HIPAA risk analysis: what OCR actually looks for
The Security Rule requires a documented, practice-specific risk analysis. Here is what HHS Office for Civil Rights expects it to contain and the four ways small practices get it wrong.
By Ed Wirsing, CISSP · Reviewed September 2026 · Not legal advice
Why this one document matters most
The HIPAA Security Rule has one "required" implementation specification that shows up in nearly every OCR enforcement action: the risk analysis at 45 CFR 164.308(a)(1)(ii)(A). Practices get fined for breaches, but the finding that turns a breach into a settlement is almost always "the covered entity failed to conduct an accurate and thorough risk analysis." If you do only one thing this year, do this one properly.
What OCR's guidance says a risk analysis must include
HHS published guidance on the required elements. In plain terms, your document needs to show:
- Scope. All electronic protected health information (ePHI) your practice creates, receives, maintains, or transmits. Not just the EHR: email, scanners, phones, billing, the cloud fax service, the backup drive in the office manager's desk.
- Data collection. Where that ePHI actually lives and moves, documented. An inventory.
- Threats and vulnerabilities. What could reasonably go wrong for each place ePHI lives: ransomware, a lost laptop, a phishing email to the front desk, a vendor breach, a flood.
- Current controls. What you already have in place against each of those, honestly.
- Likelihood. How probable each threat is given your current controls.
- Impact. How bad it would be for patients and the practice if it happened.
- Risk level. Likelihood and impact combined into a ranking, so you know what to fix first.
- Documentation. All of the above written down, dated, and kept for six years.
- Periodic review. Updated when something changes (new EHR, new location, a breach) and reviewed at least annually.
The four ways small practices get it wrong
- The EHR vendor's checklist. Your EHR vendor's "HIPAA compliance report" covers their product. OCR wants an analysis of your practice, including everything that is not the EHR.
- A questionnaire instead of an analysis. Yes/no checklists are useful inputs, but they do not identify threats, rate likelihood, or rank risk. OCR has said so explicitly.
- Done once, never updated. A risk analysis from the year you opened, before you moved to cloud billing and added a second location, is not accurate or thorough.
- No risk management plan afterward. The next specification, 164.308(a)(1)(ii)(B), requires you to actually address the risks you found. An analysis with no follow-up is evidence against you.
What comes after the analysis
A good risk analysis produces a short, ranked fix list. In most small practices it looks like: MFA on email and the EHR, encryption on every laptop, tested backups that ransomware cannot reach, a vendor list with Business Associate Agreements, a phishing-focused staff training, and a one-page incident response plan. That is a quarter of work, not a year.
About the proposed Security Rule changes
In early 2025, HHS proposed the first major Security Rule update in over a decade: mandatory MFA, mandatory encryption, a written asset inventory and network map, annual compliance audits, and the removal of the "addressable" flexibility for most specifications. Whether or not the final rule looks exactly like the proposal, a practice with a real risk analysis and those controls already in place will not have to scramble.
If you run an RIA instead of a practice
The SEC's amended Regulation S-P applies the same logic to advisers. Since June 3, 2026, every registered adviser needs a written incident response program, oversight of service providers that handle customer information, and a process to notify affected customers within 30 days. The structure is close enough to a HIPAA program that I build them the same way.
This guide pairs with the program page:
vCISO program for practices and RIAs →