Methodology

HIPAA Compliance Security Risk Assessment Methodology

How One Guy Consulting performs a HIPAA Security Risk Assessment, step by step, from asset inventory through annual review. See the methodology, the deliverables, and what to do if your clinic has not started yet.

What Is a Security Risk Assessment?

A Security Risk Assessment (SRA) is the process of identifying threats and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI). It is required by the HIPAA Security Rule at 45 CFR §164.308(a)(1)(ii)(A), which states that covered entities and business associates must "conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information."

This requirement applies to every organization that handles ePHI, including physician practices, dental offices, behavioral health providers, pharmacies, billing companies, IT vendors, cloud storage providers, and any other business associate. There is no size exemption. A solo practitioner has the same obligation as a hospital system, though the scale and complexity of the assessment will differ.

Why is this the most commonly cited deficiency? OCR enforcement data consistently shows that the failure to conduct or document a Security Risk Assessment is one of the most frequent findings in HIPAA investigations and audits. Without a completed SRA, an organization cannot demonstrate that it has identified the risks it is required to manage under the Security Rule.

How One Guy Consulting Performs a Security Risk Assessment

This 8-step methodology follows the framework outlined in NIST SP 800-30 Rev. 1 and maps directly to the requirements of the HIPAA Security Rule. Each step produces documented evidence that can be retained per §164.530(j) and produced during an OCR investigation or audit.

1

Scope and Asset Inventory

Identify all systems, devices, applications, and locations that create, receive, maintain, or transmit ePHI. This includes EHR systems, practice management software, email platforms, fax machines, mobile devices, cloud storage, backup media, and paper-to-digital conversion points. Map data flows between systems and document where ePHI is stored at rest and in transit.

2

Threat Identification

Catalog natural, human, and environmental threats per NIST SP 800-30 Rev. 1. Natural threats include floods, storms, and power outages. Human threats include unauthorized access, ransomware, phishing, social engineering, and insider misuse. Environmental threats include hardware failure, building access failures, and HVAC issues affecting server rooms. Document each threat source and the threat events it could trigger against your specific ePHI environment.

3

Vulnerability Assessment

Evaluate your current administrative, physical, and technical controls against the requirements of §164.308 (administrative safeguards), §164.310 (physical safeguards), and §164.312 (technical safeguards). Identify gaps where controls are missing, incomplete, or ineffective. Common vulnerabilities include lack of encryption, missing access controls, no audit logging, absent workforce training, and unsecured workstations.

4

Risk Determination

Assign likelihood and impact ratings to each identified threat-vulnerability pair using a structured risk matrix. Likelihood reflects how probable it is that a given threat will exploit a specific vulnerability. Impact reflects the severity of harm to the organization and to affected individuals if ePHI is compromised. Calculate risk levels as a function of likelihood and impact, and categorize each risk as high, medium, or low.

5

Control Recommendations

Map each finding to specific administrative, physical, or technical safeguards that would reduce the risk to a reasonable and appropriate level per §164.306(b). Recommendations are proportionate to the organization's size, complexity, and capabilities. For a small practice, this might mean enabling encryption on existing systems rather than purchasing new infrastructure.

6

Documentation and Evidence Packaging

Compile all assessment findings, methodologies, and supporting evidence into a documented report that meets the retention requirements of §164.530(j). This documentation must be retained for at least six years and be available for OCR review. The report includes the scope definition, asset inventory, threat catalog, vulnerability findings, risk ratings, and recommended controls.

7

Remediation Planning

Create a prioritized action plan with specific timelines, responsible parties, and measurable milestones for addressing each identified risk. High-risk findings receive immediate remediation targets. Medium and low risks are scheduled within defined timeframes. The remediation plan becomes a living document that tracks progress and demonstrates ongoing compliance effort.

8

Annual Review Cycle

The Security Risk Assessment is not a one-time project. HHS requires regulated entities to periodically assess how well their policies and safeguards meet the Security Rule. Reassess risks when systems change, new vendors are added, workforce turnover occurs, or the threat landscape shifts. Most compliance programs conduct a full reassessment annually, with interim reviews as changes occur.

What Deliverables You Receive

Every Security Risk Assessment engagement produces a set of concrete, documented outputs. These are the records you retain for OCR review and the tools you use to drive remediation.

Written Risk Assessment Report

A comprehensive document covering scope, methodology, findings, risk ratings, and recommendations. This is the primary evidence of your SRA under §164.308(a)(1)(ii)(A).

Asset and ePHI Flow Inventory

A complete catalog of every system, device, and application that creates, receives, maintains, or transmits ePHI, with data flow diagrams showing how information moves through your environment.

Threat and Vulnerability Register

A structured register documenting every identified threat source, threat event, and vulnerability, mapped to the specific assets and ePHI they could affect.

Risk Scoring Matrix

A likelihood-by-impact matrix with assigned risk levels for every threat-vulnerability pair. This makes it clear which risks require immediate attention and which can be scheduled.

Prioritized Remediation Plan

An action plan with specific tasks, deadlines, and responsible parties for addressing each finding. Organized by risk level so your practice can focus resources on the highest-impact items first.

Evidence Documentation Package

Organized supporting evidence ready for §164.530(j) retention, including completed assessment worksheets, control evaluation notes, and any screenshots or configuration records reviewed during the assessment.

What to Do If Your Clinic Has No Risk Assessment

If your clinic has no HIPAA risk assessment or written policies yet, start with a Security Risk Analysis now: identify where PHI is stored and transmitted, list your vendors and devices, document the main risks, then put the required policies and procedures in writing and assign someone responsible for security. HHS says regulated entities must periodically assess how well their policies and safeguards meet the Security Rule, and ONC/HHS offers a Security Risk Assessment Tool to help get started.

Here is a practical starting sequence:

  1. List every system that touches ePHI — your EHR, email, fax, cloud storage, mobile devices, and any vendors who access patient data on your behalf.
  2. Identify your biggest risks — unencrypted devices, missing access controls, no backup strategy, and staff who have not received HIPAA training.
  3. Put your policies in writing — even a basic set of written policies covering access control, breach response, device management, and workforce training puts you ahead of having no documentation at all.
  4. Assign a Security Officer§164.308(a)(2) requires a designated security official responsible for developing and implementing your security policies.
  5. Train your workforce§164.308(a)(5)(i) requires training for all workforce members with access to PHI.
  6. Engage a consultant if you need help — if you do not have the internal expertise or time to conduct a Security Risk Assessment, a consultant can walk you through the process and produce the required documentation.

The cost of inaction is higher than the cost of starting. OCR has imposed penalties on organizations of all sizes for failing to conduct a risk assessment. Starting the process, even imperfectly, demonstrates a good-faith compliance effort that is far better than having nothing documented.

Security Risk Assessment Questions

If your clinic has no HIPAA risk assessment or written policies yet, start with a Security Risk Analysis now: identify where PHI is stored and transmitted, list your vendors and devices, document the main risks, then put the required policies and procedures in writing and assign someone responsible for security. HHS says regulated entities must periodically assess how well their policies and safeguards meet the Security Rule, and ONC/HHS offers a Security Risk Assessment Tool to help get started. One Guy Consulting can walk you through the full process with a hands-on Security Risk Assessment and custom policy development.
The HIPAA Security Rule at 45 CFR §164.308(a)(1)(ii)(A) requires covered entities and business associates to conduct an accurate and thorough assessment of potential risks and vulnerabilities to ePHI. While the rule does not specify a fixed frequency, HHS guidance and OCR enforcement actions make clear that this is an ongoing obligation, not a one-time task. Most compliance frameworks recommend conducting a full Security Risk Assessment at least annually, and whenever significant changes occur to systems, workflows, or the threat environment.
A Security Risk Assessment identifies threats and vulnerabilities to electronic protected health information and evaluates the likelihood and impact of those threats materializing. It is required by 45 CFR §164.308(a)(1)(ii)(A). A gap analysis maps your current controls, policies, and procedures against the full scope of HIPAA requirements, including the Privacy Rule, Security Rule, and Breach Notification Rule, to identify where your compliance program falls short. Both are valuable: the SRA focuses on risk to ePHI specifically, while the gap analysis gives a broader view of overall compliance posture.
One Guy Consulting offers full-scope HIPAA compliance help for small practices and business associates, including security risk assessments under 45 CFR §164.308(a)(1)(ii)(A), gap analysis and remediation plans, custom policies and procedures per §164.316(a), staff training per §164.308(a)(5)(i), IT and physical audits under §164.310 and §164.312, vendor and BAA management per §164.502(e), incident management and breach notification support per §164.404(b), and audit-response documentation per §164.530(j). Everything is included in one flat annual rate with no per-user fees.

Learn More About HIPAA Risk Assessments

Ready to Start Your Security Risk Assessment?

Book a free 30-minute intro call. We will review your current compliance status and walk you through how the assessment process works for your practice.

Book Your Free HIPAA Compliance Review