Risk assessment
HIPAA risk assessment software that remembers what you answered last year.
A guided assessment mapped to the Security Rule safeguards, in plain language, producing a readiness score and a gap list you can actually work through. Built for organizations with no compliance officer.
Last reviewed .
Start with the free government tool. Come here when it stops being enough.
HHS publishes the SRA Tool at no cost, and for a solo practitioner doing this once it is a genuinely reasonable starting point — we would rather say so than pretend otherwise. What it does not do is the part that makes the assessment useful the second time.
- It is a desktop download, so two people cannot work on it at once
- There is no remediation tracking — you get findings, not owners and due dates
- Nothing carries forward, so next year starts from a blank form
- There is nowhere to attach the evidence that a gap was actually closed
- The output is a file on one machine, not something you can hand to a client
- It does not know what your systems are actually configured to do
Plain language, not statute
Questions are written for an office manager, not a lawyer. Each one says what it is asking for and why, with the underlying citation available if you want it — never instead of the explanation.
A score, in one sitting
Ten minutes of answering gives you a provisional score and a sense of where you stand before committing to anything. The assessment saves as you go, so the considered pass across all 68 controls — realistically an afternoon — can happen whenever you are ready.
Gaps become tasks automatically
Every answer short of satisfied creates a remediation task with an owner, a due date and a place to upload evidence. The assessment stops being a document and becomes a work queue.
Year-over-year carry forward
Next year's assessment starts pre-filled with last year's answers, showing what changed. Re-confirming twenty controls and revisiting four is an afternoon, not a fortnight.
Verified where we can verify
Connect Microsoft 365 read-only and some answers stop being self-attested. Multi-factor registration, dormant accounts, external mail forwarding, admin sprawl and baseline identity protection are checked against the real configuration. Google Workspace checks are built and awaiting Google's verification review.
Multi-user, with a record of who said what
Your IT provider answers the technical questions, your office manager answers the administrative ones, and every response is attributed and dated in an append-only log.
The 68 controls, by safeguard
The assessment walks every standard and implementation specification in the Security Rule, grouped the way the rule itself groups them. Nothing is sampled and nothing is skipped: an unanswered control counts as unsatisfied and stays in the denominator, because a score that improves when you stop answering is not a score.
| Safeguard group | Citation | What it covers |
|---|---|---|
| Administrative | 164.308 | Risk analysis and management, sanctions, workforce authorization and clearance, termination, training, incident procedures, contingency planning, periodic evaluation, business associate contracts. |
| Physical | 164.310 | Facility access controls, workstation use and security, device and media disposal, re-use and accountability. |
| Technical | 164.312 | Access control and unique user identification, emergency access, automatic logoff, encryption and decryption, audit controls, integrity, person or entity authentication, transmission security. |
| Organizational and documentation | 164.314 / 164.316 | Business associate contract requirements, policy documentation, and the six-year retention obligation. |
Controls are marked required or addressable exactly as the rule marks them. Addressable does not mean optional — it means you must implement it, or document why it is not reasonable and appropriate and what you did instead. The assessment asks for that reasoning rather than letting the control disappear.
The free HHS SRA Tool, feature by feature
We would rather set this out plainly than imply the government tool is bad. It is not. It is a genuinely reasonable choice for a solo practitioner doing this once, and if that describes you, use it.
| HHS SRA Tool | This platform | |
|---|---|---|
| Cost | Free | From $79/month, 14-day trial |
| Runs on | A Windows or iOS download, on one machine | The browser, any device |
| Multiple people | One file, one person at a time | Concurrent, with each answer attributed and dated |
| Remediation | Produces findings | Produces tasks with owners, due dates and evidence uploads |
| Next year | Start from a blank form | Answers carry forward as pending drafts, with a year-over-year comparison |
| Evidence | Nowhere to attach it | Files attach to the control or task, hashed and dated |
| Configuration checks | Asks you what is configured | Reads Microsoft 365 settings directly and records the result |
| Output | A file on one computer | A branded, dated pack you can send, plus a live trust page |
The honest summary: the SRA Tool is a questionnaire, and this is a programme. If you will do the assessment once and file it, the free tool is enough. If somebody is going to ask you for evidence — a hospital client, an insurer, a payer — the difference is the part after the questionnaire.
How often you have to redo it
The Security Rule requires the risk analysis to be reviewed periodically and updated as needed. It deliberately does not name an interval, which is why the question keeps being asked and why the answer is a judgement rather than a date.
- Annually, as the defensible default
- This is the practice almost everyone follows and the cadence an investigator will expect to see. It is also what the carry-forward is designed around: confirm what is unchanged, work what moved.
- Whenever something material changes
- A new system holding patient data, an office move, an acquisition, a significant staffing change, or a new category of service. Each of these changes the risk picture, and a review triggered by the change is stronger evidence than one triggered by the calendar.
- After a security incident
- Whether or not it turned out to be a reportable breach. The incident is evidence about your actual risk, and re-running the affected controls is the visible response.
A point worth being precise about: the risk analysis is not the same thing as a vulnerability scan or a penetration test. Scans examine technical weaknesses in systems; the risk analysis is an organization-wide assessment covering administrative and physical safeguards too. Reviews frequently find a scan report submitted in place of a risk analysis, and it does not satisfy the requirement.
What an investigator actually asks to see
Failure to conduct an accurate and thorough risk analysis is the most frequently cited issue in HIPAA enforcement. What resolves the question is rarely the sophistication of the analysis — it is whether the documentation exists and whether it shows sustained attention.
The current risk analysis, dated
Covering the whole organization, not one system. If it has no date, it cannot be shown to be current, which for these purposes is much the same as not existing.
Prior versions, showing a history
One assessment proves a moment. A series proves a programme — which is precisely what the year-over-year comparison is for.
The risk management plan that followed
Identified risks with owners, dates and what was actually done. An analysis with no remediation record reads as an exercise nobody acted on.
Evidence that the remediation happened
The configuration screenshot, the signed policy, the completed training record, the executed agreement. This is the difference between a task marked done and a task shown done.
Documented risk acceptances
Where you decided not to remediate, the reasoning and who accepted it. Recorded acceptance is a defensible position; a silent gap is not.
All of this is retained for six years under 45 CFR 164.316(b)(2) — from creation or last effective date, whichever is later. That includes superseded versions, which is why nothing here is edited in place.
Common questions
- Is a risk assessment required by HIPAA?
- Yes. Conducting and documenting a risk analysis is a Security Rule requirement (45 CFR 164.308(a)(1)(ii)(A)) for covered entities and business associates, and it is the single most commonly cited failure in enforcement actions. The rule does not mandate any particular tool.
- How do you do a HIPAA risk assessment?
- Establish where electronic patient information is created, stored and transmitted; identify the threats and vulnerabilities to it; note the safeguards already in place; rate the likelihood and impact of each risk; then document the results and a remediation plan with owners. For a small organization that is roughly an afternoon of focused work — this tool walks it in plain language, and the free HHS SRA Tool covers similar ground on the desktop.
- How often should a HIPAA risk assessment be done?
- The rule says periodically rather than naming an interval. Annually is the common, defensible practice, plus whenever something material changes — a new system, an office move, an acquisition, or an incident. The carry-forward is designed for exactly that cadence.
- What are the 5 things a risk assessment should include?
- An inventory of where patient information lives, the threats and vulnerabilities to it, the safeguards currently in place, a likelihood-and-impact rating for each risk, and a documented remediation plan with owners and dates. The documentation is not optional — an undocumented assessment does not exist as far as an investigator is concerned.
Keep reading
- Policies and acknowledgementsVersioned policies your staff read and sign.
- Staff training and certificatesAnnual courses with dated certificates and chasing.
- Vendor and BAA registerWho touches patient data, what is signed, when it expires.
- Incident and breach logFour-factor assessment with the deadline counting down.
- Free BAA template generatorA plain-language agreement with every required provision, built in your browser.
Software and researched information, not legal advice. No product can make an organization “HIPAA certified” — no such designation exists under the HIPAA rules, and using this service does not establish that you comply with them.