ComplianceTemplate3 min readUpdated September 2026

HIPAA Security Risk Assessment: A Worksheet for Small Teams

A HIPAA security risk assessment is a documented analysis of where electronic protected health information (ePHI) lives, what could threaten it, and how likely and damaging each threat is. The Security Rule expects covered entities and business associates to do one, act on it and keep it current.

You can run a first pass with a spreadsheet and a few working sessions. This guide walks through the steps and the columns to use. It isn't legal advice, so have a qualified HIPAA adviser review the result.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Does your company need a HIPAA risk analysis?

If you're a covered entity (a provider, health plan or clearinghouse) or a business associate that creates, receives, maintains or transmits ePHI for one, the Security Rule applies to you, and a risk analysis is a required part of it. A software company that stores patient data on behalf of a clinic is usually a business associate.

Two details trip up startups. First, a customer's contract may impose extra duties through a business associate agreement. Second, the risk analysis isn't a one-time exercise: repeat it when you add systems, change vendors or after a significant incident, and at regular intervals you set. HIPAA also expects you to keep the documentation for six years, so store each version. If you're unsure whether you're a business associate, ask an attorney.

How do you run the assessment in six steps?

Work through these in order:

  1. Define scope. List every system, location and person that touches ePHI, including laptops, backups, logs and third-party services.
  2. Map the data flow. Draw where ePHI enters, where it's stored, who can see it and where it leaves.
  3. Identify threats and vulnerabilities. For each system, list what could go wrong: lost devices, misconfigured storage, phishing, excessive access, vendor breach.
  4. Record current safeguards. Encryption, access controls, audit logs, backups and training already in place.
  5. Rate likelihood and impact. Use a simple scale, such as low, medium, high, and combine the two into a risk level.
  6. Plan and track remediation. Assign each significant risk an owner, an action and a date, and record decisions to accept a risk.

HHS publishes guidance on risk analysis and offers a free Security Risk Assessment Tool. Check what's current before you rely on either.

A worksheet layout you can copy into a spreadsheet

Give each row one asset and threat pair, with these columns:

  • Asset. For example, the production database that holds appointment notes.
  • Where ePHI is stored or moves. Region, service, backups, exports.
  • Threat or vulnerability. For example, public access from a misconfigured storage bucket.
  • Existing safeguards. Encryption at rest, private network, access logging.
  • Likelihood and impact. Each rated low, medium or high.
  • Risk level. The combined rating.
  • Action. Fix, transfer, accept or monitor, with an owner.
  • Due date and status.

For example, say the row is an engineer's laptop with a local copy of a patient export. The threat is device loss, the safeguard is disk encryption, and the action might be to stop exports to laptops entirely. That single change removes the risk rather than managing it.

What do assessors and customers look for?

Reviewers usually check three things: that the assessment covers all ePHI (including backups and vendors), that risks were rated by a method you can explain, and that findings turned into tracked action.

The most common gaps:

  • Missing vendors. Your analytics tool, logging service or email provider may see ePHI. Confirm a business associate agreement exists with each that does.
  • Shadow copies. Exports, test databases seeded from production and support screenshots.
  • No follow-through. A long list of high risks with no owners or dates.
  • Stale analysis. A document from two systems ago.

A vendor inventory helps here, and the vendor risk assessment template shows how to evaluate each supplier. Answers you write for customers should match this analysis, so keep your security questionnaire answers consistent with it.

How do you keep it current without a big project each year?

Make small updates part of normal change. Add a checkbox to your architecture review: does this change how ePHI is stored, accessed or shared? If yes, update the analysis row and the data flow map. Review open risks monthly, and schedule a full refresh at the interval you've written in your information security policy.

Compliance platforms such as Vanta or Drata can help you keep control status, vendor reviews and training records together, which may supply evidence for the safeguards column. Confirm in a demo what it covers for HIPAA. They don't perform the risk analysis for you, because judging likelihood and impact for your systems is your team's work. Pair the analysis with security awareness training for everyone who handles ePHI.

Executive Capability Standard

What Good Looks Like

You can point to a dated risk analysis covering every system and vendor that touches ePHI, with owners and due dates on each significant risk.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Confirm with counsel whether you're a covered entity or business associate, and read the Security Rule's risk analysis requirement.
2. Do Manually:Inventory ePHI locations and fill in the worksheet for your top five systems in one working session.
3. Delegate:Give a named compliance owner the monthly risk review and have a HIPAA adviser review the ratings annually.
4. Automate:Add an ePHI impact check to architecture reviews and pull access lists and configuration evidence from your tools on a schedule.
5. Buy:Add a compliance platform to track controls and vendors, and engage a HIPAA specialist for the analysis itself when scope grows.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

Is a HIPAA risk assessment legally required?

Yes for covered entities and business associates. The Security Rule requires an accurate and thorough analysis of risks to ePHI, and you must act on it. If you're unsure whether the rule applies to your company, ask a healthcare attorney or a qualified HIPAA adviser.

How often should we update our HIPAA risk analysis?

Update it when you introduce new systems or vendors, after significant incidents and at regular intervals you define in policy. Many organizations review yearly. Keep each version, since HIPAA expects documentation to be retained for six years.

Can we do the HIPAA risk assessment ourselves?

Yes, many small teams do a first pass internally using a structured worksheet or the free HHS tool. Have a qualified HIPAA professional review it, especially the ratings and the decisions to accept risk, since they can spot blind spots.

Does SOC 2 satisfy HIPAA?

No. They overlap in controls, but HIPAA is a law with specific requirements, including a risk analysis and business associate agreements. A SOC 2 report can support parts of your evidence but doesn't make you HIPAA compliant on its own.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides