HIPAA

HIPAA security risk assessment for healthcare organizations

The HIPAA Security Rule requires an accurate and thorough risk analysis of the ePHI you create, receive, keep or send. We perform it, document it and turn the findings into a risk management plan you can follow and defend.

  • Risk analysis under the HIPAA Security Rule
  • Documented findings and risk management plan
  • For providers, practices and business associates
Clinician working at a workstation in an exam room

Healthcare focus

Assessments for providers, practices and business associates

From findings to fixes

Engineers who can close the gaps we find

Top virtual CISO services company

Recognized by Cyber Security Review

Security expert working with an IT manager at a laptop

What the rule requires

HIPAA risk analysis is the foundation of the Security Rule

Covered entities and business associates must conduct a risk analysis of potential risks and vulnerabilities to the confidentiality, integrity and availability of ePHI, then put security measures in place to reduce those risks to a reasonable level. The analysis has to cover every system where ePHI lives, including cloud services, medical devices and vendors.

Missing or incomplete risk analysis is one of the most common problems HHS finds in its investigations. A documented, current assessment is also what cyber insurers, partners and auditors ask to see. HHS proposed updates to the Security Rule in January 2025. As of 2026 they have not been finalized, and a sound risk analysis is required either way.

What’s included

HIPAA risk analysis services built for healthcare

How it works

How your HIPAA security risk assessment works

1

Scope and inventory

We define the organization, locations and systems in scope and map where ePHI flows.

2

Interview and review

We meet with clinical, administrative and IT staff and review policies, configurations and vendor agreements.

3

Analyze and rate

Threats, vulnerabilities and current safeguards are analyzed and each risk is rated for likelihood and impact.

4

Report and plan

You receive the documented risk analysis and a risk management plan, and we walk your leadership through it.

The HHS SRA tool

How this compares with the free HHS SRA tool

HHS offers a free Security Risk Assessment (SRA) Tool to help small and medium-sized providers work through a risk assessment. It is a useful starting point, and HHS notes that using it does not by itself make you compliant.

The tool depends on the answers you enter. A HIPAA SRA consultant brings independent judgment, tests what your team reports, covers complex environments with many systems and vendors, and gives you a remediation plan and engineers to carry it out.

  • Independent review of what is actually configured
  • Coverage for cloud, devices and business associates
  • A remediation plan with owners and dates
  • Documentation ready for auditors and insurers
Consultants reviewing plans with a client on site

Deliverables

What you receive

  • ePHI inventory and data flow summary
  • Documented risk analysis with ratings
  • Safeguard gap findings by requirement
  • Risk management plan with priorities
  • Executive summary for leadership
  • Readout session and remediation guidance

FAQ

HIPAA security risk assessment questions

Yes. The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough risk analysis of risks to ePHI and to manage those risks. It is a core requirement of the rule.

HIPAA does not set a fixed interval, but the analysis must be kept current. Most organizations update it every year and after major changes such as a new EHR, a merger or a move to the cloud.

Small practices can use it as a starting point. It relies on your own answers, and HHS notes that using it does not by itself make you compliant. Larger or more complex environments usually benefit from an independent assessment.

Cost depends on the number of locations, systems that hold ePHI, business associates and whether technical testing is included. We scope it on a short call and give you a fixed price.

Yes. Business associates that handle ePHI are directly subject to the Security Rule, including its risk analysis requirement.

A risk analysis identifies and rates risks to ePHI. An audit checks compliance against the rules. Our assessment gives you the documented risk analysis the rule requires and shows where your safeguards fall short.

Talk to a HIPAA expert

Get a HIPAA risk analysis you can stand behind

Tell us about your organization and an advisor will reply by email to scope your HIPAA security risk assessment.

  • Scoping call with a Triden advisor
  • A fixed price and timeline before work begins

Prefer email? Write to [email protected] or call (858) 712-0040.

Send us a message