HIPAA Risk Assessment Requirements: What Healthcare Organizations Must Do
The HIPAA Security Rule does not make risk assessment optional. It is the foundation of every other administrative safeguard your organization is required to maintain — and the first place federal auditors look when a breach investigation begins.
What the Security Rule Actually Requires
Under 45 CFR §164.308(a)(1), covered entities and their business associates must conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all electronic protected health information (ePHI) they create, receive, maintain, or transmit. This is not a one-time checkbox — it is an ongoing process that must be repeated whenever operations, technology, or the threat landscape changes materially.
The requirement sits within the Administrative Safeguards category of the HIPAA Security Rule. Administrative safeguards govern how workforce members interact with ePHI and how your organization manages its security program at the policy and process level. Physical and technical safeguards layer on top of the foundation the risk assessment establishes. Without a defensible risk assessment, every downstream safeguard decision is legally unsupported.
The Six Required Elements of a HIPAA Risk Assessment
The HHS Office for Civil Rights has published guidance clarifying the six components that constitute a complete risk assessment. Each must be documented in a form the organization can produce on demand.
Scope Definition
Identify all ePHI your organization creates, receives, maintains, or transmits — regardless of the medium, system, or location. This includes cloud platforms, mobile devices, third-party portals, and any system a business associate can access on your behalf.
Threat Identification
Catalog reasonably anticipated threats to ePHI. These include natural events such as floods and fires, environmental events such as power outages, and human threats such as insider misuse, phishing, ransomware, and unauthorized physical access.
Vulnerability Identification
Identify technical, physical, and administrative weaknesses that could be exploited by each identified threat. Vulnerability scanning, penetration testing, configuration reviews, and workforce interviews all contribute to this step.
Current Control Assessment
Document existing safeguards — both implemented and planned — and evaluate their adequacy against each vulnerability. A gap is not a violation; an undocumented or unevaluated gap is.
Likelihood and Impact Analysis
Assign a probability and potential impact rating to each threat-vulnerability combination. This is where qualitative or quantitative risk scoring methodologies such as NIST SP 800-30 or FAIR are applied.
Risk Level Determination
Produce a prioritized list of risk levels that drives your risk management plan. High-likelihood, high-impact risks require immediate remediation with documented timelines and ownership.
How Frequently Must the Assessment Be Repeated?
The Security Rule does not mandate a specific interval. It requires that covered entities implement procedures to regularly review records of information system activity and to conduct periodic technical and non-technical evaluations based on environmental and operational changes. In practice, OCR enforcement actions and the proposed 2025 HIPAA Security Rule update signal that annual reassessment is rapidly becoming the de facto minimum, with triggered reassessments required any time you add a new application, migrate data to a new platform, onboard a new business associate, experience a security incident, or change your workforce configuration significantly.
Common Risk Assessment Failures OCR Investigates
The majority of large HIPAA civil monetary penalties issued in the past decade have included risk assessment failure as a contributing violation — often the primary one. The most common failure modes are not obscure technical oversights; they are process and documentation failures.
Assessments that cover only a subset of ePHI systems, leaving cloud repositories, legacy applications, or vendor-managed platforms unexamined.
Assessments conducted as a one-time project years before the investigation period with no evidence of updates after system changes.
Risk scores that are assigned without documented methodology, making it impossible to demonstrate the analysis was accurate and thorough.
Risk management plans that were never implemented, leaving identified high-risk vulnerabilities open for months or years.
No evidence that workforce members with security program responsibility reviewed and approved the completed assessment.
The Connection to Your Broader Security Rule Compliance Program
The risk assessment is not a compliance artifact that lives in a folder. It is the analytical input that tells you which Security Rule controls to prioritize, which gaps in your technical safeguards are most dangerous, and which vendors require enhanced scrutiny under your BAA program. When a breach occurs, regulators will trace the event back to the last completed risk assessment to determine whether the compromised system was assessed, whether the relevant risk was identified, and whether remediation was underway. That chain of documentation is your defense.
Armorstack’s 100+ technical experts conduct HIPAA risk assessments grounded in NIST SP 800-30 methodology, mapped directly to the three Security Rule safeguard categories, and delivered with a prioritized remediation roadmap that turns findings into an actionable management plan. Our SENTRY Managed Detection and Response capability integrates continuous monitoring into your risk management cycle, ensuring that emerging threats surface between scheduled assessments rather than appearing for the first time in an OCR investigation notice. Learn more at our compliance services hub or explore how the 90-Day Proof can establish your risk assessment baseline without a long-term contract commitment.
Common Questions
What does the HIPAA Security Rule require for risk assessment?
45 CFR §164.308(a)(1) requires covered entities and business associates to conduct an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI they create, receive, maintain, or transmit. The assessment must be documented and repeated whenever operations or the threat environment changes materially.
How often does a HIPAA risk assessment need to be performed?
The Security Rule does not specify a fixed interval but requires periodic reassessment. OCR enforcement guidance and the proposed 2025 Security Rule update signal that annual reassessment is the practical minimum, with additional triggered assessments required after system changes, new vendor relationships, security incidents, or significant operational shifts.
What are the most common HIPAA risk assessment failures OCR investigates?
The most common failures include assessments that cover only a subset of ePHI systems, one-time assessments never updated after system changes, risk scores without documented methodology, risk management plans that were never implemented, and no documented workforce leadership review of the completed assessment.
Does a risk assessment cover all three Security Rule safeguard categories?
Yes. A complete HIPAA risk assessment must evaluate ePHI across administrative, physical, and technical safeguard domains. Limiting the assessment to technical controls — such as firewalls and encryption — while omitting physical access controls or workforce policy gaps produces an incomplete assessment that will not withstand OCR scrutiny.
Get Help With Your HIPAA Risk Assessment
Armorstack’s 100+ technical experts build defensible, NIST SP 800-30-grounded risk assessments mapped to all three Security Rule safeguard categories — with a prioritized remediation roadmap you can hand to an auditor.
Or call 877-890-5508
Last reviewed: 2026-07-09. Authored by Dale Boehm, CEO Armorstack. CISA + CDPP.