Back to all

HIPAA Risk Assessment: What OCR Requires and How to Do It

September 12, 2026
Graphical representation doctor on a laptop needing Managed IT Solutions from The Nu-Age Group.
Healthcare IT environment handling electronic protected health information covered by a HIPAA risk assessment

A ransomware investigation uncovers a second failure: the organization has not conducted an accurate and thorough risk analysis.

That finding appeared in all four settlements announced on April 23, 2026, by the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Under the Health Insurance Portability and Accountability Act (HIPAA), the Security Rule requires documented analysis but does not prescribe one format. This work is commonly called a HIPAA risk assessment.

Current duties remain enforceable while the overhaul remains proposed. The HIPAA and System and Organization Controls (SOC) 2 relationship is covered in Nu-Age’s healthcare compliance overview.

What Is a HIPAA Risk Assessment?

A HIPAA risk assessment is the industry’s common name for the Security Rule’s required risk analysis. OCR treats the terms as the same activity. The regulation requires an “accurate and thorough assessment” of risks and vulnerabilities affecting the confidentiality, integrity, and availability of electronic protected health information (ePHI).

The current rule, section 164.308 of Title 45 of the Code of Federal Regulations, applies to covered entities and business associates. It also requires risk management that reduces identified risks and vulnerabilities to a reasonable and appropriate level.

Risk analysis evaluates risk. Risk management acts on the findings. OCR describes the analysis documentation as a direct input to risk management. They connect, but are not interchangeable.

What OCR’s Risk-Analysis Guidance Says to Cover

OCR does not prescribe one methodology, template, or scoring formula. Its Guidance on Risk Analysis, last reviewed August 12, 2026, says methods may vary by organization. OCR states that a risk analysis must incorporate the elements below, regardless of method.

Analysis elementWhat the record should show
ScopeAll ePHI the organization creates, receives, maintains, or transmits, in every form of electronic media.
Data collectionWhere ePHI is stored, received, maintained, or transmitted, plus how it enters, moves through, and leaves systems.
Threats and vulnerabilitiesReasonably anticipated threats and the weaknesses they could exploit.
Current security measuresControls in place and whether they are implemented, configured, and used properly.
LikelihoodAn assessment of how likely each relevant threat is to occur.
ImpactThe potential effect if a threat exploits a vulnerability, assessed qualitatively or quantitatively.
Risk levelA rating for each threat and vulnerability pair, with corrective actions for each risk level.
Final documentationA record connecting scope, findings, existing measures, likelihood, impact, risk levels, and corrective actions. No specific format is prescribed.

Build a connected record, not eight separate descriptions. A vulnerability is a security weakness; a threat is something that could exploit it. For each relevant pair, identify affected ePHI, current measures, and the basis for likelihood and impact. Then document the risk level and corrective action.

As a management practice, assign each action an owner, a target date, and a completion check. Those fields are not an OCR-prescribed template or deadline. Feed the findings into risk management and revisit them when conditions change.

The analysis also supports decisions about addressable implementation specifications. Addressable does not mean optional. If one is not reasonable and appropriate, document why and adopt an equivalent measure when appropriate.

Apply the analysis to unpatched software

In its January 2026 Cybersecurity Newsletter, published January 8, 2026, OCR said risk analysis must include risks and vulnerabilities to ePHI from unpatched software.

Use patching to test the record. OCR recommends vendor alerts, vulnerability scans, and monitoring the National Institute of Standards and Technology’s vulnerability database and the Cybersecurity and Infrastructure Security Agency’s exploited-vulnerability catalog. An up-to-date asset inventory can clarify the environment. For a relevant finding, record the affected asset and ePHI, controls, ratings, and corrective action. A scan report alone is not the full analysis.

Recent OCR Settlements Involving Risk-Analysis Failures

OCR announced four ransomware settlements on April 23, 2026. In its announcement, each regulated entity had failed to conduct the required risk analysis. Together, the entities paid $1,165,000 and agreed to corrective action plans subject to OCR monitoring for two years.

The breaches collectively affected over 427,000 individuals. Consociate, Inc., a third-party administrator acting as a business associate, was one. OCR Director Paula M. Stannard said proactive Security Rule implementation before a breach or investigation is both the law and the best opportunity to prevent or reduce the harm from a successful cyberattack.

Healthcare cybersecurity safeguards supporting HIPAA Security Rule risk analysis

When to Update the Assessment

The Security Rule does not set a universal schedule. OCR says the risk-analysis process should be ongoing. Set a review interval that fits the environment, and reopen the analysis after the trigger events below.

OCR identifies several reasons to review the work:

  • A security incident changes the understanding of risk.
  • A change in ownership alters systems or responsibilities.
  • Turnover in key staff or management affects the environment.
  • The organization plans to incorporate new technology.

At each review, record what changed. Reconfirm affected data flows, threats, vulnerabilities, and current measures. Update ratings, corrective actions, and documentation where needed. Do not wait for a scheduled review after a known trigger.

What the HHS Security Risk Assessment Tool Does and Does Not Do

The HHS Security Risk Assessment Tool is a desktop application supporting HIPAA security risk assessments. The Office of the National Coordinator for Health IT (ONC) developed it with OCR. It is often called the HHS SRA Tool.

OCR describes the tool as useful for small and medium-sized healthcare practices and business associates. Neither the tool nor any single method guarantees compliance.

Use it as support, not proof of completion. Compare the work against all eight guidance elements. Confirm the complete ePHI scope, document gaps, and move corrective actions into risk management. Apply the same test to any HIPAA risk assessment template.

Reviewing ePHI security measures and corrective actions during a HIPAA risk analysis

What Is Required Today and What Is Still Proposed

HHS published a notice of proposed rulemaking in the Federal Register on January 6, 2025. Comments closed March 7, 2025. As of September 2026, the proposal is not the current rule.

The proposal would make existing duties more prescriptive and add others, including:

  • A written technology asset inventory and network map covering systems and assets that may affect ePHI confidentiality, integrity, or availability.
  • Patching timelines of 15 calendar days for critical risks and 30 calendar days for high risks.
  • Annual compliance audits and annual testing of incident-response and contingency plans.
  • More prescriptive encryption requirements for ePHI at rest and in transit.
  • Restoration of critical systems and data within 72 hours.
  • A separate risk-management standard, removal of the required-versus-addressable distinction, and a definition of multi-factor authentication.

The current rule already addresses encryption as an addressable implementation specification. If encryption is not reasonable and appropriate, the organization must document why and adopt an equivalent measure when reasonable and appropriate.

The HHS and Office of Management and Budget (OMB) Unified Agenda lists final action in July 2027 under long-term actions. Until a final rule changes the requirements, proposed deadlines are not mandates. Current risk-analysis, documentation, and risk-management duties remain enforceable.

How Nu-Age Approaches This

An outside provider can help build the record, but your organization still needs to understand the scope and the risk-management handoff.

On its healthcare page, Nu-Age states that its first phase evaluates current technology infrastructure with specific focus on HIPAA compliance, patient data flows, and security controls OCR expects during investigations and audits. The company states that it acts as a business associate and helps manage business associate agreement (BAA) relationships. For a 15-provider multi-specialty practice, Nu-Age reports completing a HIPAA risk analysis. This is one company-reported engagement, not a benchmark or promised outcome.

Nu-Age also reports that its Secaucus, New Jersey, and Orlando, Florida private cloud environments ran HIPAA controls during the January through December 2025 period covered by its SOC 2 Type 2 examination. The company announced zero exceptions. Derick Diaz, Nu-Age’s Vice President of Technology, said: “A ‘Zero Exceptions’ standard isn’t just a goal; it’s our baseline.”

Ask what documentation the provider will deliver, how it will confirm scope, and how findings will become corrective actions. Distinguish evidence about its controls from analysis of your environment. Nu-Age discusses its examination in its SOC 2 Type 2 report article.

Key Takeaways

  • The Security Rule calls the required activity a risk analysis, while the industry calls it a HIPAA risk assessment.
  • OCR’s guidance says the analysis must cover the full ePHI environment and connect threats, vulnerabilities, safeguards, ratings, and corrective actions.
  • Update the record on an environment-specific schedule and after incidents, ownership changes, key turnover, or planned technology changes.
  • The HHS SRA Tool supports the process, while the January 2025 Security Rule overhaul remains proposed rather than enforceable.

Frequently Asked Questions

What is included in a HIPAA risk assessment checklist?

Include full ePHI scope and data flows, reasonably anticipated threats, vulnerabilities, current security measures, likelihood, impact, risk levels, corrective actions, and final documentation. The record should connect these elements so a reviewer can follow each material finding from the affected ePHI through the planned response.

Is a HIPAA security risk assessment required every year?

No. The Security Rule does not set one schedule for every organization. OCR says risk analysis should be ongoing. Review it at an interval suited to the environment and after a security incident, ownership change, key staff or management turnover, or a plan to introduce new technology.

Does the HHS SRA Tool make an organization HIPAA compliant?

No. The HHS SRA Tool supports the assessment process but does not establish compliance. Check the resulting work against OCR’s eight guidance elements, confirm the complete ePHI scope, document the analysis, and move corrective actions into risk management rather than treating tool completion as the endpoint.

Do business associates need their own HIPAA risk analysis?

Yes. The current rule applies to covered entities and business associates that hold ePHI. Each business associate must assess the risks and vulnerabilities in its own environment. OCR’s April 2026 settlements included a third-party administrator acting as a business associate, which makes the scope of that duty concrete.

How do vulnerability scans fit into a HIPAA risk analysis?

A vulnerability scan can identify weaknesses, but it is only an input. For relevant findings, document the affected ePHI and asset, the threat, current safeguards, likelihood, impact, risk level, and corrective action. OCR’s January 2026 newsletter specifically includes unpatched software within risk-analysis scope.

Build a Risk Analysis You Can Defend

A defensible analysis is a working management record, not a completed questionnaire. Check whether each relevant ePHI flow connects to threats, vulnerabilities, safeguards, ratings, and corrective actions. Assign owners and completion checks, then define when the record will be reopened. If an outside provider assists, require a clear scope and usable deliverables. Review Nu-Age’s healthcare services, then contact The Nu-Age Group at (866) 640-3999 or sales@thenuagegroup.us.

Archives

Related Blog Articles

Executive boardroom with technology roadmap display and night skyline for virtual CIO services

How CLO Managers Are Actually Using AI (It’s Not Trading)

September 14, 2026
Anthony Chillino

Fitch surveyed global CLO managers on AI in investment management. The pattern is AI assisted,…

Read More
Cybersecurity firm in Orlando, FL The Nu-Age Group

Patch Management for Regulated Firms: Process and Timelines

September 14, 2026
Anthony Chillino

Build a patch management process for regulated firms. Compare NYDFS and HIPAA duties with CISA’s…

Read More
The Nu-age group VCIO

What a Virtual CIO or Fractional CIO Does for a Regulated Firm

September 13, 2026
Anthony Chillino

What a virtual CIO does for a regulated firm, how the role differs from managed…

Read More
Graphical representation doctor on a laptop needing Managed IT Solutions from The Nu-Age Group.

HIPAA Risk Assessment: What OCR Requires and How to Do It

September 12, 2026
Anthony Chillino

A HIPAA risk assessment maps ePHI, documents risks and corrective actions, supports risk management, and…

Read More
graphical representation of cybersecurity by The Nu-Age Group.

Regulation S-P: What Smaller Advisers and Broker-Dealers Need Now

September 11, 2026
Anthony Chillino

Use this Regulation S-P checklist to test incident response, vendor alerts, customer notices, records, and…

Read More
Security operations center with global threat monitoring wall for alternative investment firms

Your IT Provider Keeps the Lights On. Who Watches for Threats?

September 7, 2026
Anthony Chillino

Your MSP keeps the lights on. That is not the same as managed cybersecurity watching…

Read More
Tier-3 data center aisle with enterprise server racks for financial services private cloud

Private LLM vs. Public LLM: Where Your Financial Data Actually Goes

August 31, 2026
Anthony Chillino

What changes when a financial firm runs a private LLM for financial data instead of…

Read More
Managed IT operations office for a CLO hedge fund with portfolio monitoring displays and server racks

What a SOC 2 Type 2 Report Actually Proves About Your IT Vendor

August 23, 2026
Anthony Chillino

What a SOC 2 Type 2 report actually proves about a technology vendor, what “zero…

Read More

How Cybersecurity Regulations Are Evolving Across the East Coast

July 23, 2026
Anthony Chillino

Stay ahead of changing cybersecurity regulations with expert MSP and MSSP guidance that supports compliance,…

Read More