Methodology

HIPAA Compliance Security Risk Assessment Methodology

How One Guy Consulting performs a HIPAA Security Risk Assessment, step by step, from asset inventory through annual review. See the methodology, the deliverables, and what to do if your clinic has not started yet.

What Is a Security Risk Assessment?

A Security Risk Assessment (SRA) is the process of finding threats and weak points that could put electronic protected health information (ePHI) at risk. The HIPAA Security Rule at 45 CFR §164.308(a)(1)(ii)(A) requires every covered entity and business associate to complete one.

This applies to any organization that handles ePHI, including:

  • Physician practices, dental offices, and behavioral health providers
  • Pharmacies and billing companies
  • IT vendors, cloud storage providers, and other business associates

There is no size exemption. A solo practitioner has the same obligation as a hospital system. The scope of the assessment will differ, but the requirement does not.

Why is this the most commonly cited deficiency? OCR enforcement data shows that a missing or incomplete SRA is one of the top findings in HIPAA audits and investigations. Without one, your organization cannot prove it has identified the risks the Security Rule requires you to manage.

How One Guy Consulting Performs a Security Risk Assessment

This 8-step process follows the NIST SP 800-30 Rev. 1 framework and maps directly to the HIPAA Security Rule. Each step produces documented evidence you can retain per §164.530(j) and present during an OCR audit.

1

Scope and Asset Inventory

List every system, device, app, and location that creates, receives, stores, or sends ePHI. Common examples include EHR systems, email, fax, mobile devices, cloud storage, and backup media. Then map how data flows between these systems and where ePHI sits at rest and in transit.

2

Threat Identification

List the threats that could affect your ePHI, grouped into three categories per NIST SP 800-30 Rev. 1:

  • Natural — floods, storms, power outages
  • Human — unauthorized access, ransomware, phishing, insider misuse
  • Environmental — hardware failure, building access issues, HVAC problems

Document each threat source and the events it could trigger in your environment.

3

Vulnerability Assessment

Check your current safeguards against the HIPAA Security Rule requirements:

  • §164.308 — Administrative safeguards
  • §164.310 — Physical safeguards
  • §164.312 — Technical safeguards

Flag gaps where controls are missing or weak. Common issues include missing encryption, no access controls, absent audit logs, untrained staff, and unsecured workstations.

4

Risk Determination

Score each threat-vulnerability pair using a risk matrix. Rate how likely each threat is to occur and how severe the impact would be if ePHI were compromised. Then combine those scores to label each risk as high, medium, or low. This tells you where to focus your resources first.

5

Control Recommendations

Match each finding to a safeguard that would bring the risk down to a reasonable level per §164.306(b). Every recommendation fits your organization's size and budget. For a small practice, that might mean turning on encryption in your existing EHR rather than buying new hardware.

6

Documentation and Evidence Packaging

Package all findings into a formal report that meets the retention rules of §164.530(j). You must keep this documentation for at least six years and have it ready if OCR requests it. The report covers your scope, asset inventory, threat catalog, vulnerability findings, risk scores, and recommended fixes.

7

Remediation Planning

Build a prioritized action plan with clear deadlines, owners, and milestones. High-risk findings get immediate attention. Medium and low risks are scheduled within set timeframes. This plan becomes a living document that tracks your progress and shows ongoing compliance effort.

8

Annual Review Cycle

The SRA is not a one-time project. HHS expects you to reassess risks on a regular basis. Run a new review when:

  • You add or change systems that handle ePHI
  • You bring on new vendors or business associates
  • Staff turnover changes who has access to patient data
  • New threats emerge (e.g., a new type of ransomware attack)

Most compliance programs do a full reassessment once a year, with smaller reviews as changes come up.

What Deliverables You Receive

Every SRA engagement produces concrete, documented outputs. These are the records you keep for OCR and the tools you use to fix what needs fixing.

Written Risk Assessment Report

Covers scope, methods, findings, risk scores, and recommended fixes. This is your primary proof of compliance under §164.308(a)(1)(ii)(A).

Asset and ePHI Flow Inventory

A full list of every system, device, and app that handles ePHI, plus data flow diagrams showing how patient information moves through your environment.

Threat and Vulnerability Register

A structured list of every threat and vulnerability we found, mapped to the specific systems and ePHI they could affect.

Risk Scoring Matrix

A likelihood-by-impact grid with risk levels for every finding. Makes it clear which risks need immediate attention and which can wait.

Prioritized Remediation Plan

A step-by-step action plan with tasks, deadlines, and owners for each finding. Sorted by risk level so you tackle the biggest issues first.

Evidence Documentation Package

All supporting evidence organized for §164.530(j) retention: completed worksheets, control evaluation notes, screenshots, and configuration records from the assessment.

What to Do If Your Clinic Has No Risk Assessment

If your clinic has no risk assessment or written policies, start now. You do not need to be perfect on day one. What matters is taking the first step and building from there.

Here is a practical starting sequence:

  1. List every system that touches ePHI — your EHR, email, fax, cloud storage, mobile devices, and any vendors who see patient data.
  2. Identify your biggest risks — unencrypted devices, no access controls, missing backups, and untrained staff.
  3. Put your policies in writing — even basic written policies for access control, breach response, and device management put you ahead of having nothing.
  4. Assign a Security Officer§164.308(a)(2) requires someone to own your security program.
  5. Train your workforce§164.308(a)(5)(i) requires training for everyone with access to PHI.
  6. Get help if you need it — a consultant can walk you through the process and produce the required documentation.

The cost of doing nothing is higher than the cost of starting. OCR has fined organizations of all sizes for skipping the risk assessment. Starting the process — even if it is not perfect — shows good-faith effort. That is far better than having nothing on file.

Security Risk Assessment Questions

If your clinic has no HIPAA risk assessment or written policies yet, start with a Security Risk Analysis now: identify where PHI is stored and transmitted, list your vendors and devices, document the main risks, then put the required policies and procedures in writing and assign someone responsible for security. HHS says regulated entities must periodically assess how well their policies and safeguards meet the Security Rule, and ONC/HHS offers a Security Risk Assessment Tool to help get started. One Guy Consulting can walk you through the full process with a hands-on Security Risk Assessment and custom policy development.
The HIPAA Security Rule at 45 CFR §164.308(a)(1)(ii)(A) requires covered entities and business associates to conduct an accurate and thorough assessment of potential risks and vulnerabilities to ePHI. While the rule does not specify a fixed frequency, HHS guidance and OCR enforcement actions make clear that this is an ongoing obligation, not a one-time task. Most compliance frameworks recommend conducting a full Security Risk Assessment at least annually, and whenever significant changes occur to systems, workflows, or the threat environment.
A Security Risk Assessment identifies threats and vulnerabilities to electronic protected health information and evaluates the likelihood and impact of those threats materializing. It is required by 45 CFR §164.308(a)(1)(ii)(A). A gap analysis maps your current controls, policies, and procedures against the full scope of HIPAA requirements, including the Privacy Rule, Security Rule, and Breach Notification Rule, to identify where your compliance program falls short. Both are valuable: the SRA focuses on risk to ePHI specifically, while the gap analysis gives a broader view of overall compliance posture.
One Guy Consulting offers full-scope HIPAA compliance help for small practices and business associates, including security risk assessments under 45 CFR §164.308(a)(1)(ii)(A), gap analysis and remediation plans, custom policies and procedures per §164.316(a), staff training per §164.308(a)(5)(i), IT and physical audits under §164.310 and §164.312, vendor and BAA management per §164.502(e), incident management and breach notification support per §164.404(b), and audit-response documentation per §164.530(j). Everything is included in one flat annual rate with no per-user fees.

Learn More About HIPAA Risk Assessments

Ready to Start Your Security Risk Assessment?

Book a free 30-minute intro call. We will review your current compliance status and walk you through how the assessment process works for your practice.

Book Your Free 30 Minute HIPAA Compliance Review