Skip to main content
GuidesBy Rutvi VaderaAugust 28, 202611 min read

Healthcare Security Risk Assessment: What OCR Actually Expects

Healthcare Security Risk Assessment: What OCR Actually Expects

The direct answer: a healthcare security risk assessment, done properly, is the risk analysis required by 45 CFR 164.308(a)(1)(ii)(A). The rule words it plainly: conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate. Every covered entity and business associate owes it, including digital health vendors, billing companies, third-party administrators, and analytics firms that never touch a patient. It produces four things: an inventory of where ePHI actually lives, documented threats and vulnerabilities with likelihood and impact, an evaluation of the safeguards in place today, and risk levels that feed a risk management plan.

Status verified August 28, 2026. This page is updated when the regulatory status changes.

To see the shape of the questions before committing to an engagement, start with our free interactive HIPAA security risk assessment. It walks the Security Rule standards, scores your answers, and gives you a written result you can hand to leadership. It is a starting point and a scoping instrument, not a substitute for the enterprise-wide analysis described below.

What the assessment covers

Scope is set by the data, not the network. Every domain below is examined for each place ePHI is created, received, maintained, or transmitted.

Domain assessed What gets examined Rule anchor
ePHI inventory and data flowEvery system, site, device, and vendor where ePHI enters, rests, or leaves164.306(a), 164.308(a)(1)(ii)(A)
Security management processRisk analysis, risk management, sanction policy, information system activity review164.308(a)(1)
Workforce and access managementAuthorization, clearance, termination, role-based access, unique user identification164.308(a)(3), (a)(4), 164.312(a)
Awareness and trainingSecurity reminders, malware protection, login monitoring, password management164.308(a)(5)
Incident responseDetection, response, reporting, and documented incident outcomes164.308(a)(6)
Contingency planningBackup, disaster recovery, emergency mode operation, testing, criticality analysis164.308(a)(7)
EvaluationPeriodic technical and nontechnical review against the rule164.308(a)(8)
Business associate oversightAgreements in place, ePHI shared, subcontractor chains, cloud and AI vendors164.308(b), 164.502(e)
Physical safeguardsFacility access, workstation security, device and media controls, disposal and reuse164.310
Technical safeguardsAudit controls, integrity, authentication, transmission security, encryption164.312
DocumentationWritten policies, evidence of actions taken, six-year retention164.316(b)(2)(i)

Risk analysis versus generic security assessment

This is the distinction that decides whether your document holds up. A generic security assessment measures controls against a checklist or scans a defined network segment. The HIPAA risk analysis is scoped by data. OCR guidance on risk analysis states that the scope covers all ePHI an organization creates, receives, maintains, or transmits, in all forms of electronic media, from a single workstation to complex networks connected between multiple locations, regardless of the source or location of the ePHI. A checklist can pass while the analysis fails, because the checklist never asked where all the ePHI was.

Three properties separate a defensible analysis from a template. Enterprise-wide scope, meaning every clinic, every acquired practice, every laptop, every cloud tenant, and every vendor holding your data. Documented reasoning, meaning threat and vulnerability pairs with likelihood, impact, and assigned risk levels rather than a maturity score with no derivation. And evidence the findings were acted on, because risk management under 164.308(a)(1)(ii)(B) is a separate required implementation specification. Note also that the periodic evaluation standard at 164.308(a)(8) is its own requirement, so an annual policy review is not the risk analysis and does not replace it.

Enforcement on this point is current. On April 23, 2026 OCR announced settlements with four regulated entities following separate ransomware investigations, totaling $1,165,000 and two-year corrective action plans, and stated the resolutions marked 19 completed ransomware investigations and 13 completed investigations in its Risk Analysis Initiative. All four were cited for failing to conduct an accurate and thorough risk analysis. On July 29, 2026 OCR settled with OSF Healthcare System for $552,250 in what it called its 21st ransomware enforcement action, again including a risk analysis failure. Our companion piece on why doing the assessment is not the same as passing it goes deeper on those files.

What actually triggers one

Six events send healthcare organizations looking for this work, on different deadlines and for different audiences.

A reportable breach or an OCR investigation. The risk analysis is what your posture is judged against after the fact, and a corrective action plan will require a new one regardless.

A material environment change. A new EHR, a cloud migration, a telehealth build, an ambient AI scribe, a new billing vendor, or an acquired practice all move ePHI into places your last analysis never covered.

Medicare attestation. Under the 2026 MIPS Promoting Interoperability requirements, clinicians must submit two yes attestations covering both components of the Security Risk Analysis measure during the calendar year of the performance period. That is a calendar-driven trigger with a hard year-end edge.

A customer or payer security review. Health systems and payers increasingly require evidence from vendors, and some require a HITRUST certification specifically. That is a commercial trigger, not a regulatory one, and it changes the shape of the work.

A business associate agreement. Many now name the risk analysis explicitly and give the covered entity audit rights.

Diligence and insurance. Buyers and cyber carriers ask for the current analysis, and a stale one becomes a priced risk in the deal or the renewal.

Not sure whether what you have would survive an OCR document request?

An advisor can review your existing analysis against the rule's scope and elements, show you where the gaps are, and recommend a remediation sequence your team decides on and owns.

Talk to an Advisor →

What you get out of it

Deliverables, described honestly. An ePHI inventory and data flow map covering every location, system, and vendor in scope. A threat and vulnerability register with likelihood, impact, and an assigned risk level for each pair, with the reasoning written down. A safeguard evaluation stating which implementation specifications are in place, partial, or absent, with the documented rationale addressable specifications demand. A prioritized risk management plan with owners and target dates. A documentation package a regulator, a payer, or a board can read without rework. And an executive briefing that turns the register into funding and sequencing decisions.

What you do not get is a certification. Z Cyber is not an accredited certification body and does not certify or attest to your compliance. The advisor leads the analysis, challenges weak evidence, and briefs your leadership. Your organization approves the findings, decides which risks to accept, and owns the risk. The obligation belongs to the covered entity or business associate.

How it maps to the frameworks that matter in healthcare

HIPAA Security Rule. The regulatory floor and the scope definition. Everything else is a lens over it.

HHS 405(d) Health Industry Cybersecurity Practices. The HICP 2023 Edition organizes the sector's top five threats against ten mitigating practices, and it matters legally as well as practically. Public Law 116-321, enacted January 5, 2021, added section 13412 to the HITECH Act, requiring the Secretary to consider whether a regulated entity had recognized security practices in place for not less than the previous 12 months when setting fines, shortening audits, and agreeing remedies. The statute names the 405(d) approaches and NIST-developed practices as qualifying, so mapping your analysis to HICP creates the record that provision runs on.

NIST CSF 2.0 and SP 800-66r2. NIST published SP 800-66 Revision 2 in February 2024 as a cybersecurity resource guide for implementing the Security Rule, with mappings from the rule's standards to CSF subcategories and SP 800-53r5 controls. If your board already reads a NIST CSF maturity view, this is how the HIPAA work reports up without a second data collection.

HITRUST, when a customer demands it. HITRUST offers tiered assessments, e1, i1, and r2, and a validated assessment requires a HITRUST Authorized External Assessor. Z Cyber does readiness and remediation work toward those tiers. We do not perform the validated assessment or issue the certification.

Timeline and what you have to supply

Our security risk assessment engagements typically run four to eight weeks depending on scope. The phases are scope and data collection, safeguard evaluation and interviews, risk rating, treatment planning, then the leadership briefing. What moves the schedule is evidence availability, not analyst capacity.

Plan to supply a named internal owner with authority to convene people, an accurate list of locations and legal entities, access to IT and EHR administrators, a vendor list with the corresponding business associate agreements, your current policy set, any prior risk analysis and its remediation record, and interview time from clinical operations as well as IT. The two dependencies that most often stretch a timeline are an incomplete vendor inventory and acquisitions whose systems were never folded into the parent's documentation.

Which assessment do I actually need

If a regulator, a payer, or your own counsel asked for it, you need the HIPAA risk analysis described here. If you want to know how your program measures against a framework rather than against your own risk, you want a NIST CSF gap and maturity assessment. If you need to prove specific controls work rather than exist on paper, that is a controls effectiveness assessment. If you want to know whether an attacker can get in, that is a penetration test, an input to the risk analysis rather than a replacement for it. If your obligation is broader than security, covering uses, disclosures, and patient rights, that is compliance and privacy work alongside the security analysis.

Most healthcare organizations need the risk analysis first, because it is the required one and it tells you which of the others are worth buying. For the control-by-control view, see our HIPAA Security Rule compliance checklist, and for how we staff this work across health systems, clinics, digital health, and business associates, see the healthcare practice page.

What to watch next

July 2027, estimated. The HIPAA Security Rule overhaul proposed at 90 FR 898 on January 6, 2025 now shows a final action date of July 2027 in the Unified Agenda entry for RIN 0945-AA22, and the rulemaking sits on the Long-Term Actions list. Treat that date as an estimate rather than a commitment. We track the proposal's contents in our page on the pending final rule.

Enforcement in the meantime. The delay changes nothing about the current rule. OCR settled a risk analysis case in late July 2026 and keeps adding investigations under the Risk Analysis Initiative.

December 31, 2026. The MIPS Security Risk Analysis attestation runs on the calendar performance year, and practices that start in November discover their ePHI inventory is out of date.

For a read on your own scope rather than the general picture, start with the free SRA tool, then talk to an advisor.

Frequently Asked Questions

What is a healthcare security risk assessment?

It is the risk analysis required of every HIPAA covered entity and business associate under 45 CFR 164.308(a)(1)(ii)(A): an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information the organization holds. It produces a documented inventory of where ePHI lives, rated threat and vulnerability pairs, an evaluation of current safeguards, and a risk management plan.

What is the difference between a HIPAA risk analysis and a security assessment?

A generic security assessment measures your controls against a checklist or scans a defined network segment. The HIPAA risk analysis is scoped by data, not by system: OCR guidance says it must cover all ePHI the organization creates, receives, maintains, or transmits, regardless of the electronic medium, the source, or the location. A control checklist can pass while the risk analysis fails, because the checklist never asked where all the ePHI was.

What does OCR look for in a HIPAA risk analysis?

Enterprise-wide scope covering every location and system holding ePHI, documented threats and vulnerabilities with likelihood and impact, an honest evaluation of the safeguards actually in place, assigned risk levels, and evidence that findings drove a risk management plan under 164.308(a)(1)(ii)(B). Settlements announced in 2026 repeatedly cite the same failure: no accurate and thorough risk analysis, discovered only after a ransomware breach.

How long does a HIPAA security risk assessment take?

Our security risk assessment engagements typically run four to eight weeks depending on scope. The schedule is driven by evidence availability rather than analyst hours. Multi-site health systems, recent acquisitions, and organizations without a current vendor and business associate agreement inventory take longer, because the ePHI inventory has to be rebuilt before anything can be rated.

How much does a healthcare security risk assessment cost?

Price tracks scope, not headcount. The variables that move it are the number of locations and entities holding ePHI, the number of distinct systems and cloud services in the data flow, how many business associates you use, whether a current asset inventory exists, and whether you need a plain HIPAA risk analysis or readiness work for a customer-driven framework such as HITRUST. Ask any firm to price against a written scope, not a template.

Subscribe for Updates

Get cybersecurity insights delivered to your inbox.