Two years ago a five-provider orthopedic group asked us to look at their compliance file before a payer audit. In the folder marked HIPAA was a 30-page policy manual from 2016, a signed training roster, and a one-page checklist titled "Security Risk Assessment" with every box ticked and no date. When we asked where the encrypted laptops were listed, or which vendor hosted the backups, or when the last time anyone reviewed who had administrator access to the EHR, nobody knew. The practice believed it had done a risk analysis. It had done a checklist.

That distinction is the one the HHS Office for Civil Rights (OCR) keeps returning to. The HIPAA Security Rule, in force since 2005, requires every covered entity to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of its electronic protected health information. OCR has said publicly that a missing or inadequate risk analysis appears in the large majority of its Security Rule enforcement actions. In October 2024 it launched what it calls the Risk Analysis Initiative, a series of enforcement actions focused on that one requirement, and by August 18, 2025 it had announced the tenth settlement under it. Many of the settling organizations were small, including a CPA firm, a behavioral health group and an ambulatory surgery center.

A HIPAA security risk analysis for a small practice does not have to be a consultant's 200-page deliverable. It has to be real: an inventory of where the data is, an honest look at what could go wrong, a rating of how likely and how bad, and a plan for the items that scored high. Here is how we walk practices through it.

Key takeaways

  • A risk analysis is an inventory of every system that holds ePHI, a list of realistic threats and vulnerabilities for each, and a likelihood and impact rating that produces a ranked risk list.
  • A ticked checklist without an inventory, dates and a named person is not a risk analysis and OCR treats it as none at all.
  • The risk analysis produces the risk management plan; the plan is where remediation lives and it must be dated and revisited.
  • Small practices are being settled with under OCR's Risk Analysis Initiative, so size is not a defense.
  • Repeat it at least annually and whenever the environment changes: a new EHR, a new location, a new telehealth platform, a breach.

What the rule actually requires

The Security Rule has a specific provision, 45 CFR 164.308(a)(1)(ii)(A), that requires the risk analysis, and a companion, 164.308(a)(1)(ii)(B), that requires risk management: implementing security measures sufficient to reduce the identified risks to a reasonable and appropriate level. The two are separate. The first is a document that describes your risks. The second is the ongoing work of fixing them. OCR cites both when it finds neither.

OCR published guidance on the risk analysis requirement in 2010 that still describes what it expects: define the scope (all ePHI, wherever it lives), collect data on where ePHI is stored, received, maintained or transmitted, identify and document reasonably anticipated threats and vulnerabilities, assess current security measures, determine the likelihood and impact of each threat, assign risk levels, document everything, and review and update periodically. That list is the outline of the document you are going to produce. Notably, the rule is flexible about method and scale. A solo practice and a hospital system have the same requirement and very different documents.

HHS also proposed a substantial update to the Security Rule in January 2025 that would make the risk analysis requirements more prescriptive, including a written asset inventory and network map. As of this writing that rule has not been finalized, but the direction is clear, and building the inventory now is the right move regardless.

Step one: inventory where the ePHI is

You cannot analyze risk to data you have not located. The inventory is a table, and for most small practices it fits on two pages. List every system, device and service that creates, receives, stores or transmits ePHI. The EHR and practice management system, whether hosted by the vendor or on a server in a closet. The clearinghouse. The patient portal and any texting or reminder platform. Email, including whether it is encrypted. The phone system if it records or transcribes. Laptops, desktops, tablets and phones that access any of these, with a note on whether each is encrypted and whether it leaves the building. Backup systems and where the backups physically or virtually live. Fax, scanners and copiers with hard drives. Paper is not ePHI, but the scanner that turns paper into PDFs is.

For each entry, record the owner (the vendor or the practice), the person in the practice responsible for it, how access is controlled, and whether a business associate agreement (BAA, the contract HIPAA requires with any vendor that handles PHI on your behalf) is on file with a date. The orthopedic group's inventory turned up a texting app the front desk had adopted on their own, no BAA, patient names and appointment reasons flowing through it daily. That is the sort of thing the inventory exists to find.

Step two: threats, vulnerabilities and current controls

For each system, list what could realistically go wrong and what makes it possible. A threat is the event: ransomware, a lost laptop, a former employee logging in, a vendor breach, a flood in the server closet, a phishing email that captures a password. A vulnerability is the weakness that lets the threat succeed: no multifactor authentication on the EHR, unencrypted laptops, no offboarding checklist, a BAA that was never signed, backups stored on the same network as the server, staff who have never been trained to recognize phishing.

Then write down the controls already in place. Be honest. "Antivirus installed" is a control. "We think the IT vendor handles that" is not. This is where small practices most often discover that their security depends on a single outside IT person whose work nobody has verified, and that the audit logs the EHR generates have never been looked at by anyone.

SystemThreatVulnerabilityLikelihoodImpactRisk
Hosted EHRCredential theft via phishingNo multifactor authentication for remote loginsHighHighHigh
Provider laptopsLoss or theftTwo of six laptops not encryptedMediumHighHigh
Front desk texting appVendor breach or misuseNo BAA, no access reviewMediumMediumMedium
Local backup driveRansomware encrypts backupsBackup connected to the same networkMediumHighHigh
Copier hard driveDisposal without wipingNo disposal procedureLowMediumLow

Step three: score, rank and write it down

Likelihood and impact can be rated on a simple three-level scale. Likelihood: low if the threat is rare and the controls are strong, medium if it is plausible within a few years, high if it is common in practices like yours and controls are weak. Impact: low if the exposure would involve few records and be quickly contained, medium if it would trigger breach notification, high if it would take systems down or expose the whole patient database. Combine them into an overall risk level. The exact scoring method matters less than applying it consistently and explaining it in the document.

The output is a ranked list. Everything rated high goes to the top. The document itself should contain the scope statement, the inventory, the threat and vulnerability table, the scoring method, the ranked risks, the date, and the names of the people who conducted it. Sign it. Date it. Keep the previous versions. OCR asks for the risk analysis in nearly every investigation, and "we did one but it is not written down" has been treated as not having done one.

There are free tools for this. The HHS Security Risk Assessment Tool, published jointly by OCR and the Office of the National Coordinator, walks a small practice through the questions and produces a report. It is a reasonable starting point, and it is far better than a blank page, but it still requires you to enter your real inventory and real answers. A tool completed by clicking "yes" down the page produces the orthopedic group's checklist.

Step four: the risk management plan

The risk analysis says what is wrong. The risk management plan says what you will do about it, by when, and who owns it. For each high and medium risk, write the remediation, the responsible person, the target date and the status. Turning on multifactor authentication for the EHR is usually a phone call to the vendor and a week of staff grumbling. Encrypting the two laptops is an afternoon. Moving backups off the production network may take the IT vendor a month. Signing a BAA with the texting vendor, or replacing the vendor, is a decision for the practice owner.

Review the plan monthly until the high items are closed, then quarterly. Update the risk analysis when something changes: a new EHR module, a telehealth platform, a second location, a new IT vendor, a breach or a near miss. And repeat the whole exercise at least annually. OCR's settlements routinely note that the organization's last risk analysis was several years old, or that it covered only one system. A dated annual cycle is the simplest defense against both findings. Practices that want a structured second set of eyes on this can pair it with a broader operational audit, since access control and offboarding failures tend to show up in billing systems as well as clinical ones.

Questions we hear

Our EHR vendor is HIPAA compliant. Does that cover our risk analysis?

No. The vendor is responsible for the security of its own systems under its BAA. You are responsible for how your staff access it, the devices they use, the passwords they choose, the other systems you connect to it, and everything else in your environment. The vendor's compliance is one line in your inventory, not a substitute for the document.

Do we need to hire a consultant?

Not necessarily. A small practice with an engaged manager and a cooperative IT vendor can complete a defensible risk analysis using the HHS tool and the steps above. A consultant helps when nobody in the practice has time, when the environment is complicated, or when the practice has already had an incident. What you cannot do is outsource it and never read it.

What does OCR actually fine small practices?

Settlements under the Risk Analysis Initiative in 2025 ranged from tens of thousands of dollars to several hundred thousand, and every one came with a corrective action plan and two or more years of monitoring. The money is often the smaller cost. The corrective action plan requires the organization to do the risk analysis properly anyway, on OCR's schedule, with OCR reviewing it.

What to do this week

  1. Find your current risk analysis, check its date and whether it contains an inventory, and decide honestly whether it would satisfy an investigator.
  2. Start the ePHI inventory: every system, device and vendor, with the responsible person and the BAA date, in one table.
  3. Ask your EHR and practice management vendors whether multifactor authentication is available and turned on for every user.
  4. Check every laptop and phone that touches patient data for full-disk encryption, and list the ones that fail.
  5. Schedule a half-day in the next month to complete the threat table and scoring with the manager, one clinician and your IT support.