HIPAA Security Risk Assessment: A Worksheet for Small Teams
A HIPAA security risk assessment is a documented analysis of where electronic protected health information (ePHI) lives, what could threaten it, and how likely and damaging each threat is. The Security Rule expects covered entities and business associates to do one, act on it and keep it current.
You can run a first pass with a spreadsheet and a few working sessions. This guide walks through the steps and the columns to use. It isn't legal advice, so have a qualified HIPAA adviser review the result.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Does your company need a HIPAA risk analysis?
If you're a covered entity (a provider, health plan or clearinghouse) or a business associate that creates, receives, maintains or transmits ePHI for one, the Security Rule applies to you, and a risk analysis is a required part of it. A software company that stores patient data on behalf of a clinic is usually a business associate.
Two details trip up startups. First, a customer's contract may impose extra duties through a business associate agreement. Second, the risk analysis isn't a one-time exercise: repeat it when you add systems, change vendors or after a significant incident, and at regular intervals you set. HIPAA also expects you to keep the documentation for six years, so store each version. If you're unsure whether you're a business associate, ask an attorney.
How do you run the assessment in six steps?
Work through these in order:
- Define scope. List every system, location and person that touches ePHI, including laptops, backups, logs and third-party services.
- Map the data flow. Draw where ePHI enters, where it's stored, who can see it and where it leaves.
- Identify threats and vulnerabilities. For each system, list what could go wrong: lost devices, misconfigured storage, phishing, excessive access, vendor breach.
- Record current safeguards. Encryption, access controls, audit logs, backups and training already in place.
- Rate likelihood and impact. Use a simple scale, such as low, medium, high, and combine the two into a risk level.
- Plan and track remediation. Assign each significant risk an owner, an action and a date, and record decisions to accept a risk.
HHS publishes guidance on risk analysis and offers a free Security Risk Assessment Tool. Check what's current before you rely on either.
A worksheet layout you can copy into a spreadsheet
Give each row one asset and threat pair, with these columns:
- Asset. For example, the production database that holds appointment notes.
- Where ePHI is stored or moves. Region, service, backups, exports.
- Threat or vulnerability. For example, public access from a misconfigured storage bucket.
- Existing safeguards. Encryption at rest, private network, access logging.
- Likelihood and impact. Each rated low, medium or high.
- Risk level. The combined rating.
- Action. Fix, transfer, accept or monitor, with an owner.
- Due date and status.
For example, say the row is an engineer's laptop with a local copy of a patient export. The threat is device loss, the safeguard is disk encryption, and the action might be to stop exports to laptops entirely. That single change removes the risk rather than managing it.
What do assessors and customers look for?
Reviewers usually check three things: that the assessment covers all ePHI (including backups and vendors), that risks were rated by a method you can explain, and that findings turned into tracked action.
The most common gaps:
- Missing vendors. Your analytics tool, logging service or email provider may see ePHI. Confirm a business associate agreement exists with each that does.
- Shadow copies. Exports, test databases seeded from production and support screenshots.
- No follow-through. A long list of high risks with no owners or dates.
- Stale analysis. A document from two systems ago.
A vendor inventory helps here, and the vendor risk assessment template shows how to evaluate each supplier. Answers you write for customers should match this analysis, so keep your security questionnaire answers consistent with it.
How do you keep it current without a big project each year?
Make small updates part of normal change. Add a checkbox to your architecture review: does this change how ePHI is stored, accessed or shared? If yes, update the analysis row and the data flow map. Review open risks monthly, and schedule a full refresh at the interval you've written in your information security policy.
Compliance platforms such as Vanta or Drata can help you keep control status, vendor reviews and training records together, which may supply evidence for the safeguards column. Confirm in a demo what it covers for HIPAA. They don't perform the risk analysis for you, because judging likelihood and impact for your systems is your team's work. Pair the analysis with security awareness training for everyone who handles ePHI.
What Good Looks Like
You can point to a dated risk analysis covering every system and vendor that touches ePHI, with owners and due dates on each significant risk.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Fits when you want safeguards, vendor reviews and training records kept together to support the risk analysis, though it doesn't replace it.
Fits when you want tracked controls and tasks feeding the remediation list; confirm in a demo how it handles HIPAA-specific needs.
Frequently Asked Questions
Is a HIPAA risk assessment legally required?
Yes for covered entities and business associates. The Security Rule requires an accurate and thorough analysis of risks to ePHI, and you must act on it. If you're unsure whether the rule applies to your company, ask a healthcare attorney or a qualified HIPAA adviser.
How often should we update our HIPAA risk analysis?
Update it when you introduce new systems or vendors, after significant incidents and at regular intervals you define in policy. Many organizations review yearly. Keep each version, since HIPAA expects documentation to be retained for six years.
Can we do the HIPAA risk assessment ourselves?
Yes, many small teams do a first pass internally using a structured worksheet or the free HHS tool. Have a qualified HIPAA professional review it, especially the ratings and the decisions to accept risk, since they can spot blind spots.
Does SOC 2 satisfy HIPAA?
No. They overlap in controls, but HIPAA is a law with specific requirements, including a risk analysis and business associate agreements. A SOC 2 report can support parts of your evidence but doesn't make you HIPAA compliant on its own.
About the numbers
This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.
Related Guides
Vendor Security Risk Assessment: Tiers, Questions and Evidence
How to assess vendor security risk: tier suppliers, match question depth to risk, review SOC 2 reports properly and track contracts and renewals.
How to Answer Security Questionnaires Faster With an Answer Library
Build a reusable security questionnaire response library: answer format, evidence links, owners and review rules so sales reviews close in days, not weeks.
Information Security Policy for a Small Business: Outline and Examples
Write a short information security policy set for a small business: which policies you need, a section-by-section outline and example requirements.
What SOC 2 Auditors Expect From Security Awareness Training
What security awareness training satisfies a SOC 2 audit: content, timing, who must complete it and the evidence to keep for the auditor.
What Drives Penetration Test Cost for a Small SaaS Company
Understand what drives penetration test pricing for a small SaaS product, how to scope a test, compare quotes and get more value from the report.
SOC 2 Timeline: Each Phase and What Slows It Down
SOC 2 timelines depend on scope, gaps and report type. See the phases from scoping to the final report, what slows each one and how to plan a schedule.