAA Security Risk Analysis Workbook gives you a pre-built threat library, all 47 safeguard specifications, auto-scored risk register, remediation plan and a step-by-step guide. $79, instant download.

Get the workbook Or start with the free checklist
This guide is educational and is not legal advice. It reflects the HIPAA Security Rule in force as of October 2026. HHS proposed significant Security Rule changes in January 2025; they had not been finalized as of this update.