1. Complete scope
Identify the systems, devices, cloud services, applications, vendors, locations, and workflows that create, receive, maintain, or transmit ePHI.
Healthcare Security & HIPAA
A HIPAA Security Rule risk analysis should identify where electronic protected health information exists, the threats and vulnerabilities that could affect it, the safeguards already in place, and the risks that require action. Small practices need a documented, repeatable process that reflects their actual systems, workforce, vendors, and care workflows.
A HIPAA risk analysis is the documented process of identifying and evaluating risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information. HHS does not prescribe one required methodology; the analysis should be accurate, thorough, and appropriate to the organization's size, complexity, capabilities, technology, and environment.
Identify the systems, devices, cloud services, applications, vendors, locations, and workflows that create, receive, maintain, or transmit ePHI.
Identify reasonably anticipated threats and vulnerabilities, evaluate the safeguards already operating, and determine the likelihood and potential impact of harmful events.
Translate findings into prioritized remediation with accountable owners, target dates, dependencies, and decisions about how each material risk will be reduced.
Retain the methodology, scope, findings, risk ratings, remediation decisions, implementation evidence, and review history so the practice can demonstrate how risks are being managed.
Document where ePHI enters the practice, where it is stored, who can access it, how it moves between systems, and which third parties or business associates interact with it.
Consider unauthorized access, phishing, ransomware, lost devices, weak authentication, unpatched systems, vendor failures, improper disposal, outages, and workflow weaknesses that could affect ePHI.
Document existing administrative, physical, and technical safeguards, then use a consistent method to evaluate the likelihood and impact of remaining risks rather than relying on informal impressions.
Assign treatment actions, verify that safeguards are implemented, record residual risk and management decisions, and revisit the analysis when systems, vendors, locations, workflows, threats, or the practice materially change.
This guide is based on the current HIPAA Security Rule and HHS risk-analysis guidance. HHS proposed substantial Security Rule changes in January 2025, but those changes remain proposed as of this review. Practices should distinguish current obligations from proposed requirements and monitor HHS for final-rule updates.
Connect the risk analysis to the practice's broader security program, risk-management process, remediation work, and readiness assessment.
Last reviewed August 10, 2026. This guide reflects the current HIPAA Security Rule and HHS risk-analysis guidance. The January 2025 Security Rule changes remain proposed as of this review.
Use the free HIPAA Security Readiness Assessment to review risk management, ePHI protection, workforce access, technical safeguards, incidents, and contingency planning. If gaps need implementation work, explore HIPAA Security Operations.