A HIPAA risk assessment is the foundation of the entire Security Rule — and one of the most scrutinised requirements in any HIPAA investigation. It identifies the risks to your protected health information so you can protect it appropriately. This guide explains what a HIPAA risk assessment is, why it is required, and how to conduct one.

For the wider context, see our complete HIPAA guide.
What is a HIPAA risk assessment?
A HIPAA risk assessment (also called a security risk analysis) is a systematic evaluation of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the electronic protected health information your organization holds. It examines where ePHI lives, the threats it faces, the likelihood and impact of those threats, and the safeguards you have in place — producing a clear picture of your risk and where to focus.
Why a HIPAA risk assessment is required
The Security Rule explicitly requires covered entities and business associates to conduct an accurate and thorough risk analysis. It is not a one-off exercise but an ongoing obligation, and it drives every other security decision: you cannot know which safeguards you need until you understand your risks. A missing or inadequate risk assessment is one of the most common findings in HIPAA enforcement actions, so getting it right matters.
How to conduct a HIPAA risk assessment
- Map your ePHI. Identify all the places electronic protected health information is created, received, stored, or transmitted — including systems, devices, and vendors.
- Identify threats and vulnerabilities. Consider technical, physical, and human risks that could compromise ePHI.
- Assess current safeguards. Document the administrative, physical, and technical controls already in place.
- Determine likelihood and impact. Rate the risk of each threat exploiting a vulnerability, and the potential harm.
- Assign risk levels. Prioritise the risks so the most serious are addressed first.
- Document everything. Record your methodology, findings, and risk ratings as evidence.
What to do after the risk assessment
The risk assessment feeds directly into risk management — your plan to reduce risks to a reasonable and appropriate level. From the prioritised findings, you implement or strengthen safeguards, update policies, and assign owners and deadlines. Because HIPAA requires this to be ongoing, you should repeat the assessment periodically and whenever your systems, vendors, or environment change significantly. A structured template makes both the assessment and its remediation far faster.
Run your risk assessment the fast way.
Our HIPAA Toolkit includes a structured security risk assessment and risk-management templates — plus the safeguards and policies to close the gaps it reveals — in Word and Excel.
Frequently asked questions
What is a HIPAA risk assessment?
A systematic evaluation of the risks and vulnerabilities to the confidentiality, integrity, and availability of your electronic protected health information, and the safeguards protecting it.
Is a HIPAA risk assessment required?
Yes. The Security Rule requires an accurate and thorough risk analysis, and it must be kept up to date — a missing or inadequate assessment is a common enforcement finding.
How often should you do a HIPAA risk assessment?
Periodically and whenever your systems, vendors, or environment change significantly. HIPAA treats it as an ongoing obligation, not a one-time task.