Skip to content
Compliance

The HIPAA Security Risk Assessment, Explained

August 7, 2026

If you only get one thing right in your HIPAA program, make it the risk assessment. It is the foundation everything else is built on, it is required by law, and it is the single most-cited failure in federal enforcement. And yet it is the piece practices most often skip, do once and forget, or reduce to a one-page checklist. Here is what the HIPAA Security Risk Assessment actually is and how to treat it seriously.

It is required, specifically

The HIPAA Security Rule requires a risk analysis under 45 CFR 164.308(a)(1)(ii)(A), part of the Security Management Process. The requirement is to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information. This applies to covered entities and to business associates, which includes your IT vendor. It is not optional, and "we are a small practice" is not an exemption.

It is the foundation, not a formality

Every other safeguard in the Security Rule is supposed to be implemented based on what the risk analysis finds. You cannot reasonably decide what protections you need until you have assessed where your risks actually are. That is why the risk analysis comes first. Skip it, and every other control you put in place is a guess. Do it well, and it becomes the plan that drives the rest of your security program.

What a real risk assessment covers

A genuine risk analysis inventories where ePHI lives, how it moves, and who can access it, then evaluates the threats and vulnerabilities against each of those, and documents the likelihood and impact. That includes your EMR, your email, your backups, your devices, your cloud services, and your vendors. It is not a questionnaire you fill out in an afternoon. It is a structured look at your actual environment, followed by a remediation plan in priority order.

It is the most-cited HIPAA failure

Failure to conduct an accurate and thorough risk analysis is consistently the most-cited HIPAA violation in Office for Civil Rights enforcement actions and audits. When something goes wrong and OCR gets involved, this is the first document they ask for. A practice that can produce a current, thorough risk analysis and a record of acting on it is in a fundamentally different position than one that cannot.

Do it, document it, and act on it, on a cadence

The requirement is not a one-time event. Environments change: you add a vendor, adopt a new system, open a location. The risk analysis should be reviewed and updated on a regular cadence and whenever something material changes, and, just as importantly, you have to act on what it finds and keep the records. HHS and ONC even publish a free Security Risk Assessment Tool, but a tool only helps if the assessment is honest and the findings get remediated.

HIPAA risk assessments in Texas: what is different

Texas practices have obligations beyond the federal Security Rule. The Texas Medical Records Privacy Act (HB 300) defines covered entity far more broadly than HIPAA, so businesses that merely come into possession of protected health information can be covered, and it layers on its own training and privacy requirements. Texas breach notification law requires notifying affected individuals within 60 days and reporting breaches affecting 250 or more Texans to the Texas Attorney General, who maintains a public list of reported breaches. The Texas Data Privacy and Security Act adds general data protection duties for many businesses as well.

For a risk assessment, that means two practical things. First, your assessment scope in Texas should cover state definitions of sensitive information, not just HIPAA ePHI. Second, enforcement can come from two directions, the HHS Office for Civil Rights and the Texas Attorney General, and both expect to see a current, documented risk analysis when something goes wrong.

Most DFW and Houston practices we work with settle into a rhythm of a full security risk assessment annually, refreshed whenever something material changes: a new EHR or practice management system, a new location, a merger, or a move to remote or offshore billing.

Want a quick read on where you stand first? Take the free 3-minute IT Risk Assessment.

How Galleon helps

We conduct HIPAA risk assessments for our clients, document them, and drive the remediation in priority order, then keep the posture current as the environment changes. As your IT partner we are also a business associate, so we hold the same obligation, and we produce the documentation that holds up under review. For a fast, informal starting point, our free IT Risk Assessment gives you a plain-language snapshot of where your gaps are before a formal analysis.

If you are not sure whether your last risk assessment is current, or whether one has ever been done, that uncertainty is the finding. Explore our Regulatory Compliance service, take the free IT Risk Assessment, or schedule a discovery call.

Get Started

Ready for a straight answer about your IT?

Schedule a 20-minute discovery call. We will tell you what is working, what is not, and what the gaps would cost.