Skip to main content
Guide

HIPAA Risk Assessment Checklist for Small Practices

Your annual Security Risk Analysis (SRA) is the most-audited HIPAA requirement — and the one small practices most often miss. This is a plain-language, nine-step checklist you can complete yourself, aligned to NIST 800-66 and HIPAA §164.308.

Why this checklist exists

Under HIPAA §164.308(a)(1)(ii)(A), every covered entity must conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information. In practice, this is the artifact HHS OCR asks for first after a breach — and the artifact your cyber insurer wants at renewal. When it is missing, penalties reach into the tier-4 range (up to CA$2.13M annual cap). This checklist walks a 1–25 provider practice through the nine steps in plain language.

  1. Step 01§164.308(a)(1)(ii)(A) · NIST 800-66 Step 1

    Inventory every system that touches ePHI

    You cannot analyze risk to systems you have not named. Walk every workflow — front desk, exam room, billing, imaging, refills, telehealth, backups — and list every place electronic protected health information (ePHI) is created, received, stored, or transmitted.

    • EHR / practice-management platform (name, version, hosting model)
    • E-prescribing and EPCS system
    • Clearinghouse and billing service
    • Patient portal and secure messaging
    • Telehealth platform (audio, video, transcripts, chat)
    • Imaging (PACS, ultrasound, EKG, in-office lab)
    • Connected medical devices (glucometers, monitors, infusion, home devices)
    • Business email and shared drives
    • Backups (on-site, cloud, vendor-managed)
    • Staff and provider mobile devices
    • Front-desk fax, scanners, and multifunction printers
  2. Step 02§164.308(a)(1)(ii)(A) · NIST 800-66 Step 2

    Identify reasonably anticipated threats and vulnerabilities

    For each system on the inventory, name what could go wrong and how. OCR expects both intentional threats (ransomware, phishing, insider access) and unintentional ones (lost device, misdirected fax, vendor outage). Use plain language — you are documenting reality, not a threat-modeling PhD.

    • Ransomware or extortion against the EHR
    • Business email compromise at the front desk
    • Lost or stolen laptop, tablet, phone, or USB
    • Vendor / business associate breach (billing, MSP, clearinghouse, EHR)
    • Portal account takeover targeting refills
    • Insider snooping or curiosity access
    • Misdirected fax or email of PHI
    • Clearinghouse or EHR outage disrupting downtime billing
    • Compromise of a connected medical device flagged by CISA or FDA
  3. Step 03§164.308(a)(1)(ii)(A) · NIST 800-66 Step 3

    Assess your current security measures

    For each system, document what is already in place. HIPAA calls these administrative, physical, and technical safeguards. This is where most small practices realize the gap is not the control — it is the documentation of the control.

    • MFA enforced on EHR, email, portal, and remote access
    • Unique user accounts and role-based access
    • Encryption at rest on devices and in transit
    • Audit logging turned on and reviewed at a defined cadence
    • Written sanction and workforce access-termination policy
    • Business Associate Agreements on file for every vendor with ePHI
    • Backups tested (not just performed) with a documented restore
    • Physical safeguards: locked server closet, screen privacy, badge access
  4. Step 04§164.308(a)(1)(ii)(B) · NIST 800-66 Step 4

    Determine likelihood and impact

    For each threat–vulnerability pair, rate how likely it is and how bad it would be if it happened. A 3×3 matrix (low / medium / high on each axis) is more than enough for a small practice — OCR is not grading your calculus, they want to see that you thought about it.

    • Likelihood rated for every threat you named in Step 02
    • Impact rated in terms of patient safety, HIPAA breach scope, and revenue
    • Special weight for scenarios that would trigger the 60-day breach clock
    • Note any threats where a single control failure creates multiple exposures
  5. Step 05§164.308(a)(1)(ii)(B) · NIST 800-66 Step 5

    Assign a risk level

    Multiply likelihood by impact to get a risk rating for each pair. Highs and mediums drive your remediation plan. Lows are documented and accepted.

    • Every threat has a risk rating (low / medium / high)
    • High-risk items have a written owner and a target date
    • Accepted risks have a documented rationale
  6. Step 06§164.308(a)(1)(ii)(B) · §164.316(b)(1) · NIST 800-66 Step 6

    Write the remediation plan

    This is what OCR asks for after "show me your SRA." A plan with owners and dates converts risk analysis from theatre into evidence of good faith. It also becomes the artifact your cyber insurer wants at renewal.

    • Each medium/high risk has a named owner
    • Each has a target date and a completion criterion
    • The plan is reviewed at a defined cadence (quarterly is common)
    • Progress since last year's SRA is documented
  7. Step 07§164.308(a)(3), (a)(4), (a)(5)

    Review workforce training, sanctions, and access

    The Security Rule expects periodic security awareness training, a sanction policy for workforce members who violate it, and evidence that access is granted on a least-privilege basis and terminated when a person leaves.

    • Security awareness training completed in the past 12 months
    • Sanction policy exists and is applied consistently
    • New-hire access provisioning follows a documented workflow
    • Terminations trigger same-day access removal — EHR, email, portal, VPN, MFA
  8. Step 08§164.316(b)(1) · §164.316(b)(2)

    Document the analysis and the date

    OCR's #1 finding for small practices is the absence of a documented SRA. HIPAA requires you to keep the analysis, the decisions, and the actions in a format that can be produced on request — for six years from the date created or last in effect.

    • Analysis is written down (a spreadsheet is acceptable)
    • Date performed and reviewer named
    • Version history retained (six years minimum)
    • Stored somewhere a leadership team member can retrieve within an hour
  9. Step 09§164.308(a)(8) · NIST 800-66 Step 7

    Schedule the next review

    The SRA is not a one-time exercise. Repeat annually at minimum, and any time you materially change systems — new EHR, new location, new modality, new business associate, or after any incident.

    • Next scheduled review is on the practice calendar
    • Trigger list for out-of-cycle reviews is written down
    • Prior year's remediation plan is closed out in the new SRA
Next step

Want a second set of eyes on the finished SRA?

Run the ten-question self-check first — it takes five minutes and tells you whether your documentation would survive an OCR request. Then talk to us about the Practice subscription if you want the SRA templated, reviewed, and refreshed on a schedule.

Not legal advice. HIPAA §164.308 and §164.316 govern; consult counsel for enforcement questions.

Built by

Travis R. Barlow.

25+ years in incident response. 580+ engagements. Founder of AtlSecCon, one of Canada's longest-running security conferences. No SDR, no junior associate — you talk to the person who has run this incident before.

25+
years IR
580+
engagements
1–25
provider ICP
Scenarios we have walked practices through

Illustrative composites drawn from practitioner conversations. No patient or practice identifiers.

  • Ransomware · Friday afternoon

    Walked the office manager of an 8-provider primary-care clinic through the first three hours — who to call, what not to touch, and what the 60-day HIPAA clock meant.

  • Cyber-insurer renewal

    A 3-provider dermatology clinic pulled the playbooks, customized two pages, and the underwriter accepted the plan — instead of a $9,000 consulting engagement.

  • BEC wire-fraud attempt

    A 5-provider OB/GYN group had read the Front-Desk Email Compromise playbook the week before. Their dual-approval rule caught the wire and prevented the loss.

  • MSP handoff to physician-owner

    The HIPAA self-check produced a one-page gap list an MSP could hand to a physician-owner — no jargon translation required.

Upgrade — vCISO

Your MIPS-ready SRA — and a named owner for the 60-day clock.

Training gets your people ready and advisory is there when something breaks. When you need someone to own the program — the HIPAA Security Rule, your annual SRA, and 405(d) “reasonable security” — and be the name your OCR, cyber insurer, EHR/clearinghouse business associates, and (in Canada) your provincial health privacy commissioner can point to, that’s the HackFirstAid vCISO: a security leader on retainer. Built for the EHR/vendor ransomware event mid-clinic-day, where the breach clock starts before the schedule clears.

We own your program

Strategy, risk register, roadmap, governance, cadenced reviews, and the OCR, cyber-insurer, EHR/clearinghouse BA, and provincial privacy commissioner conversations.

Independent partners execute

DFIR, SOC, pen-testing, tooling, legal, brokerage — coordinated by your vCISO, never sold by us.

Small Practice
CA$1,800/mo
Solo & the smallest offices — quarterly cadence
Foundations
CA$3,000/mo
Managed
CA$6,500/mo
Most chosen
Embedded
CA$12,000/mo

Billed annually. Every tier includes a named vCISO, a 90-day on-ramp, and household coverage.