Skip to content

Do we need a HIPAA risk assessment?

Short answer

Yes, if you're a covered entity or business associate. The HIPAA Security Rule requires an accurate and thorough risk analysis of threats to electronic protected health information, and it's the first thing investigators ask for after a breach. It should be updated regularly and whenever your systems or operations change significantly.

Draft · pending expert review

The risk analysis is the foundation of HIPAA security compliance. Everything else, from policies to safeguards, is supposed to flow from it.

Who needs one

Covered entities (providers, health plans, clearinghouses) and business associates that create, receive, maintain, or transmit ePHI on their behalf.

What it covers

  • Where ePHI lives and how it moves
  • Threats and vulnerabilities to that information
  • Current safeguards and their gaps
  • The likelihood and impact of each risk
  • A plan to reduce the risks that matter most

How often

HIPAA doesn't set a fixed schedule, but it expects the analysis to stay current. Annually, and after any major change, is a sound practice.

Talk to a person, not a ticket

Tell us what's going on. We'll listen, ask good questions, and give you a straight answer about whether we can help.

Call us