Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

HIPAA risk assessment steps from mapping ePHI to risk management and remediation

How to Conduct a HIPAA Risk Assessment

A HIPAA risk assessment is the foundation of the entire Security Rule — and one of the most scrutinised requirements in any HIPAA investigation. It identifies the risks to your protected health information so you can protect it appropriately. This guide explains what a HIPAA risk assessment is, why it is required, and how to conduct one.

HIPAA risk assessment steps from mapping ePHI to risk management and remediation

For the wider context, see our complete HIPAA guide.

What is a HIPAA risk assessment?

A HIPAA risk assessment (also called a security risk analysis) is a systematic evaluation of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the electronic protected health information your organization holds. It examines where ePHI lives, the threats it faces, the likelihood and impact of those threats, and the safeguards you have in place — producing a clear picture of your risk and where to focus.

Why a HIPAA risk assessment is required

The Security Rule explicitly requires covered entities and business associates to conduct an accurate and thorough risk analysis. It is not a one-off exercise but an ongoing obligation, and it drives every other security decision: you cannot know which safeguards you need until you understand your risks. A missing or inadequate risk assessment is one of the most common findings in HIPAA enforcement actions, so getting it right matters.

How to conduct a HIPAA risk assessment

  1. Map your ePHI. Identify all the places electronic protected health information is created, received, stored, or transmitted — including systems, devices, and vendors.
  2. Identify threats and vulnerabilities. Consider technical, physical, and human risks that could compromise ePHI.
  3. Assess current safeguards. Document the administrative, physical, and technical controls already in place.
  4. Determine likelihood and impact. Rate the risk of each threat exploiting a vulnerability, and the potential harm.
  5. Assign risk levels. Prioritise the risks so the most serious are addressed first.
  6. Document everything. Record your methodology, findings, and risk ratings as evidence.

What to do after the risk assessment

The risk assessment feeds directly into risk management — your plan to reduce risks to a reasonable and appropriate level. From the prioritised findings, you implement or strengthen safeguards, update policies, and assign owners and deadlines. Because HIPAA requires this to be ongoing, you should repeat the assessment periodically and whenever your systems, vendors, or environment change significantly. A structured template makes both the assessment and its remediation far faster.

Run your risk assessment the fast way.

Our HIPAA Toolkit includes a structured security risk assessment and risk-management templates — plus the safeguards and policies to close the gaps it reveals — in Word and Excel.

Explore the HIPAA Toolkit →

Frequently asked questions

What is a HIPAA risk assessment?

A systematic evaluation of the risks and vulnerabilities to the confidentiality, integrity, and availability of your electronic protected health information, and the safeguards protecting it.

Is a HIPAA risk assessment required?

Yes. The Security Rule requires an accurate and thorough risk analysis, and it must be kept up to date — a missing or inadequate assessment is a common enforcement finding.

How often should you do a HIPAA risk assessment?

Periodically and whenever your systems, vendors, or environment change significantly. HIPAA treats it as an ongoing obligation, not a one-time task.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.