Do You Need a HIPAA Security Risk Analysis?
By Cooper Kelley, Founder, Tailwater Tech · July 15, 2026
Short answer: yes. If your practice creates, stores, or touches electronic patient data, a written HIPAA security risk analysis is not optional, it is required by law, and it is the very first thing an investigator asks for.
It is also the most common thing practices get wrong. Not because they refuse to do it, but because they assume someone else already handled it, or that a compliant EHR covers them. It does not. Here is what a risk analysis actually is, why being small is not a defense, and what a real one looks like.
What a risk analysis actually is
The HIPAA Security Rule (45 CFR 164.308(a)(1)(ii)(A)) requires a risk analysis as a required implementation specification, not an addressable one. It is an accurate, thorough assessment of the risks to the confidentiality, integrity, and availability of the electronic protected health information (ePHI) your practice holds, wherever it lives.
The key word is thorough. It is not a checklist you buy and file. It has to look at your actual systems: the EHR, email, laptops and phones, backups, the cloud services you use, and the vendors who can reach any of it.
Why “we’re too small” is not a defense
HIPAA applies to covered entities and business associates regardless of size. A solo therapist and a hospital have the same obligation to do a risk analysis; only the scope differs. And small practices are not flying under the radar: the Office for Civil Rights runs a Risk Analysis Initiative and has settled a string of cases, some with practices of just a few people, specifically for failing to do one.
The assumption that gets practices in trouble
Two myths do most of the damage. First, that your EHR being “HIPAA compliant” covers you. It does not. A compliant vendor secures their piece; your risk analysis has to cover your environment, the devices, email, and access around the EHR. Second, that a generic “compliance in a box” template is a risk analysis. A blank template you never filled in against your real systems is worse than nothing, it shows you knew the requirement and skipped it.
What a real risk analysis covers
A defensible risk analysis works through, and documents, roughly this:
- Where the data is. An inventory of everywhere ePHI is created, received, stored, or transmitted: EHR, email, workstations, laptops, phones, backups, cloud apps.
- What could go wrong. The threats and vulnerabilities to that data: lost devices, phishing, ransomware, unpatched software, weak access controls, a vendor breach.
- How likely and how bad. A reasonable assessment of the likelihood and impact of each, so you can prioritize.
- Written and dated. The whole thing documented, with a date, so you can prove it exists and is current.
- A plan to fix it. A risk management plan that actually addresses the gaps the analysis found. The analysis identifies risk; the management plan reduces it.
How often you have to do it
It is not one and done. HIPAA expects the analysis to stay current, so you review and update it at least annually and after any major change: a new system, an office move, a new vendor, or a security incident. An analysis from four years ago that predates half your current tools will not hold up.
What skipping it actually costs
The missing or inadequate risk analysis is the most-cited failure in HIPAA enforcement, and it is the first document OCR requests in an investigation. Recent settlements have hit practices of every size, including a CPA firm acting as a business associate that paid $175,000 in 2025 after ransomware, with OCR pointing squarely at the lack of a proper risk analysis. It is the foundation the rest of your compliance stands on, and its absence is the easiest thing for a regulator or a cyber insurer to spot.
Not sure if your risk analysis would hold up?
The HIPAA Security Check scores your practice against the safeguards OCR looks at first, starting with the risk analysis, in a few minutes, and emails a plain-English report of your biggest gaps. No sales call required to see your score.
Take the free HIPAA Security Check →Frequently asked questions
- Is a HIPAA risk analysis actually required by law?
- Yes. It is a required implementation specification under the Security Rule (45 CFR 164.308(a)(1)(ii)(A)). Every covered entity and business associate must conduct one, regardless of size.
- What is the difference between a risk analysis and a risk assessment?
- The terms are often used interchangeably. “Risk analysis” is the specific term in the Security Rule for assessing risks to ePHI. Some people use “risk assessment” for the broader review. What matters is that it is accurate, thorough, documented, and current.
- Can my EHR vendor do my risk analysis for me?
- No. A vendor tool can help gather information, but the analysis has to cover your entire environment, including the devices, email, network, and vendors around the EHR. You own it, and OCR will hold you, not the vendor, responsible for it.
- How much does a HIPAA risk analysis cost?
- It varies with the size and complexity of the practice. A thorough one for a small practice typically runs from a low four figures up, depending on scope. Some managed IT and compliance services include a risk analysis as part of onboarding.
Keep reading