CompyMax

The HIPAA SRA Tool, and what it does not do

The Security Risk Assessment Tool is free, published by the government, and genuinely good at the job it was built for. It is also a single-user desktop file scoped to one organization and one document, and four of the things people expect it to cover are outside that scope by design. Here is what it does, and where the line is.

Last reviewed .

Get it from HHS, free

The tool is published by the Office of the National Coordinator for Health IT with the HHS Office for Civil Rights, at version 3.6.1 as of our last review. There is a Windows application for 64-bit Windows 7, 8, 10 and 11, and an Excel workbook for everyone else. HHS states that all information entered is stored locally on your own computer and that it does not collect, view, store or transmit any of it.

Download the SRA Tool from healthit.gov →

We have no affiliation with HHS or ONC and receive nothing if you download it. For a single practice doing this for the first time, it is the sensible place to start.

What the rule actually requires

The obligation people are trying to discharge when they search for a “HIPAA risk assessment tool” is 45 CFR 164.308(a)(1)(ii)(A): conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of the electronic protected health information you hold. Three words in that sentence do most of the work.

  • Accurate

    It has to describe your actual systems, not a template's. The commonest failure is an assessment that never mentions the laptop the billing runs on.

  • Thorough

    All electronic protected health information you create, receive, maintain or transmit — every system, including the ones no clinician touches.

  • Documented

    45 CFR 164.316(b)(1) requires the analysis to be in writing and kept. An assessment that happened in a meeting did not happen.

Note what is not in that citation: any mention of a product, a vendor, a certificate or an annual date. The Security Rule names no tool, and no tool can discharge the requirement on your behalf.

Four things the download does not cover

None of these are faults. They are scope decisions, and they are the right ones for a free single-purpose government tool — but they are the reason a practice that has “done the SRA Tool” can still fail a client’s review.

It assesses; it does not track remediation

The tool documents the risks you identified. The separate requirement at 45 CFR 164.308(a)(1)(ii)(B) — implementing security measures sufficient to reduce those risks to a reasonable and appropriate level — happens somewhere else, and in most small organizations that somewhere else is nowhere. Producing an assessment with no record of what was done about it is the gap OCR finds most often.

It is a file on one computer

That is a deliberate privacy design and it is the right call for the data involved. It also means the assessment lives or dies with that machine and that person: no version history, no second reviewer, and nothing that survives the office manager leaving. Back it up somewhere durable, and keep it — documentation has a six-year retention requirement under 45 CFR 164.316(b)(2)(i).

It covers one organization at a time

Fine for a single practice. If you are an MSP or a billing company carrying an assessment for each of twenty clients, you are managing twenty desktop files on twenty review cycles, and the thing that fails is not the assessment — it is remembering whose is out of date.

It does not produce the rest of the evidence pack

A risk analysis is one document. When a client's security questionnaire or an OCR request arrives, what is asked for is the analysis plus policies with acknowledgement dates, per-person training records, executed business associate agreements and an incident log. The tool is scoped to the first of those, correctly.

Which side of the line are you on?

Use the free tool if

You are one organization, one location, doing this for the first time, and the person who fills it in will still be there next year to redo it. Download it today rather than reading three more articles.

You will outgrow it if

You carry assessments for several client organizations, need remediation tracked with owners and dates, get asked for the whole evidence pack rather than one document, or need last year’s answers to carry forward instead of starting blank.

Common questions

What is the HIPAA SRA Tool?
A free desktop application published by the Office of the National Coordinator for Health IT in collaboration with the HHS Office for Civil Rights. It walks you through a structured set of questions about your practice and produces a risk assessment report. It is aimed at medium and small providers, runs on 64-bit Windows, and ships alongside an Excel workbook version for anyone not on Windows. Everything you enter stays on your own computer — HHS states it does not collect, view, store or transmit anything entered into the tool.
Does using the SRA Tool make you compliant?
No, and HHS does not claim it does. The tool helps you conduct and document a risk analysis, which is one required implementation specification — 45 CFR 164.308(a)(1)(ii)(A). The separate requirement at 164.308(a)(1)(ii)(B) is to actually implement measures sufficient to reduce the risks you found, and the periodic evaluation at 164.308(a)(8) is a third obligation again. A completed assessment that nothing happened after is the most common finding in OCR's enforcement history.
Is the SRA Tool required?
No. The risk analysis is required; this particular tool is not. Nothing in the Security Rule names a product, and an assessment done in a spreadsheet, in another vendor's software, or by a consultant satisfies the requirement equally well provided it is accurate, thorough, covers all electronic protected health information you hold, and is documented.
How often do you have to redo a risk analysis?
The rule says the analysis must be accurate and thorough and that security measures must be reviewed and modified as needed to continue providing reasonable and appropriate protection — it does not print an interval. Annual is the defensible convention, and a material change to your systems or operations is its own trigger regardless of when the last one was. A new practice management system, a second location or a shift to remote working all restart the question.
Can business associates use the SRA Tool?
Yes, though it is written in the language of a provider practice, so some questions will need translating. Business associates have the same risk analysis obligation as covered entities. If you are a billing company or an MSP holding data for many clients, the harder problem is usually not the questionnaire but keeping one current assessment per entity, which is the part a single-user desktop file makes awkward.

When one file on one laptop stops being enough.

Our assessment carries last year’s answers forward, turns each finding into a tracked task with an owner and a date, and exports alongside the policies, training records and agreements the same request usually asks for. 14 days free, no credit card, no sales call.

Informational only, based on the published text of 45 CFR Part 164 and on ONC’s own description of the SRA Tool at healthit.gov, read on August 13, 2026. Version numbers and system requirements change; check the download page before relying on them. We are not affiliated with HHS or ONC, and this is not legal advice. No organization or product can be “HIPAA certified” — no such designation exists. See our editorial standards.