Skip to main content

HEALTHCARE COMPLIANCE

What Is Security Risk Analysis (HIPAA SRA)?

DEFINITION

A Security Risk Analysis (SRA) is the accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information that the HIPAA Security Rule requires of every covered entity and business associate. It is the foundational document of a HIPAA security program and a central focus of OCR enforcement.

A Security Risk Analysis identifies where ePHI is created, received, maintained, and transmitted, then evaluates the threats and vulnerabilities that could compromise it, the likelihood and impact of each, and the effectiveness of current safeguards. The output is a documented, risk-ranked picture of the organization that drives the risk management plan required by the same rule. An SRA is not a one-time project. It must be reviewed and updated as systems, vendors, and threats change.

The requirement applies to every HIPAA covered entity and business associate, regardless of size. A solo practice, a regional hospital, and a health-tech vendor that touches ePHI all carry the same obligation, and OCR routinely requests the risk analysis as one of the first documents in an investigation.

The practical stakes are high. OCR's Risk Analysis Initiative is actively producing enforcement settlements against organizations that lacked an adequate risk analysis, including four ransomware-related settlements announced in April 2026. A missing or outdated SRA is one of the most cited findings in those actions. Organizations that want a structured starting point can use Z Cyber's free HIPAA Security Risk Assessment tool, and healthcare teams can see how an SRA fits a broader program on our healthcare industry page.

Running a program that has to satisfy this?

A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.

Meet Your Security Team →