What Does a HIPAA Risk Assessment Actually Involve for a Small Practice?
What does a HIPAA risk assessment actually involve?
A HIPAA risk assessment is a written review of every place your practice creates, stores or sends electronic patient information, what could go wrong with each, how likely and how serious that would be, and what you will do about it. It is required, not optional. For a small practice it is mostly an inventory exercise, and the inventory is where most practices come up short.
The rule itself is one sentence. Under 45 CFR 164.308, every covered practice must “conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information.” The next requirement is to actually reduce those risks to “a reasonable and appropriate level.”
That sounds abstract, so this guide translates it into what a small medical or dental practice actually does, from the IT side.
What are the steps in a HIPAA risk assessment?
HHS’s guidance on risk analysis lists the elements every assessment must include, whatever method you use. In plain terms:
- Scope. All electronic patient information the practice “creates, receives, maintains, or transmits.” Not just the EHR.
- Data collection. Find where that information actually lives. This is the step that decides whether the rest is real.
- Threats and vulnerabilities. For each place, what could go wrong: a stolen laptop, a phishing email, a failed backup, a former employee who still has a login.
- Current safeguards. What you already have in place against each one.
- Likelihood. How likely each threat is, given those safeguards.
- Impact. How bad it would be if it happened.
- Risk level. Likelihood and impact combined, with “a list of corrective actions” for each risk.
- Documentation. Written down. HHS does not require a specific format, but it must exist.
- Review and update. Revisited as the practice changes.
Where does patient information actually live in a small practice?
Step two is where we see assessments fall apart, because patient information spreads well beyond the EHR. In a typical small practice it also lives in:
- Email: referrals, lab results, patient messages, and every attachment anyone ever saved
- The phone system: voicemail, call recordings and voicemail-to-email (see is VoIP HIPAA compliant?)
- Fax: an online fax service that drops documents into a shared inbox
- Scanners and copiers: many keep copies on an internal drive
- Workstations and laptops: downloads folders, exported reports, desktop shortcuts to spreadsheets
- Phones and tablets: staff devices with work email, and photos taken for clinical reasons (see our guide to personal phones at work)
- Backups: every copy, wherever it is stored
- Vendors: billing companies, IT providers, cloud storage, anyone with a Business Associate Agreement or who should have one
An assessment that only covers the EHR misses most of where breaches actually start. The questions that find the rest are simple: where do referrals arrive, who can listen to voicemail, what happens to scans, and which devices can open work email.
How often does a practice need a HIPAA risk assessment?
The current rule does not set a fixed schedule. HHS says the Security Rule “does not specify how frequently to perform risk analysis,” that the process “should be ongoing,” and that some practices do it annually or as needed. In practice, annually plus whenever something significant changes (a new EHR, a new office, a move to cloud phones) is the sensible default.
That may become a hard requirement. HHS’s proposed Security Rule update from January 2025 would require a written assessment reviewed “no less frequently than at least once every 12 months,” plus a written inventory of technology assets and a network map. As of October 2026 it is still a proposal, with final action listed for July 2027. A practice that builds the inventory now is ready either way.
Can a small practice do its own HIPAA risk assessment?
Yes. HIPAA does not require an outside firm. HHS’s own myth-busting page on risk analysis says it is “possible for small practices to do risk analysis themselves using self-help tools,” while adding that one that “will stand up to a compliance review will require expert knowledge.”
The government’s free starting point is the Security Risk Assessment Tool from HHS and the Office of the National Coordinator, currently version 3.7, aimed at “medium and small providers.” It walks you through the questions. Two cautions from its own page: using it “is neither required by nor guarantees compliance,” and the survey “alone may not identify all risks.” The tool asks what your safeguards are; it cannot check whether they actually work.
Is a HIPAA checklist the same as a risk assessment?
No. HHS lists “a checklist will suffice” among its myths and marks it false. A checklist tells you which safeguards exist. A risk assessment tells you which risks matter most in your practice and what you are doing about them, in writing. If your current “assessment” is a checklist with every box ticked, that is the gap.
What happens if a practice skips it?
Since 2024, HHS’s Office for Civil Rights has run a Risk Analysis Initiative focused specifically on this requirement, and it reaches small practices, not only hospitals:
| Organization | Type | Settlement | Announced |
|---|---|---|---|
| Northeast Surgical Group | Surgical practice, Michigan | $10,000 | January 2025 |
| Comprehensive Neurology | Small neurology practice, New York | $25,000 | April 2025 |
| Deer Oaks | Behavioral health provider | $225,000 | July 2025 |
| Regional Women’s Health Group | Women’s health provider network | $320,000 | August 2025 |
| Northeast Radiology | Radiology practice | $350,000 | April 2025 |
The settlement is rarely the biggest cost. Northeast Surgical’s case, for example, began as a ransomware investigation, and settlements like these come with a corrective action plan that OCR monitors. The missing risk assessment is what turns an incident into a finding.
How long do we have to keep the risk assessment?
Six years. Under 45 CFR 164.316, required documentation must be kept “for 6 years from the date of its creation or the date when it last was in effect, whichever is later.” Keep every version, not just the latest; the history is what shows the process is ongoing.
Does a small practice need the same assessment as a hospital?
No. The Security Rule is explicitly scalable. Section 164.306 tells practices to weigh “the size, complexity, and capabilities” of the organization and “the costs of security measures” when choosing safeguards. A five-person practice is not expected to buy what a hospital buys. It is expected to know its risks and make reasonable decisions about them, in writing.
What you should have at the end
- A written inventory of every system, device and vendor that touches patient information
- A list of threats and vulnerabilities for each, with likelihood, impact and a risk level
- A corrective action plan: who fixes what, by when, ranked by risk
- Evidence that key safeguards actually work, such as a backup you have restored from and MFA turned on for every account (see why “addressable” does not mean optional)
- A date for the next review, and a copy filed where you can find it in six years
Our HIPAA compliance checklist for Florida practices covers the wider program around the assessment. And because so many of these cases begin with a stolen device, what to do in the first hour after losing a laptop is worth reading too.
Need Help With the Technical Side?
iTech Plus supports medical and dental practices across Central Florida, from our base in Haines City to practices in Lakeland, Winter Haven, Davenport and Kissimmee. The part of a risk assessment most practices struggle with is the technical inventory and proving the safeguards work, which is our everyday work. See our HIPAA IT services.
If you want to know where you stand, we offer a free IT assessment with a written report and prioritised recommendations. Call (321) 221-7117 or email info@itechplus.co. This article explains the requirements; it is not legal advice.







