Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

HIPAA Risk Assessment Template — guide from Governance Docs

HIPAA Risk Assessment Template: What It Must Contain

A HIPAA risk assessment template exists to satisfy one of the few requirements
in the Security Rule that is not open to interpretation. The risk analysis at
45 CFR §164.308(a)(1)(ii)(A) is a required implementation
specification, not an addressable one — there is no “reasonable and appropriate” escape from
doing it. This guide sets out what the document must contain.

A HIPAA risk assessment template records a risk analysis, not a checklist

The most common failure is building a HIPAA risk assessment template as a compliance checklist. A checklist asks
whether you have a policy; a risk analysis asks what could happen to electronic protected health
information, how likely it is, and what it would cost you. OCR has been consistent on this point in
enforcement actions for over a decade, and “we completed a HIPAA questionnaire” has never satisfied
it.

The second most common failure is scope. A HIPAA risk assessment template must reach every system holding ePHI. The analysis must cover ePHI everywhere it is
created, received, maintained or transmitted — which includes laptops, phones, backups, the
cloud, third-party platforms and the vendor nobody told IT about.

The fields a HIPAA risk assessment template needs

  • Asset or system, and where the ePHI sits within it.
  • ePHI data flow — created, received, maintained, transmitted. All four
    verbs come from the rule and all four need answering.
  • Volume and sensitivity of the ePHI involved.
  • Threat, split into the three categories OCR expects: natural, human (both
    intentional and accidental) and environmental. Accidental human threats are the ones most often
    omitted and the ones that cause most breaches.
  • Vulnerability — the weakness the threat would exploit, stated
    specifically rather than as “weak security”.
  • Current security measures already in place.
  • Likelihood of occurrence, against a scale defined in advance.
  • Impact if it occurred, covering confidentiality, integrity and availability
    — not just disclosure.
  • Risk level, derived from likelihood and impact by a documented method.
  • Risk management action under §164.308(a)(1)(ii)(B), with an owner and a
    date — the risk analysis and the risk management step are separate requirements.
  • Residual risk after the action, and who accepted it.
  • Review date or trigger.

A risk assessment workbook that already asks these questions.

The HIPAA Toolkit includes the security risk analysis workbook, the risk management plan it feeds, and 160+ policy templates — with a documented methodology so you can explain your scoring rather than defend it.

Explore the HIPAA Toolkit →

Where a HIPAA risk assessment template falls down at audit

  • No documented methodology. The register exists; nothing explains how likelihood
    and impact were scored, so nobody can reproduce the result.
  • Assets missing. A risk analysis that covers the EHR but not the backup vendor,
    the billing platform or the imaging system is incomplete by definition.
  • Availability and integrity ignored. Teams assess disclosure risk only.
    Ransomware is an availability event, and it is currently the most common serious incident in
    healthcare.
  • No link to risk management. Risks identified, nothing done, no owner. This is
    the single most cited failing in OCR settlements.
  • Done once. The Security Rule requires periodic review; a risk analysis dated
    four years ago and untouched through two system migrations is not current.
  • Business associates excluded. They hold your ePHI. See our guide to the
    HIPAA business associate agreement.

How often to redo the HIPAA risk assessment template

The rule does not name an interval for refreshing a HIPAA risk assessment template, which people read as permission to do it once. The workable
standard is annually and on trigger: a new system, a new business associate, a merger, a
move to a new cloud provider, or a security incident. Update the same document rather than starting
fresh each time, because the version history is itself evidence that the process is running.

HHS and ONC publish a free Security Risk Assessment Tool aimed at small and medium providers.
It is a reasonable starting point, though it produces its own report format rather than fitting into
an existing documentation set.

One change worth building into your HIPAA risk assessment template now

The proposed Security Rule overhaul would remove the “addressable” classification entirely and
make specifications such as encryption and multi-factor authentication mandatory, alongside annual
penetration testing and six-monthly vulnerability scans. That rule is not final and
is not expected until 2027, so nothing changes today. But if your template has a column recording
whether a control is required or addressable, expect that column to become redundant — and
recording why you chose not to implement an addressable specification is worth doing now
regardless. See our HIPAA Security Rule update guide.

For the wider process, see our HIPAA risk assessment guide, the
HIPAA compliance checklist, or start from the
free HIPAA templates.

References

More on HIPAA

All of these are covered by the HIPAA Toolkit, or start with the free HIPAA templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.