- What is the HIPAA SRA Tool?
- A free desktop application published by the Office of the National Coordinator for Health IT in collaboration with the HHS Office for Civil Rights. It walks you through a structured set of questions about your practice and produces a risk assessment report. It is aimed at medium and small providers, runs on 64-bit Windows, and ships alongside an Excel workbook version for anyone not on Windows. Everything you enter stays on your own computer — HHS states it does not collect, view, store or transmit anything entered into the tool.
- Does using the SRA Tool make you compliant?
- No, and HHS does not claim it does. The tool helps you conduct and document a risk analysis, which is one required implementation specification — 45 CFR 164.308(a)(1)(ii)(A). The separate requirement at 164.308(a)(1)(ii)(B) is to actually implement measures sufficient to reduce the risks you found, and the periodic evaluation at 164.308(a)(8) is a third obligation again. A completed assessment that nothing happened after is the most common finding in OCR's enforcement history.
- Is the SRA Tool required?
- No. The risk analysis is required; this particular tool is not. Nothing in the Security Rule names a product, and an assessment done in a spreadsheet, in another vendor's software, or by a consultant satisfies the requirement equally well provided it is accurate, thorough, covers all electronic protected health information you hold, and is documented.
- How often do you have to redo a risk analysis?
- The rule says the analysis must be accurate and thorough and that security measures must be reviewed and modified as needed to continue providing reasonable and appropriate protection — it does not print an interval. Annual is the defensible convention, and a material change to your systems or operations is its own trigger regardless of when the last one was. A new practice management system, a second location or a shift to remote working all restart the question.
- Can business associates use the SRA Tool?
- Yes, though it is written in the language of a provider practice, so some questions will need translating. Business associates have the same risk analysis obligation as covered entities. If you are a billing company or an MSP holding data for many clients, the harder problem is usually not the questionnaire but keeping one current assessment per entity, which is the part a single-user desktop file makes awkward.