HIPAA Security Risk Analysis: What It Means for Your Organization

If your organization is a HIPAA covered entity or business associate and creates, receives, keeps or sends electronic patient information, the HIPAA Security Rule requires you to conduct an accurate and thorough risk analysis. It is the starting point for every safeguard you put in place. There is no small-practice exemption and no fixed schedule, but the analysis has to reflect how your organization actually works today. ALCON DTS helps you complete it, act on what it finds and keep it current.

Talk with ALCON DTSSee what you need in place

At a glance

  • Requirement: HIPAA Security Rule, risk analysis, 45 CFR 164.308(a)(1)(ii)(A). It is labeled “Required,” not addressable.
  • Who it applies to: HIPAA covered entities (health plans, health care clearinghouses and most health care providers) and their business associates
  • What it covers: All electronic protected health information (ePHI) you create, receive, maintain or transmit
  • How often: The rule sets no fixed interval. It requires an accurate and thorough assessment, and HHS says the process “should be ongoing.” You review and update your documentation as your environment or operations change (164.316(b)(2)(iii)), keep it for six years (164.316(b)(2)(i)), and perform periodic evaluations (164.308(a)(8)).
  • Enforced by: the HHS Office for Civil Rights (OCR)
  • Official text: 45 CFR 164.308 on eCFR
  • Last reviewed: September 30, 2026

What is a HIPAA security risk analysis?

The HIPAA Security Rule asks you to protect electronic patient information with administrative, physical and technical safeguards. The risk analysis is how you decide which safeguards you need. The rule states it this way:

“Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate.” (45 CFR 164.308(a)(1)(ii)(A))

HHS calls this “the first step in identifying and implementing safeguards that comply with and carry out the standards and implementation specifications in the Security Rule.” The rule does not tell you which method to use. In HHS’s words, “the Security Rule does not prescribe a specific risk analysis methodology,” and “there is no single method or ‘best practice’ that guarantees compliance.” What it does set are the objectives any method must meet, which are listed below. If you want more detail on methods, NIST SP 800-66 Rev. 2 (February 2024) provides practical guidance and resources that regulated entities of all sizes can use to safeguard ePHI.

The risk analysis sits next to a second required step: risk management. Once you know your risks, you must “implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with ยง 164.306(a)” (45 CFR 164.308(a)(1)(ii)(B)). The analysis tells you what to fix; risk management is the fixing.

What does the risk analysis cover, and what doesn’t it?

It covers: electronic protected health information, and all of it. HHS guidance says: “All e-PHI created, received, maintained or transmitted by an organization is subject to the Security Rule.” That includes patient information on a single workstation, on laptops and phones, in email, in file storage, in backups and on portable media, whatever the source or location.

It is not:

  • A HIPAA Privacy Rule assessment. The risk analysis is a Security Rule requirement about electronic patient information. Paper records, patient rights and use and disclosure questions fall under the Privacy Rule and need their own review.
  • A certification. Completing a risk analysis does not make your organization “HIPAA certified.” It is a required assessment you document and keep.
  • A one-time checkbox. HHS says “The risk analysis process should be ongoing.” A document from several years and several systems ago may no longer describe your environment.
  • The same as a gap assessment. A checklist of which Security Rule controls you have in place can be useful, but OCR has explained that a gap analysis may not satisfy the risk analysis requirement because, for example, it does not assess the risks to all of the ePHI you create, receive, maintain or transmit (OCR Cybersecurity Newsletter, April 2018, “Risk Analyses vs. Gap Analyses: What is the difference?”).

Does the risk analysis requirement apply to you?

The requirement applies to both groups the Security Rule covers:

  1. Covered entities. Health plans, health care clearinghouses and most health care providers. Clinics, practices, imaging centers and similar providers usually fall here.
  2. Business associates. Organizations that create, receive, maintain or transmit protected health information on behalf of a covered entity, such as billing services, administrators and IT providers. OCR has resolved risk analysis investigations with business associates as well as providers and health plans (HHS press release, April 23, 2026).

Quick check: does this apply to you?

  • You are a HIPAA covered entity (a health plan, a health care clearinghouse, or a health care provider that conducts standard transactions such as insurance billing electronically), or you create, receive, maintain or transmit patient information on behalf of one.
  • You hold any patient information electronically: in an EHR, email, file shares, scanned documents, backups or devices.

If both are true, the risk analysis requirement very likely applies to you. Only health care providers that bill or conduct other standard transactions electronically are covered entities. If you are unsure whether you are a covered entity or business associate, confirm with your attorney.

There is no small-practice exemption. A two-provider clinic has the same duty to complete a risk analysis as a large system. What changes with size is how you meet it. The Security Rule is flexible by design. Under 45 CFR 164.306(b), you may use any security measures that allow you to reasonably and appropriately implement the standards, and you must take into account:

  • your size, complexity and capabilities,
  • your technical infrastructure, hardware and software security capabilities,
  • the costs of security measures, and
  • the probability and criticality of potential risks to ePHI.

HHS notes that small organizations “tend to have fewer variables (i.e. fewer workforce members and information systems) to consider,” so the right safeguards for a small practice may differ from those for a large one. The analysis still has to cover all of your ePHI.

What do you need to have in place?

HHS guidance lists the elements a risk analysis must incorporate, “regardless of the method employed.” The table below follows those elements and shows how each one scales with your size and complexity.

Elements from the HHS Guidance on Risk Analysis and 45 CFR 164.308(a)(1)(ii). The scaling columns are general illustrations of the flexibility in 45 CFR 164.306(b), not requirements of the rule.
Element (HHS guidance) What it asks of you Smaller, simpler practice Larger or more complex organization
Scope of the analysis Consider risks to all ePHI you create, receive, maintain or transmit, in every form of electronic media A handful of workstations, laptops, phones, email and backups Multiple locations, networks, systems and outside parties that handle ePHI
Data collection Identify where ePHI is stored, received, maintained or transmitted, and document it Walk through each device, system and vendor that touches patient information Interviews, project and documentation reviews across departments and sites
Threats and vulnerabilities Identify and document reasonably anticipated threats and the vulnerabilities they could exploit Common human, natural and environmental threats to a single office A broader set of threats unique to each environment and site
Current security measures Assess and document the measures you use, whether required measures are in place and whether they are configured and used properly Fewer systems to check, often with more direct control More systems, owners and configurations to verify
Likelihood Estimate how likely each threat and vulnerability combination is, and document it Estimates for a shorter list of combinations Estimates across a longer list of combinations
Impact Assess the potential impact of each combination, using a qualitative or quantitative method or both A qualitative scale is often enough Qualitative, quantitative or a combination
Risk level Assign a risk level to every combination and produce a list of corrective actions A short, ranked list of corrective actions A ranked list of corrective actions by system, site or owner
Documentation Document the risk analysis in any format, and keep it for six years (164.316) A written report with supporting records A formal report tied to each area’s records
Periodic review and updates Keep the process ongoing and update it after changes such as a security incident, a change in ownership, turnover in key staff or management, or new technology Review on a regular cycle you choose and after any change A regular cycle built into planning for new systems and operations
Risk management (164.308(a)(1)(ii)(B)) Implement security measures that reduce the risks you found to a reasonable and appropriate level Work through the corrective action list in order of risk A tracked plan with owners and target dates

Is the free HHS tool enough?

ONC, in collaboration with the HHS Office for Civil Rights (OCR), offers a free Security Risk Assessment (SRA) Tool. It can be a good way to organize your first analysis. Keep two points from the tool’s own page in mind: “The target audience of this tool is medium and small providers; thus, use of this tool may not be appropriate for larger organizations,” and “the SRA Tool survey alone may not identify all risks present in an organization.” Using the tool does not by itself establish compliance. The tool’s own disclaimer says: “Use of this tool is neither required by nor guarantees compliance with federal, state or local laws.”

How do you keep it current?

The Security Rule does not set a schedule. HHS says: “The Security Rule does not specify how frequently to perform risk analysis as part of a comprehensive risk management process.” It adds that some organizations perform these processes annually or as needed, depending on their circumstances. Three parts of the rule shape your review cycle:

  • Documentation review (164.316(b)(2)(iii)). Review your documentation periodically and update it as needed in response to environmental or operational changes affecting the security of ePHI.
  • Retention (164.316(b)(2)(i)). Keep required documentation for six years from the date it was created or the date it was last in effect, whichever is later.
  • Evaluation (164.308(a)(8)). Perform a periodic technical and nontechnical evaluation, based first on the Security Rule’s standards and then in response to environmental or operational changes affecting the security of ePHI, to establish how well your security policies and procedures meet the rule.

A practical approach is to pick a regular review cycle that fits your practice and also revisit the analysis whenever something important changes: a new system, a new location, an incident or a change in leadership.

How can ALCON DTS help you?

You keep the legal decisions, we run the controls. We complete the security risk analysis with you, turn what it finds into a work plan, run the safeguards that address it, and keep the records in one evidence file, so you have a clear picture when your attorney, insurer or OCR asks.

Risk analysis element What ALCON DTS provides
Scope and data collection A security risk analysis that maps where patient information lives across email, devices, file storage and backups
Threats and vulnerabilities A review of the threats that matter for your practice, including account takeover, business email compromise, ransomware, lost or unmanaged devices and vendor access
Current security measures A review of identity and access, email, devices, backups and vendor access, so you know what is logged, what is backed up and who can restore
Likelihood, impact and risk level A work plan that puts the most important risks first, with a snapshot leadership can use
Documentation An organized evidence file with your risk analysis, business associate agreements, training records and written procedures, plus policies covering HIPAA Security and Omnibus
Risk management (164.308(a)(1)(ii)(B)) Identity and access with multifactor authentication and tight administrator rights; email authentication and mailbox controls; devices kept updated, protected and encrypted; tested backup and recovery; and monitoring that routes alerts to a named owner
Workforce training New-hire and annual HIPAA security training with completion records. Texas Chapter 181 separately requires training on state and federal law for new hires within 90 days (see below)
Business associate agreements A business associate agreement with ALCON DTS wherever our services require one
Periodic review and updates A risk analysis kept current as part of an ongoing relationship, revisited when your systems, locations or staff change

Your EHR, billing and hospital platforms stay with the vendors who own them. We work alongside them on the systems around them. The exact controls in your environment depend on your ALCON DTS plan and any project work, and we will show you which are in place today and which would close a gap.

A risk analysis from ALCON DTS does not make your organization HIPAA certified, and we do not claim a HIPAA certification. It gives you a documented, current assessment and a plan you can act on.

Want to know where your risk analysis stands? We will look at what you have today, where patient information lives and what would bring the analysis up to date.

Talk with ALCON DTS

How does the risk analysis fit with other rules?

  • Texas Cybersecurity Safe Harbor (SB 2610, Bus. and Com. Code Ch. 542). Texas business entities with fewer than 250 employees that own or license computerized data that includes sensitive personal information (Sec. 542.002) can qualify for a defense against exemplary damages in a breach lawsuit by maintaining a qualifying cybersecurity program. HIPAA is one of the laws that program must also conform to if your organization is subject to it (Sec. 542.004(b)(2)(A)). A current HIPAA risk analysis is a natural part of that program. See Texas SB 2610 Cybersecurity Safe Harbor.
  • Texas breach notification law (Bus. and Com. Code Sec. 521.053). If you conduct business in Texas and own or license computerized data that includes sensitive personal information (which in Texas includes health information that identifies a person), you must notify affected individuals without unreasonable delay and no later than 60 days after determining the breach occurred. If you maintain that data for someone else, you must notify the owner immediately after discovering the breach. If at least 250 Texas residents are involved, you must also notify the Texas Attorney General no later than 30 days after that determination. Texas also requires businesses to implement and maintain reasonable procedures to protect sensitive personal information (Sec. 521.052).
  • Texas medical records privacy law (Texas Health and Safety Code Ch. 181, Medical Records Privacy, as amended by HB 300 in 2011). Texas defines “covered entity” more broadly than HIPAA, including anyone who comes into possession of protected health information (Sec. 181.001). Chapter 181 requires each covered entity to train employees on state and federal law concerning protected health information, as necessary and appropriate for their duties, within 90 days of hire. Employees whose duties are affected by a material change in the law must be retrained within a reasonable period, and no later than one year after the change takes effect. Each employee signs a statement verifying the training, which the entity keeps for six years (Sec. 181.101). Chapter 181 also requires notice to individuals when their protected health information is subject to electronic disclosure (Sec. 181.154), and, since September 1, 2025, most covered entities must post instructions on their website and at their facilities for requesting health records, contacting their licensing authority and filing a complaint (Sec. 181.105). The Texas Attorney General can seek injunctions and civil penalties (Sec. 181.201), and state licensing agencies can discipline licensed entities (Sec. 181.202). Your risk analysis and training program can support both HIPAA and Chapter 181. Talk with your attorney about how Chapter 181 applies to you.
  • HIPAA Consulting. The risk analysis, policies, training and evidence file that make up your day-to-day HIPAA Security program.
  • Healthcare IT. The managed IT and security work that carries out your risk management plan every day.
  • Proposed Security Rule changes. On January 6, 2025, HHS published a proposed rule, “HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information” (90 FR 898). The comment period closed March 7, 2025. As of September 30, 2026, no final rule has been published in the Federal Register, so the current Security Rule, including the risk analysis requirement described on this page, remains the rule you follow.

Frequently asked questions

Yes. It is a required implementation specification under 45 CFR 164.308(a)(1)(ii)(A) for covered entities and business associates. It is not one of the “addressable” specifications.

The Security Rule sets no fixed interval. HHS says the process “should be ongoing” and notes that some organizations perform it annually or as needed, depending on their circumstances. Review and update it when your environment or operations change, such as after a security incident, a change in ownership, turnover in key staff or new technology.

No. Every covered entity and business associate must complete a risk analysis. The rule is scalable under 45 CFR 164.306(b), so the methods and safeguards can fit your size, complexity, capabilities and costs, but the analysis still has to cover all of your ePHI.

Yes, and many small and medium practices do. The tool’s own page says it is aimed at medium and small providers, may not be appropriate for larger organizations, and that its survey alone may not identify all risks. Treat it as a way to organize the work, then confirm it covers every place your patient information lives.

Not on its own. A gap assessment shows which controls you have in place. OCR has explained that a gap analysis may not satisfy the risk analysis requirement because, for example, it does not assess the risks to all of the ePHI you create, receive, maintain or transmit.

Six years from the date it was created or the date it was last in effect, whichever is later (45 CFR 164.316(b)(2)(i)). Superseded versions must also be kept for six years from the date they were last in effect.

No. The risk analysis is a required assessment, not a certification. It gives you a documented understanding of your risks and the basis for your risk management plan.

HHS proposed changes to the Security Rule in January 2025. As of September 30, 2026, those changes are still a proposal and no final rule has been published. The current rule, including the risk analysis requirement, applies today.

Sources

Last reviewed: September 30, 2026

This page is general information about the HIPAA Security Rule and related Texas law, not legal advice for your situation.

Talk with ALCON DTS about your risk analysis

Not sure when your risk analysis was last updated, or whether it covers every place your patient information lives? We will walk through what you have, show you what is current and give you a clear plan for the rest.

Email: info@alcondts.com ยท Phone: 512-892-6900

Talk with ALCON DTS