After a breach, OCR rarely finds that an organisation had no security at all. What it finds, again and again, is a risk analysis that was never done, covered only the EHR, or was last touched three years and two systems ago.
The HIPAA Security Rule requires every covered entity and business associate to carry out an accurate and thorough risk analysis of the electronic protected health information (ePHI) it holds, and then to manage the risks it finds. This free HIPAA security risk assessment checklist runs that yearly exercise from start to finish: scoping every system that touches ePHI, identifying threats and vulnerabilities, rating likelihood and impact, building the risk register, writing the risk management plan and keeping the evidence. It is deliberately narrow. Our HIPAA Compliance Audit Checklist checks your whole programme against the Privacy, Security and Breach Notification Rules, and our HIPAA compliance guide explains the rules themselves. This template is the risk analysis workflow that both of them assume you have already done.
Risk Analysis, Risk Management and the Compliance Audit: Three Different Jobs
Two implementation specifications sit at the very start of the Security Rule’s administrative safeguards, and both are required rather than addressable. Under 45 CFR 164.308(a)(1)(ii)(A), you must assess the potential risks and vulnerabilities to the confidentiality, integrity and availability of all the ePHI you create, receive, maintain or transmit. Under 164.308(a)(1)(ii)(B), you must then put security measures in place that reduce those risks to a reasonable and appropriate level. Every other safeguard decision in the rule, from encryption to audit logging, is supposed to follow from that analysis.
The rule does not prescribe a method. HHS’s guidance on risk analysis sets out the elements OCR expects to see: a scope that covers all ePHI, data collection, identified threats and vulnerabilities, an assessment of current security measures, likelihood and impact, a level of risk, documentation and periodic review. NIST SP 800-30 and SP 800-66 Rev. 2 describe methods that satisfy those elements. OCR has made weak risk analyses an enforcement priority: its Risk Analysis Initiative had produced at least 14 enforcement actions by mid-2026, and most ransomware settlements cite the same failure.
Risk analysis
What could go wrong, and how badly?
Rule: 164.308(a)(1)(ii)(A), required.
Output: an ePHI inventory, threat and vulnerability pairs, likelihood and impact ratings, and a risk register.
Covered by: Phases 1–4 of this template.
Risk management
What are we doing about it?
Rule: 164.308(a)(1)(ii)(B), required.
Output: a treatment decision, owner and date for every risk, with remediation tracked to closure.
Covered by: Phases 5–7 of this template.
Compliance audit
Does the whole programme meet HIPAA?
Rule: all three HIPAA Rules, standard by standard.
Output: findings against the Privacy, Security and Breach Notification Rules.
What the HIPAA Security Risk Assessment Checklist Covers
Six phases take the assessment from scoping to a signed report. A seventh phase switches on automatically when any risk is rated High.
Phase 1
Phase 1: Scope, Team & ePHI Inventory
The most common reason OCR rejects a risk analysis is scope. If a system holds ePHI and is not in the inventory, it is not in the analysis.
Name the assessment lead and confirm the Security Official — who runs the assessment and who approves it
Define the scope — every location, workforce group, system, device and vendor that creates, receives, maintains or transmits ePHI, including remote staff
Pull last year’s risk register and risk management plan — record which actions closed and which are still open
Update the ePHI asset inventory — EHR, billing, imaging, email, file shares, backups, laptops, phones, connected medical devices and cloud services
Map how ePHI flows — where it enters, where it is stored, who it is sent to and which business associates handle it
Record what has changed since the last assessment — new systems, sites, vendors, mergers or incidents
Phase 2
Phase 2: Threats & Vulnerabilities
List the reasonably anticipated threats to each asset — ransomware, phishing and credential theft, insider misuse, lost or stolen devices, vendor compromise, fire, flood and power loss
Gather technical evidence — the latest vulnerability scan, penetration test results, unsupported software and patch status
Review the year’s security incident and breach log — incidents show which threats are real for you, not in theory
Interview system owners and department leads — shared logins, workarounds, unapproved apps and paper-to-digital gaps
Record each threat and vulnerability pair against the asset it affects
Phase 3
Phase 3: Current Safeguards
Access controls — unique user IDs, role-based access, prompt removal of leavers, and MFA for remote and privileged access
Encryption — ePHI at rest on servers, laptops, phones and backups, and in transit over email and interfaces
Audit controls — logging switched on for ePHI systems, and the logs actually reviewed
Backup and recovery — backups isolated from the network, restores tested and recovery times known
Physical safeguards — facility access, workstation placement, and device and media disposal
Business associate agreements — a current BAA for every vendor in the ePHI inventory
Addressable specifications — document whether each is implemented, replaced by an equivalent measure or not reasonable, and why
Phase 4
Phase 4: Likelihood, Impact & the Risk Register
Rate the likelihood of each threat exploiting each vulnerability, given the safeguards already in place — Low, Moderate or High
Rate the impact if it happens — patient safety, records affected, downtime, and regulatory and financial exposure
Combine the two into a risk level using the matrix below — one scale, applied the same way to every risk
Enter every risk in the register — asset, threat, vulnerability, existing controls, likelihood, impact and risk level
Security Official reviews the ratings for consistency — challenge any rating the evidence does not support
Record whether any risk is rated High — this answer switches on Phase 6
Phase 5
Phase 5: Risk Management Plan
Decide a treatment for every risk — mitigate, transfer, avoid or accept, with the reason recorded
Give each mitigation an owner, a target date and an estimated cost
Document accepted risks with the rationale and the approver — acceptance is a decision, not an omission
Prioritise the plan by risk level and set progress review dates for the Security Official
Brief leadership on the plan and the budget it needs
Phase 6 — High Risks Only
Phase 6: High-Risk Remediation
Shown only when Phase 4 records at least one High risk. Conditional logic keeps these tasks out of the way when there is nothing urgent to fix.
Put interim safeguards in place for each High risk within the deadline you set — for example, close an exposed service, enforce MFA or isolate a legacy device
Open a remediation project for each High risk, with milestones and a named owner
Verify each fix with evidence — a rescan, a configuration export or a successful restore test
Re-rate the risk after remediation and update the register
Escalate any High risk still open at its target date to leadership
Phase 7
Phase 7: Sign-Off, Retention & Next Review
Assigned to the Security Official by name. The analyst who compiled the register should not approve it.
Compile the risk analysis report — scope, method, inventory, register, risk management plan and conclusions
Security Official and leadership approve the report — record who approved it and when
Retain the report, register and evidence for at least six years from the date created or last in effect, whichever is later
Feed the findings into security awareness training and the policies they affect
Schedule next year’s assessment and record the events that trigger an earlier update — a new EHR, a new site, a merger or a significant incident
A risk register is only useful if two people would rate the same risk the same way. Agree the scale before Phase 4 starts and keep it for the whole assessment. The three-point scale below matches the Low, Moderate and High language used in the HHS SRA Tool, and it is simple enough for a small practice to apply consistently. Larger organisations often use five points, which also works, provided the definitions are written down.
Likelihood ↓ Impact →
Low impact
Moderate impact
High impact
High likelihood
Moderate
High
High
Moderate likelihood
Low
Moderate
High
Low likelihood
Low
Low
Moderate
Level
Likelihood means
Impact means
What the checklist does next
High
Expected within the year, or has already happened here or at a peer
Harm to patients, a reportable breach of many records, or days of downtime
Phase 6 opens: interim safeguards, a remediation project and leadership escalation
Moderate
Plausible within the year, with some controls in place
A limited breach, hours of disruption or a regulatory finding
Mitigation with an owner and a date in the risk management plan
Low
Unlikely, with strong controls in place
Minimal records affected and no effect on care
Accept with a documented rationale, or monitor at the next review
The proposed Security Rule update. HHS published a proposed overhaul of the Security Rule in the Federal Register on 6 January 2025. As of September 2026 it is still a proposal: OCR has not issued a final rule, and the content and timing could change. As drafted, it would require a written risk analysis reviewed at least every 12 months, a technology asset inventory and network map on the same cycle, and would remove the distinction between required and addressable specifications. Phases 1, 3 and 7 of this template already produce those documents, so an organisation using it would have little to change if the rule is finalised as proposed.
Why Run Your HIPAA Risk Assessment in CheckFlow?
1
It starts on time every year
A recurring schedule opens the assessment on the same date each year and assigns Phase 1 to the assessment lead. If a trigger event happens mid-year, such as a new EHR or a merger, you start an extra run from the same template.
2
High risks cannot hide
Answer “yes” to the High-risk question in Phase 4 and the remediation phase appears, with its own owners and due dates. The risk management plan becomes a set of tracked tasks rather than a table in a report nobody reopens.
3
Six years of evidence in one place
Scan reports, the inventory, the register and the signed report are attached to the tasks they support, each with a name and a timestamp. When OCR asks for your risk analysis history, you export past years’ completed checklists instead of searching shared drives.
CheckFlow does not scan your network or replace the HHS SRA Tool. It runs the human side of the assessment around them: who does what, by when, with what evidence, and who signed it off. CheckFlow’s healthcare checklist software shows how the same approach handles credentialing, incident reporting and the rest of a practice’s compliance calendar.
The risk analysis is one requirement among many. For the full picture of the Privacy, Security and Breach Notification Rules, read our HIPAA compliance checklist guide, then use the HIPAA Compliance Audit Checklist to test the whole programme once the risk analysis is done.
It is the risk analysis required by 45 CFR 164.308(a)(1)(ii)(A) of the HIPAA Security Rule: an accurate and thorough assessment of the risks and vulnerabilities to the confidentiality, integrity and availability of all the ePHI an organisation holds. In practice it means listing every system and vendor that touches ePHI, identifying what could go wrong with each, rating how likely and how damaging each risk is, and recording the result in a risk register. The companion requirement in 164.308(a)(1)(ii)(B) is to manage those risks down to a reasonable and appropriate level.
How often does HIPAA require a risk assessment?
+
The current rule does not set a fixed interval. It requires the analysis to be kept current and documentation to be reviewed periodically and updated when environmental or operational changes affect the security of ePHI. Most organisations, and most auditors, treat once a year as the baseline, with an extra update after a major change such as a new EHR, a new location or a merger. HHS’s proposed Security Rule update would make a 12-month review explicit, but as of September 2026 it has not been finalised.
What is the difference between a risk assessment and a HIPAA compliance audit?
+
A risk assessment asks what could happen to your ePHI and how serious it would be. A compliance audit asks whether your policies and practices meet each HIPAA standard. The risk assessment comes first, because many Security Rule decisions, especially on addressable specifications, are meant to be based on it. Use this template for the risk analysis and the HIPAA Compliance Audit Checklist for the programme-wide audit.
Can we use this checklist with the HHS SRA Tool?
+
Yes. The Security Risk Assessment Tool from ONC and OCR is free, and version 3.7, released in September 2026, is designed for small and medium-sized providers. It guides you through the questions and produces a report. This checklist runs the work around it: assigning the inventory, collecting scan results, getting ratings reviewed, tracking remediation and recording sign-off. Attach the SRA Tool report to the Phase 7 report task. HHS notes that using the tool does not by itself guarantee compliance.
How long must we keep risk assessment records?
+
Security Rule documentation must be retained for six years from the date it was created or the date it was last in effect, whichever is later, under 45 CFR 164.316(b)(2)(i). Keep each year’s report, the risk register, the risk management plan and the supporting evidence. Older assessments also show OCR that the analysis has been kept current over time, which is often exactly what an investigation asks for.
Do business associates need their own risk assessment?
+
Yes. Business associates, such as billing companies, IT providers and cloud vendors that handle ePHI, are directly subject to the Security Rule and must carry out their own risk analysis. A covered entity cannot rely on a vendor’s assessment in place of its own, but it should record each business associate in its ePHI inventory and confirm a current business associate agreement is in place.
Is CheckFlow free for this template?
+
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.
A Risk Analysis You Can Hand to OCR, Every Year
Free trial — no credit card required.
Do you like cookies? 🍪 We use cookies to ensure you get the best experience on our website. Learn more