US Federal Law United States

HIPAA Security Risk Analysis: How to Do It Right

The 45 CFR 164.308(a)(1) risk analysis: scope, methodology, common failures OCR cites, the Risk Analysis Initiative, and how to keep the assessment current.

Regulation

HIPAA Security Rule, 45 CFR 164.308(a)(1)(ii)(A); OCR Guidance on Risk Analysis; NIST SP 800-66r2

Max Penalty

Risk-analysis failures anchor OCR settlements from tens of thousands to multi-million dollar amounts, with willful-neglect tiers reaching roughly $2.1 million per violation category per year

Enforcing Authority

HHS Office for Civil Rights (OCR)

Official Source

www.hhs.gov

Executive Summary

  • The security risk analysis required by 45 CFR 164.308(a)(1)(ii)(A) is HIPAA's foundational control: an accurate, thorough assessment of risks to all ePHI the organization creates, receives, maintains, or transmits.
  • It is the most commonly cited failure in OCR enforcement, and OCR launched a dedicated Risk Analysis Initiative in 2024 that has produced a continuing series of settlements.
  • A compliant analysis is enterprise-wide and asset-based; gap assessments, penetration tests, and questionnaires do not satisfy the standard on their own.
  • The output must feed a risk management plan under 164.308(a)(1)(ii)(B), unremediated known risks are the aggravating fact pattern in the largest penalties.
  • OCR's guidance plus NIST SP 800-30/800-66 provide the accepted methodology; documentation is retained six years and refreshed on material change.

Every large OCR penalty tells the same story in its first paragraph: a breach happened, the investigation opened, and the entity could not produce a current, enterprise-wide risk analysis. The rule asks for one document, an honest map of where ePHI lives and what threatens it, and treats everything else in the Security Rule as flowing from it. OCR made the point structural in 2024 by building an entire enforcement initiative around this single provision. Doing the analysis well is genuinely cheaper than any alternative, including doing it badly.

Requirement45 CFR 164.308(a)(1)(ii)(A)
ScopeAll ePHI, enterprise-wide, asset-based
Not sufficientGap assessments, pen tests, questionnaires alone
FeedsRisk management plan, 164.308(a)(1)(ii)(B)
CadencePeriodic + on material change (annual in practice)
EnforcementOCR Risk Analysis Initiative (2024-)

Doing it right

Inventory before you assess. The ePHI asset and data-flow inventory is the analysis’s skeleton; the compliance roadmap shows where it anchors the whole program.

Rate risks you intend to treat. Every high risk needs a line in the risk management plan with an owner and date, unremediated known risks are what turn penalties from thousands into millions.

Cover the vendor edge. Business associates and their subcontractors hold your ePHI too; align the analysis with your BAA inventory and cloud arrangements.

Version and retain. Signed, dated, six years, with a change log that shows the analysis moved when the environment did; OCR’s enforcement trends show the document’s absence is the finding.

Web-facing systems belong in scope, tracker-based PHI leakage from hospital websites is an OCR-flagged risk: check your public pages with a free scan.

Frequently Asked Questions

What must the risk analysis cover?

All ePHI, everywhere: EHR and practice management systems, email, file shares, databases, cloud services (including shadow SaaS), medical devices and biomedical equipment, mobile and remote endpoints, backups and media, and PHI held by or flowing to business associates. The most common scoping failure is analyzing 'the EHR' while ignoring the imaging system, the billing vendor's SFTP drop, the marketing team's web forms, and departed-employee laptops. The analysis identifies threats and vulnerabilities per asset or asset class, rates likelihood and impact, documents current controls, and lands each risk at a level your risk management plan then accepts or treats.

What does OCR say does NOT count?

Three recurring substitutes fail: (1) a Security Rule gap assessment, checking whether each rule provision has a policy, which measures paperwork, not risk; (2) a penetration test or vulnerability scan, which samples technical weaknesses but does not inventory ePHI or assess enterprise risk; (3) a vendor questionnaire or automated tool run against part of the environment. OCR's guidance requires the analysis to be accurate and thorough for the entire organization. In resolution agreements, OCR repeatedly recites that the entity 'failed to conduct an accurate and thorough risk analysis' even where the entity had produced one of these substitutes.

How often must it be updated?

The rule says the analysis must be current, OCR reads this as periodic review plus event-driven refresh. Triggers: new or replaced systems (EHR migration, new cloud platform), mergers and acquisitions, new service lines (telehealth was the classic example), material incidents, and organizational restructuring. Annual review is the de facto industry standard and the cadence corrective action plans typically impose. The dated version history matters as much as the content: an investigator's first question after a breach is when the analysis was last updated and whether it covered the breached system.

What is the OCR Risk Analysis Initiative?

An enforcement program OCR announced in October 2024 focusing specifically on the risk analysis requirement, on the logic that most large breaches trace back to unassessed risk. It has produced a continuing series of settlements against providers, plans, and business associates, typically following ransomware or hacking breaches, where the investigation found no enterprise-wide risk analysis. The settlements pair five- to seven-figure payments with multi-year corrective action plans requiring a compliant analysis, a risk management plan, and OCR monitoring. Its practical message: after a breach, the absence of a current risk analysis converts an incident into a violation.

What methodology should we use?

OCR's own guidance is methodology-neutral but element-specific; NIST SP 800-30 (risk assessment) operationalized through SP 800-66r2 (the NIST-HIPAA crosswalk) is the accepted mainstream approach, and HHS's Security Risk Assessment Tool suits smaller practices. Whatever the method, produce: an ePHI asset inventory with data flows; a threat/vulnerability catalog per asset; likelihood-impact ratings with rationale; current-control documentation; residual risk levels; and a signed, dated report feeding a risk management plan with owners and deadlines. Six-year retention. If a regulator, cyber insurer, and your own security team can each use the document, it is probably right.

Regulatory Crosswalk

NIST SP 800-66NIST SP 800-30HITRUST CSF

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.