HIPAA Security Risk Assessment: The Step-by-Step Walkthrough

How to actually perform a HIPAA security risk assessment: ePHI inventory, threat rating, remediation plans with owners and dates, plus a printable checklist.

By Scott McAuley · Aug 4, 2026 · 11 min read

Every HIPAA obligation your practice has rests on one document, and it's the one most practices don't actually possess: the security risk assessment (SRA). It's explicitly required by the Security Rule, it's the first thing the Office for Civil Rights requests in an investigation, and "no or inadequate risk assessment" shows up in enforcement action after enforcement action.

We covered why the SRA matters in our [complete HIPAA compliance and healthcare IT guide](/resources/hipaa-compliance-healthcare-it-guide). This article is the how — the actual working process we run with Houston-area practices, step by step, written for practice managers rather than IT people. By the end you'll know exactly what a defensible SRA contains, and you'll have a checklist you can print and work through.

One reassurance before we start: this is not a technical exercise that requires a security certification. It's a structured inventory-and-honesty exercise. The hard part isn't the method — it's the discipline of doing it completely and then working the plan it produces.

Step 1: Scope It — Find Every Place ePHI Lives

The single most common SRA failure is scoping: practices assess the EHR and the server and call it done, while patient data quietly flows through a dozen systems nobody wrote down.

The rule for scoping is simple: electronic protected health information (ePHI) is in scope wherever it is created, received, stored, or transmitted. Not just where it's supposed to be — where it actually is.

Start with the obvious systems, then work through the list practices forget. This starter table catches most of the strays we find in real assessments:

| Commonly forgotten system | Why it holds ePHI |

|---|---|

| Fax-to-email service | Inbound referrals and records arrive as email attachments — stored in mailboxes and often auto-forwarded |

| VoIP voicemail and call recordings | Patients leave names, conditions, and callback numbers; modern phone systems store these as files in the cloud |

| Backup drives and old external disks | Full copies of everything, frequently unencrypted, sometimes in a desk drawer or an employee's house |

| Staff texting | Schedule swaps and patient questions on personal phones over standard SMS — unencrypted and unmanaged |

| Copiers, scanners, and printers | Multifunction devices have internal hard drives that retain images of everything scanned; they leave the building at lease-end |

| Personal devices and home computers | Anywhere staff check email or the EHR portal remotely |

| Billing clearinghouses and patient-payment tools | Claims data is ePHI; so are payment records tied to treatment |

| Spreadsheets and downloads | The recall list someone exported to Excel "just this once" in 2023 — still on a desktop somewhere |

Walk the office physically, interview each role about how they actually work ("show me what you do when a referral comes in"), and list every system, device, and data flow. Communication channels deserve particular care, because they're where compliant practices leak: if your inventory turns up patient texting or PHI in voicemail, the compliant-channel options — what makes a texting platform acceptable, how phone systems should be configured — are covered thoroughly in Talk Is Cheap's guide to [HIPAA compliant communications](https://talkischeap.io/hipaa-compliant-communications), and fixing those channels will likely become a line in your remediation plan.

The output of this step is your ePHI inventory: one table listing each system, what data it holds, where it physically or virtually lives, who can access it, and which vendor is behind it. Everything else in the SRA builds on this table.

Step 2: Identify Threats and Vulnerabilities

For each inventory item, ask two questions: *what could go wrong here* (threats), and *what weakness would let it* (vulnerabilities).

Threats worth considering for a typical practice:

Vulnerabilities are the practice-specific weaknesses that give a threat its opening: no MFA on email, shared logins on exam-room workstations, an unencrypted backup drive, no termination checklist, a server running an operating system that stopped receiving patches. Pair them up — "ransomware (threat) via unpatched server and no MFA (vulnerabilities)" — because the pairs are what you'll rate next.

Step 3: Rate Likelihood and Impact

You cannot fix everything at once, so the SRA requires you to prioritize honestly. Keep the method simple enough that you'll actually use it: rate each threat-vulnerability pair for likelihood (how plausible is this in the next year or two?) and impact (how bad if it happens?), each on a three-point scale.

| | Low impact | Medium impact | High impact |

|---|---|---|---|

| High likelihood | Medium risk | High risk | Critical — fix first |

| Medium likelihood | Low risk | Medium risk | High risk |

| Low likelihood | Low risk | Low risk | Medium risk |

Impact should account for more than downtime: breach notification duties, regulatory exposure, and patient trust all count. A stolen unencrypted laptop might be low-likelihood, but its impact is a reportable breach of every record on it — that lands it high on the list. Phishing against staff email is high-likelihood almost everywhere, and its impact depends entirely on what that mailbox can reach.

Resist the temptation to score everything "medium." The whole value of this step is separation — a short list of criticals and highs that get owners and dates, above a longer tail that gets scheduled maintenance.

Step 4: Document Current Controls — Including the Missing Ones

For each risk, write down what you already have in place: encryption, MFA, backup routines, access reviews, training, physical locks, signed business associate agreements. Then — and this is the part that takes honesty — write down what you *don't* have.

The gaps are not embarrassing; they're the point. An SRA that finds nothing is an SRA that wasn't looking. Regulators are consistently more forgiving of a practice that documented a gap and scheduled the fix than of one whose paperwork claims perfection contradicted by the evidence.

If this step feels familiar, it should: it's the same discipline as a general [IT assessment](/resources/what-is-it-assessment-houston-business), pointed through a regulatory lens. Practices that have had a recent IT assessment can reuse much of that inventory and control documentation here.

Step 5: The Remediation Plan — Owners and Dates or It Isn't a Plan

Every identified gap goes into a remediation plan with four columns: the finding, the fix, a named owner, and a target date. Not "IT will handle encryption" — "Maria (office manager) confirms full-disk encryption enabled on all 11 laptops with our IT provider by October 15."

Sequence by the risk ratings from Step 3: criticals first, typically MFA, encryption, access cleanup, and backup verification, because those four close the most dangerous doors fastest. Cheap-and-fast fixes (disabling a departed employee's account takes ten minutes) shouldn't wait behind big projects regardless of rating.

Budget reality is allowed. If the server replacement is a next-fiscal-year item, the plan can say so — a dated, funded, documented deferral is a legitimate risk decision. An undated "someday" is not.

Step 6: Evidence of Progress — the Discipline That Makes It Defensible

Here is the counterintuitive part, and the place we see practices genuinely hurt themselves: a risk assessment with an un-worked remediation plan is worse than no assessment at all. It is written proof that you knew about specific problems and chose not to fix them — which is close to the regulatory definition of willful neglect. Under the current penalty structure, that's the difference between the lowest tiers (starting around $145 per violation) and the top tier (starting above $73,000 per violation, with annual caps around $2.19 million per provision).

So build the evidence habit:

This paper trail is precisely what determines penalty tiers. An organization with a current SRA, a worked plan, and dated evidence that still suffers a breach lands in the low tiers, and OCR frequently resolves such cases with corrective action plans instead of fines. Maintaining this cadence — assessments, reviews, evidence files — is the core of what our [compliance support](/services/compliance-support) practice does for healthcare clients year-round.

The Printable SRA Checklist

Work these phases in order. Each one produces a document; together they *are* the SRA.

Phase 1 — Inventory (weeks 1–2)

Phase 2 — Risk analysis (weeks 2–3)

Phase 3 — Controls and gaps (week 3)

Phase 4 — Remediation plan (week 4)

Phase 5 — Evidence discipline (ongoing)

Cadence: Annual, Plus Material Change

Perform the full assessment annually — many practices anchor it to a quiet month or their insurance renewal so it never gets orphaned. Between annual passes, trigger a scoped update whenever something material changes: a new EHR or practice management system, a new location, a merger or acquisition, adopting telehealth, a new AI or automation tool that touches patient data, or a significant new vendor. Each of those changes your inventory, and an inventory that no longer matches reality quietly invalidates the whole document.

The annual pass is also where the loop closes: last year's remediation plan becomes this year's evidence of progress, and this year's findings seed next year's plan. That rhythm — not any single binder — is what "compliance program" actually means, and it's the operational heart of everything else in [the full HIPAA guide](/resources/hipaa-compliance-healthcare-it-guide), from BAAs to breach readiness.

Doing It Yourself vs. Bringing Help

Small practices can absolutely self-assess — HHS even publishes a free SRA tool, and the process above works at kitchen-table scale. The honest limits of DIY are blind spots (nobody inventories the system they forgot exists) and momentum (the plan that stalls in month three). A third-party assessment buys three things: objectivity, completeness, and a paper trail written by someone whose findings a regulator will credit.

We run HIPAA-focused assessments for practices across the Houston area as part of our [healthcare IT practice](/industries/healthcare) — it's often the first project with a new client, because everything else sequences from it. If your practice has never done an SRA, or the last one is gathering dust with an un-worked plan attached, [contact us](/contact) for a HIPAA-focused assessment: we'll build the inventory with you, hand you the findings and the remediation plan in writing, and you can work it with us or without us.

*Scott McAuley is the founder and CEO of Texas Management Group, and founder of Talos Automation and Talk Is Cheap — 25+ years running IT, communications, and automation for Texas businesses.*

Frequently Asked Questions

What is a HIPAA security risk assessment?

A documented review of every place ePHI is created, received, stored, or transmitted in your practice; the threats and vulnerabilities to each; the likelihood and impact of each risk; your current controls and gaps; and a remediation plan with owners and dates. The Security Rule explicitly requires it, and it's the first document OCR requests in an investigation.

How often does a HIPAA risk assessment need to be done?

At least annually, plus a scoped update whenever something material changes — a new EHR, a new location, a merger, adopting telehealth, or a significant new vendor touching patient data. The annual pass also reviews progress on the prior year's remediation plan.

Can we do a HIPAA risk assessment ourselves?

Yes. HIPAA doesn't require an outside firm, and HHS publishes a free SRA tool. The realistic limits of DIY are blind spots — you can't inventory the system you forgot exists — and follow-through. Third-party assessments buy objectivity and a paper trail a regulator will credit.

What happens if a practice has no risk assessment?

A missing or inadequate SRA is among the most common findings in OCR enforcement, and it pushes cases toward the willful-neglect penalty tiers — currently roughly $145 to over $73,000 per violation, with annual caps around $2.19 million per provision. It also weakens every other defense, because you can't show your safeguards match your actual risks.

Is a risk assessment with unfinished remediation items a liability?

Not if the plan is being worked. Open items with named owners, dates, and documented progress demonstrate good faith and land in the lowest tiers. What genuinely hurts is a plan that was written and then ignored — documented knowledge of problems you chose not to fix.