Healthcare Security & HIPAA

How to Perform a HIPAA Security Risk Analysis for a Small Healthcare Practice

A HIPAA Security Rule risk analysis should identify where electronic protected health information exists, the threats and vulnerabilities that could affect it, the safeguards already in place, and the risks that require action. Small practices need a documented, repeatable process that reflects their actual systems, workforce, vendors, and care workflows.

Direct answer

What is a HIPAA Security Rule risk analysis?

A HIPAA risk analysis is the documented process of identifying and evaluating risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information. HHS does not prescribe one required methodology; the analysis should be accurate, thorough, and appropriate to the organization's size, complexity, capabilities, technology, and environment.

Four outputs a useful risk analysis should produce

1. Complete scope

Identify the systems, devices, cloud services, applications, vendors, locations, and workflows that create, receive, maintain, or transmit ePHI.

2. Documented risks

Identify reasonably anticipated threats and vulnerabilities, evaluate the safeguards already operating, and determine the likelihood and potential impact of harmful events.

3. Prioritized treatment

Translate findings into prioritized remediation with accountable owners, target dates, dependencies, and decisions about how each material risk will be reduced.

4. Evidence for review

Retain the methodology, scope, findings, risk ratings, remediation decisions, implementation evidence, and review history so the practice can demonstrate how risks are being managed.

How to perform the analysis

Map ePHI and the environment

Document where ePHI enters the practice, where it is stored, who can access it, how it moves between systems, and which third parties or business associates interact with it.

Identify threats and vulnerabilities

Consider unauthorized access, phishing, ransomware, lost devices, weak authentication, unpatched systems, vendor failures, improper disposal, outages, and workflow weaknesses that could affect ePHI.

Evaluate safeguards and risk

Document existing administrative, physical, and technical safeguards, then use a consistent method to evaluate the likelihood and impact of remaining risks rather than relying on informal impressions.

Remediate and reassess

Assign treatment actions, verify that safeguards are implemented, record residual risk and management decisions, and revisit the analysis when systems, vendors, locations, workflows, threats, or the practice materially change.

Current rule versus proposed changes

This guide is based on the current HIPAA Security Rule and HHS risk-analysis guidance. HHS proposed substantial Security Rule changes in January 2025, but those changes remain proposed as of this review. Practices should distinguish current obligations from proposed requirements and monitor HHS for final-rule updates.

Related HIPAA security guidance

Connect the risk analysis to the practice's broader security program, risk-management process, remediation work, and readiness assessment.

Primary sources used for this guidance

Last reviewed August 10, 2026. This guide reflects the current HIPAA Security Rule and HHS risk-analysis guidance. The January 2025 Security Rule changes remain proposed as of this review.

Assess your HIPAA security readiness

Use the free HIPAA Security Readiness Assessment to review risk management, ePHI protection, workforce access, technical safeguards, incidents, and contingency planning. If gaps need implementation work, explore HIPAA Security Operations.