HIPAA·11 min read

HIPAA Risk Assessment: What It Requires and How to Do One

A HIPAA risk assessment is the foundation of a HIPAA compliance program, and it is not optional. The Security Rule requires it directly, and it is the single most-cited failure in federal enforcement actions, which means getting it right matters as much for avoiding penalties as it does for actually protecting data.

This guide covers whether HIPAA requires a risk assessment (it does), what it must include, how to run one step by step, and how often to repeat it. It also clears up the common confusion between the security risk analysis and the separate breach four-factor test. For the full program, see the HIPAA service page.


Does HIPAA require a risk assessment?

Yes, unambiguously. The HIPAA Security Rule requires every covered entity and business associate to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the electronic protected health information (ePHI) it holds. This is written into the rule as a required implementation specification, not a suggestion.

The risk assessment is foundational because everything else depends on it. You cannot decide which safeguards are reasonable and appropriate for your organization until you understand your actual risks. That is why the analysis comes first: it is the input that drives every other security decision.

Critically, the obligation applies to business associates too, not just healthcare providers. If your SaaS platform holds ePHI on behalf of a healthcare customer, you are required to perform your own HIPAA risk assessment. If you are still confirming whether HIPAA applies to your platform, start with the HIPAA compliance checklist for HealthTech.

Risk analysis vs risk management

These two terms are often used interchangeably, but HIPAA treats them as distinct, sequential steps.

Risk analysis is the assessment itself: identifying the threats and vulnerabilities to ePHI and determining the level of risk each one represents. It is a diagnostic activity. It tells you where you stand.

Risk management is what comes next: implementing security measures sufficient to reduce the identified risks to a reasonable and appropriate level. It is the treatment. HIPAA requires both, and the risk analysis feeds directly into the risk management plan.

The mistake many organizations make is stopping at the analysis. Producing a document that lists risks and then leaving them unaddressed is not compliance. The assessment has to lead to action, and that action has to be documented too.

What a HIPAA risk assessment must include

Federal guidance from the Department of Health and Human Services lays out the elements a compliant HIPAA risk assessment should contain. Pulled together, they form a clear sequence:

  • Scope and data inventory. Identify everywhere ePHI is created, received, maintained, or transmitted, across all systems, devices, and media. You cannot protect data you have not located.
  • Threat and vulnerability identification. Document the reasonably anticipated threats (attackers, insider error, natural events, system failure) and the vulnerabilities each could exploit.
  • Assessment of current security measures. Evaluate the controls you already have in place and whether they are configured and used correctly.
  • Likelihood and impact. For each threat-vulnerability pair, determine how likely it is to occur and what the impact on ePHI would be if it did.
  • Risk level. Combine likelihood and impact into a risk rating that lets you prioritize.
  • Documentation. Record the entire analysis. The Security Rule requires it to be written, and enforcement turns heavily on whether documentation exists.
  • Periodic review. Treat the assessment as living, and update it as your environment changes.

Those middle five points are what the People Also Ask box is reaching for when it asks what a risk assessment should include. HHS also publishes a HIPAA Security Risk Assessment tool aimed at small and medium practices, which is a reasonable starting scaffold, though larger or more complex environments usually need a more tailored approach.

How to do a HIPAA risk assessment, step by step

Turning the requirements into a process looks like this:

  1. Define scope. Decide what is being assessed, and make sure it covers every system that touches ePHI, including cloud services and subcontractors.
  2. Locate the ePHI. Build a data map of where PHI enters, where it is stored, how it moves, and where it leaves. This doubles as documentation you will reuse elsewhere.
  3. Identify threats and vulnerabilities. Work through technical, physical, and administrative angles: unpatched software, weak access controls, lost devices, phishing, misconfigured cloud storage.
  4. Assess existing controls. Note what protections are already in place and how effective they are.
  5. Rate likelihood and impact. Score each risk so you can compare them consistently.
  6. Assign risk levels and prioritize. High-likelihood, high-impact risks go to the top of the remediation list.
  7. Document everything. Capture the methodology, findings, and ratings in writing.
  8. Feed risk management. Turn the prioritized risks into a remediation plan with owners and timelines, then track it to completion.
  9. Review and update. Revisit on a schedule and after significant changes.

This process maps closely to the risk-based approach in SOC 2 and ISO 27001, which is why HealthTech companies pursuing multiple frameworks run a single assessment and apply it across all of them. We cover that reuse in SOC 2 and HIPAA compliance.

The four-factor breach risk assessment is a different thing

Here is a distinction that trips up a lot of teams. The word "risk assessment" in HIPAA refers to two entirely different exercises, and confusing them causes real errors.

The security risk analysis described above is proactive. It runs on a schedule and asks: what could go wrong with our ePHI, and how do we reduce that risk?

The four-factor risk assessment is reactive and lives in the Breach Notification Rule. When PHI is used or disclosed in a way that is not permitted, you run this four-factor test to decide whether the incident is a reportable breach requiring notification. The four factors are:

  1. The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification.
  2. The unauthorized person who used the PHI or to whom it was disclosed.
  3. Whether the PHI was actually acquired or viewed.
  4. The extent to which the risk to the PHI has been mitigated.

If that assessment shows a low probability that PHI was compromised, notification may not be required. This is a narrow, incident-specific test, and it does not replace the ongoing security risk analysis. Both exist; they answer different questions.

Why OCR cites the risk assessment most

Failure to conduct an accurate and thorough risk analysis is one of the most common findings in HIPAA enforcement. Regulators repeatedly point to it in settlements, often because an organization either never performed one, performed a superficial one, or performed one and then failed to act on the results.

The pattern is instructive. Many penalties follow a breach, but the finding is not only the breach; it is that the organization had never properly assessed the risk that led to it. A thorough, documented, and acted-upon risk assessment is both the best protection against incidents and the clearest evidence of good-faith compliance when regulators come asking.

For where the risk assessment sits inside a full audit, see the HIPAA compliance audit guide.


For the surrounding program, see the HIPAA service page and the HIPAA compliance checklist. For how the assessment reuses across frameworks, see SOC 2 and HIPAA compliance, and for the audit context, the HIPAA compliance audit guide.


Frequently Asked Questions

Does HIPAA require a risk assessment? Yes. The Security Rule explicitly requires an accurate and thorough assessment of the risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. It is foundational and non-optional, and failing to perform one is treated as a serious violation even absent a breach.

How often should a risk assessment be performed in HIPAA? HIPAA sets no fixed interval but requires periodic review and updates after significant changes. Most organizations run a full assessment at least annually and refresh it whenever they add a system, have an incident, or materially change how they handle PHI.

What are the five things a risk assessment should include? Define scope and inventory ePHI; identify threats and vulnerabilities; assess current security measures; determine likelihood and impact; and assign a risk level that drives remediation. Federal guidance adds documentation and periodic review around these.

How do you do a HIPAA risk assessment? Define scope, locate all ePHI, identify threats and vulnerabilities, assess existing controls, rate likelihood and impact, assign and prioritize risk levels, document everything, and feed the results into a risk management plan. The documentation is what proves the work was done.

What is the four-factor risk assessment in HIPAA? It is a separate breach-notification test, not the Security Rule risk analysis. After an impermissible use or disclosure, you weigh the nature of the PHI, who received it, whether it was actually acquired or viewed, and how well the risk was mitigated, to decide whether notification is required.


Ready to Run a Defensible HIPAA Risk Assessment?

ShieldKey Solutions conducts thorough, documented HIPAA risk assessments for HealthTech SaaS companies and business associates, then turns the findings into a prioritized risk management plan. We give you both the analysis regulators expect and the remediation that actually reduces your exposure.

Schedule a scoping call →