HIPAA
HIPAA security risk assessment for healthcare organizations
The HIPAA Security Rule requires an accurate and thorough risk analysis of the ePHI you create, receive, keep or send. We perform it, document it and turn the findings into a risk management plan you can follow and defend.

Healthcare focus
Assessments for providers, practices and business associates
From findings to fixes
Engineers who can close the gaps we find
Top virtual CISO services company
Recognized by Cyber Security Review

What the rule requires
HIPAA risk analysis is the foundation of the Security Rule
Covered entities and business associates must conduct a risk analysis of potential risks and vulnerabilities to the confidentiality, integrity and availability of ePHI, then put security measures in place to reduce those risks to a reasonable level. The analysis has to cover every system where ePHI lives, including cloud services, medical devices and vendors.
Missing or incomplete risk analysis is one of the most common problems HHS finds in its investigations. A documented, current assessment is also what cyber insurers, partners and auditors ask to see. HHS proposed updates to the Security Rule in January 2025. As of 2026 they have not been finalized, and a sound risk analysis is required either way.
What’s included
HIPAA risk analysis services built for healthcare
ePHI inventory
We find where ePHI is created, stored and sent, across EHRs, devices, email, cloud and vendors.
Threats and vulnerabilities
Realistic threats such as ransomware, phishing and lost devices, matched against your weaknesses.
Safeguards review
Administrative, physical and technical safeguards measured against Security Rule requirements.
Likelihood and impact rating
Each risk rated consistently so your highest priorities are clear.
Risk management plan
A prioritized plan with owners and dates to bring each risk to a reasonable level.
How it works
How your HIPAA security risk assessment works
Scope and inventory
We define the organization, locations and systems in scope and map where ePHI flows.
Interview and review
We meet with clinical, administrative and IT staff and review policies, configurations and vendor agreements.
Analyze and rate
Threats, vulnerabilities and current safeguards are analyzed and each risk is rated for likelihood and impact.
Report and plan
You receive the documented risk analysis and a risk management plan, and we walk your leadership through it.
The HHS SRA tool
How this compares with the free HHS SRA tool
HHS offers a free Security Risk Assessment (SRA) Tool to help small and medium-sized providers work through a risk assessment. It is a useful starting point, and HHS notes that using it does not by itself make you compliant.
The tool depends on the answers you enter. A HIPAA SRA consultant brings independent judgment, tests what your team reports, covers complex environments with many systems and vendors, and gives you a remediation plan and engineers to carry it out.

Deliverables
What you receive
FAQ
HIPAA security risk assessment questions
Related services
Related services
Talk to a HIPAA expert
Get a HIPAA risk analysis you can stand behind
Tell us about your organization and an advisor will reply by email to scope your HIPAA security risk assessment.
Prefer email? Write to [email protected] or call (858) 712-0040.
