How to Perform a Successful HIPAA Risk Assessment? Explained

Data breach is one of the biggest challenges every industry is facing nowadays. However, the health industry is leading the chart with a probability of 69% of data breaches.
Healthcare organizations lose more than money when a data breach happens — they lose patient trust. A HIPAA risk assessment is the single most important exercise a covered entity or business associate can run to catch gaps before an attacker (or an auditor) finds them first. This guide walks through what a HIPAA risk assessment actually is, the exact steps to run one, and what's changing under the 2026 HIPAA Security Rule update — so your organization isn't caught off guard.
What is a HIPAA risk assessment?
A HIPAA risk assessment (also called a Security Risk Analysis or SRA) is a systematic review of how your organization creates, receives, stores, and transmits electronic protected health information (ePHI), and what could go wrong along the way. It's a core requirement of the HIPAA Security Rule's Administrative Safeguards, specifically the standard at 45 CFR § 164.308(a)(1)(ii)(A).
At its core, the assessment answers three questions:
- Where does ePHI live, and how does it move through your systems?
- What threats and vulnerabilities could expose, alter, or destroy that data?
- How likely is each threat, and how severe would the impact be?
Unlike a one-time compliance checkbox, a risk assessment is meant to be an ongoing process. Every new system, vendor, device, or workflow change introduces new risk, which is why HHS expects organizations to reassess regularly — not just once and forget it. Organizations that treat the SRA as a living document, rather than an annual paperwork exercise, are far better positioned when OCR (the HHS Office for Civil Rights) comes knocking after a breach.
Partner with Intercert to assess your risks, improve your security posture, and confidently Meet HIPAA Requirements.
Key Steps Involved in HIPAA Risk Assessments
A HIPAA risk assessment isn't a single task — it's a structured process made up of several distinct stages. Here's how to work through it properly.
Scope and Asset Inventory
Before you can protect ePHI, you need to know exactly where it exists. This step involves building a complete inventory of every system, application, device, and storage location that creates, receives, maintains, or transmits ePHI — EHR platforms, billing systems, email, cloud storage, mobile devices, medical equipment, and backup servers included.
Alongside the asset inventory, map the actual flow of data: who accesses it, how it moves between systems, and which third parties (billing vendors, cloud hosts, IT support) touch it along the way. Without this map, threats and vulnerabilities are almost impossible to assess accurately.
Identify Threats and Vulnerabilities
Once you know where ePHI lives, identify what could go wrong. Threats include external attackers, ransomware, insider misuse, natural disasters, and simple human error (a misdirected email, a lost laptop). Vulnerabilities are the weaknesses that let those threats succeed — unpatched software, weak passwords, missing encryption, or untrained staff.
A useful approach is to pair each asset from your inventory with the realistic threats that could affect it, then note any existing weaknesses that make that threat more likely to succeed.
Assess Risk Levels
Not every vulnerability deserves the same urgency. For each threat-vulnerability pair, estimate the likelihood of occurrence and the potential impact on confidentiality, integrity, or availability of ePHI. Combining likelihood and impact produces a risk rating (commonly low, medium, or high) that tells you where to focus first.
This is also where documentation matters most for audit purposes — OCR consistently cites incomplete or superficial risk-rating methodology as a top finding in enforcement actions.
Evaluate Current Safeguards
Next, look at what protections are already in place — administrative controls like policies and training, physical controls like facility access restrictions, and technical controls like encryption, access logging, and multi-factor authentication. The goal is to determine whether existing safeguards adequately reduce the risks identified in the previous step, or whether gaps remain.
Develop a Mitigation Plan
For every gap identified, define a corrective action, an owner, and a realistic timeline. High-risk items — say, an unencrypted database containing patient records — should be prioritized over lower-risk administrative gaps. A mitigation plan without assigned ownership and deadlines tends to stall, so treat this step as a project plan, not a wish list.
Document and Audit
Every stage above needs to be documented — the methodology used, the assets reviewed, the risks identified, the ratings assigned, and the remediation steps taken. This documentation is what you'll produce if OCR ever requests evidence of compliance, and it's also the baseline you'll compare against during your next assessment cycle.
What Are the Key Changes in the 2026 HIPAA Security Rule?
HHS has proposed the most significant overhaul of the HIPAA Security Rule since the 2013 HITECH update, driven largely by the surge in healthcare ransomware attacks and large-scale breaches like the 2024 Change Healthcare incident. As of mid-2026, these changes remain proposed rather than finalized — HHS has targeted finalization around May 2026, though the timeline has shifted before and could shift again, so organizations should treat the specifics below as directional rather than locked in.
The central theme of the update is the elimination of the "addressable" safeguard category. Historically, organizations could document why a safeguard like encryption or MFA wasn't "reasonable and appropriate" for their environment and skip it entirely. Under the proposed rule, nearly every technical safeguard becomes mandatory, with only narrow exceptions — closing a loophole that regulators believe contributed to major breaches where basic controls like MFA were simply never implemented.
Beyond eliminating the addressable category, the proposal also introduces written technology asset inventories and network maps, tighter oversight of business associates (including annual written verification of their safeguards), and compressed breach notification timelines. Organizations that wait for the final rule to start preparing are likely to face a compressed and costly scramble once the compliance clock starts.
What Are the Four Mandatory Technical Safeguards in the 2026 HIPAA Security Rule?
Four technical safeguards stand out as the backbone of the proposed update. Each moves from "addressable" or unspecified to explicitly mandatory.
Mandatory Multi-Factor Authentication (MFA)
Under the proposed rule, MFA becomes required for essentially all systems that access ePHI — EHR logins, VPNs, cloud platforms, and remote access alike. Password-only access, including shared logins, would no longer satisfy compliance. For clinical environments where speed matters, options like proximity badges or biometric authentication are commonly used to meet the requirement without slowing down care.
Encryption for Data at Rest and in Transit
Encryption also loses its "addressable" status. Stored patient records, databases, and backups (data at rest) and information moving between systems, such as emails and API calls (data in transit), would need to be encrypted with no general waiver process. Organizations with legacy systems that can't support modern encryption would need to upgrade, replace, or isolate them from ePHI entirely.
Annual Penetration Testing and Biannual Vulnerability Scanning
The proposed rule moves beyond passive documentation and requires organizations to actively test their defenses. Vulnerability scans would be required at least twice a year, and full penetration testing — actually attempting to exploit weaknesses rather than just identifying them — would be required annually. Results and remediation steps would need to be tracked and documented.
72-Hour Data Restoration Requirement
Contingency planning standards would require organizations to demonstrate they can restore access to critical systems containing ePHI within 72 hours of a disruption, such as a ransomware attack. This shifts contingency planning from a paper policy to something organizations must actually be able to prove works.
How Can Healthcare Organizations Prepare for the 2026 HIPAA Security Rule?
Waiting for the final rule before acting is a risky strategy — most of the proposed requirements are already recognized security best practices, so early movers reduce both cost and risk. A few practical starting points:
- Run a current-state gap analysis. Compare your existing safeguards against the proposed requirements to see where encryption, MFA, and testing gaps exist today.
- Prioritize MFA and encryption rollout. These are the two changes with the widest technical footprint and the longest implementation timelines, especially across legacy systems.
- Audit vendor and business associate agreements. Since business associates were responsible for a large share of breached records in recent years, confirm vendors can meet — and prove — the same technical standards you're held to.
- Build (or update) your asset inventory and network map. This is a foundational requirement for both the existing risk assessment standard and the proposed rule.
- Establish a testing cadence. Set up recurring vulnerability scans and schedule annual penetration testing now, rather than scrambling once a compliance deadline is set.
- Treat this as an ongoing program, not a project. The direction of the rule — continuous monitoring, annual audits, documented evidence — signals that one-time compliance efforts won't hold up long term.
Conclusion
A HIPAA risk assessment isn't just a regulatory checkbox — it's the foundation of a healthcare organization's entire security posture. Getting the fundamentals right — knowing where ePHI lives, identifying realistic threats, rating risk honestly, and closing gaps with a real mitigation plan — puts you ahead of both attackers and auditors. With the 2026 Security Rule update poised to make safeguards like MFA, encryption, and regular testing mandatory rather than optional, organizations that start strengthening their risk assessment process now will be far better positioned than those waiting for a final rule — or a breach — to force their hand.
Frequently Asked Questions
How do you conduct a HIPAA security risk analysis?
Conducting a HIPAA security risk analysis involves identifying every system, application, device, and location that stores, processes, or transmits electronic protected health information (ePHI). Next, identify potential threats and vulnerabilities, assess the likelihood and impact of each risk, evaluate existing security controls, develop a prioritized mitigation plan, and document the entire process. Smaller organizations may use the HHS Security Risk Assessment Tool, while larger organizations often follow frameworks such as NIST SP 800-30.
What is an example of an effective HIPAA risk assessment practice?
An effective HIPAA risk assessment assigns every identified risk to a specific owner with a defined remediation deadline. Organizations should also verify that corrective actions have been completed rather than simply documenting them. This approach demonstrates continuous risk management and strengthens compliance during OCR audits.
What are common HIPAA risk assessment mistakes?
Common mistakes include treating the assessment as a one-time compliance exercise, overlooking systems such as mobile devices, cloud services, or third-party vendors, using inconsistent risk ratings, failing to implement remediation plans, and relying on generic templates instead of conducting an organization-specific assessment. These gaps can increase security risks and create compliance issues during audits.
Is a HIPAA risk assessment only required once a year?
No. Although many organizations perform a comprehensive HIPAA risk assessment annually, the Security Rule requires organizations to reassess risks whenever significant changes occur. Examples include implementing new technologies, migrating to the cloud, onboarding new vendors, expanding facilities, or responding to a security incident. Continuous monitoring should complement annual assessments.
What are the five pillars of risk assessment?
The five core pillars of risk assessment are asset identification, threat identification, vulnerability identification, risk analysis, and risk mitigation. Together, these steps help organizations understand what needs protection, identify potential threats, prioritize risks based on likelihood and impact, and implement safeguards that reduce risks to an acceptable level while supporting HIPAA compliance.