What Is a HIPAA Risk Assessment — and How Often Does Your Practice Need One?

The HIPAA Security Rule has required covered entities to conduct a risk assessment since the rule took effect in 2005. Yet it remains one of the most misunderstood and inconsistently performed obligations in healthcare compliance. Many practices believe they’ve completed one when they haven’t — because they completed a checklist, signed a form, or had their IT vendor run a scan. Those activities may be useful, but they are not a HIPAA risk assessment as the regulation defines it. Here’s what the requirement actually involves.
What the Security Rule Actually Requires
The HIPAA Security Rule at 45 CFR § 164.308(a)(1) requires covered entities to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all electronic Protected Health Information (ePHI) that the organization creates, receives, maintains, or transmits. This is a required implementation specification — not addressable, not optional. The HHS Office for Civil Rights (OCR) has cited failure to conduct an adequate risk analysis as a finding in a substantial number of enforcement actions, including many involving smaller covered entities.
What a Risk Assessment Must Include
OCR has published detailed guidance on the required elements of a HIPAA risk analysis. At minimum, it must include:
Scope: Identify all ePHI your organization creates, receives, maintains, or transmits across all systems — EHR, email, billing, mobile devices, cloud storage, and any third-party systems that touch patient data
Threat and vulnerability identification: Identify reasonably anticipated threats to ePHI and vulnerabilities in your current systems and processes — both technical (unpatched software, missing MFA) and non-technical (inadequate workforce training, lack of access controls)
Current controls assessment: Evaluate the security measures your practice already has in place and assess whether they are sufficient to address the identified threats and vulnerabilities
Likelihood and impact analysis: For each identified threat-vulnerability pair, assess how likely it is to occur and what the potential impact would be on ePHI confidentiality, integrity, and availability
Risk level assignment and documentation: Assign a risk level to each identified risk and document your findings in a form that you can use to prioritize and track remediation
How Often Is It Required?
The Security Rule does not specify a fixed frequency — it requires that the risk analysis be reviewed and updated periodically in response to environmental or operational changes. In practice, this means you should update your risk analysis whenever significant changes occur: when you adopt a new EHR system, add a new location, onboard a new vendor who will access ePHI, experience a security incident, or significantly change your workflows. OCR’s guidance suggests that most practices should conduct or update their risk analysis at least annually, not because the regulation says “annually” but because a year is a reasonable maximum interval before the environment has changed enough to make an older analysis unreliable.
What Documentation It Should Produce
A completed HIPAA risk assessment should produce a written document — not just a vendor scan report or a checklist — that covers the scope of ePHI in your environment, the threats and vulnerabilities identified, the current controls in place, the assigned risk levels, and the remediation steps you plan to take. This document is what OCR expects to review in the event of an audit or breach investigation. A risk assessment that was never documented is difficult to demonstrate after the fact.
The Most Common Gaps
Small practices most often fall short in these ways:
Confusing a vulnerability scan with a risk assessment. A technical scan of your network identifies software vulnerabilities — it does not assess the full range of threats to ePHI, evaluate administrative controls, or document risk levels in the way the Security Rule requires.
Incomplete scope. The assessment only covers the EHR system and misses email, billing software, portable devices, paper-to-digital workflows, or third-party vendors with ePHI access.
No documented output. The assessment was done verbally or informally — there is no written record of findings, risk levels, or remediation plans that could be produced in response to an OCR request.
Never updated. The risk analysis from 2018 is still in the file, unchanged, despite two EHR migrations and the addition of a telehealth platform since then.
Treating it as a standalone event. The risk assessment is supposed to feed into your risk management program — meaning the findings produce a remediation plan with assigned responsibilities and timelines. An assessment that identifies gaps and produces no action is not compliant with the spirit or the letter of the rule.
If your practice hasn’t completed a HIPAA risk assessment, hasn’t updated one in several years, or isn’t certain the one in your files meets the Security Rule’s requirements, DataMoat can conduct a formal assessment and deliver the documented findings your practice needs for compliance and for the next time someone asks.
Read other blogs
Stay informed with our latest articles on compliance, security, and risk management.


