(401) 203-5032

Guides

What a HIPAA security risk analysis is, and what OCR asks for first

By Mario Del MazoUpdated August 9, 20268 minute read

Somewhere in your practice's paperwork, an attestation says a security risk analysis exists. Many small practices have never actually performed one, or did a checklist years ago that nobody has looked at since. That gap matters because the risk analysis is the foundation the whole Security Rule is built on, and it is the first document the Office for Civil Rights requests when a complaint or a breach puts a practice in front of an investigator. This guide explains what the analysis actually is, what it covers, and what a good one looks like at small-practice scale. It is the IT side of the subject, not legal advice; your obligations are a question for qualified healthcare counsel.

What is a HIPAA security risk analysis?

The Security Rule requires every covered practice, regardless of size, to conduct a thorough, documented assessment of the risks to all of its electronic protected health information: where patient data lives, how it moves, who can reach it, and what protects it. That requirement does not scale away for a two-provider office; it is the same citation for you as for a hospital system. The same analysis is also what Medicare's incentive programs have practices attest to, which is why many offices have signed for its existence without quite possessing it. And one thing it is not: a certification. There is no such thing as being HIPAA certified, and anyone selling a certificate is selling paper.

What it actually covers

The rule groups its safeguards into three families, and in a small practice they translate into concrete questions. Administrative: who is responsible for security, who has access to what, whether staff are trained, what the plan is when a system fails, and whether every vendor that touches patient data has signed a business associate agreement. Physical: whether a screen with a chart on it is visible from the waiting room, what happens to old drives and copiers when they leave the building, and who can walk into the room where the server sits. Technical: unique logins rather than shared ones, multi-factor sign-in, encryption on the devices that could be stolen, and audit logs that record who opened which record. A real analysis walks all of it, scores what it finds, and writes the findings in language the practice owner can act on.

The trap in the word addressable

Some safeguards in the rule are labeled required and some addressable, and the second word has lulled a lot of practices. Addressable does not mean optional. It means the practice must either implement the safeguard or document, in writing, why it is not reasonable in its environment and what equivalent protection stands in its place. Skipping an addressable item without that written reasoning is a gap, and it is one of the most common findings in a small-practice assessment, because somewhere along the way somebody read addressable as skippable and moved on.

What OCR asks for first

When an investigation starts, the opening requests are predictable: the current risk analysis, and the risk management plan that addresses what it found. That second document matters as much as the first, because finding risk is step one and reducing it to a reasonable level is the actual obligation. A risk analysis with no follow-up plan documents that the practice knew and did nothing, which is worse than paperwork trouble. Behind those two come the supporting records: training logs, signed business associate agreements, evidence that somebody reviews system activity, and the breach notification procedure. Every one of those is producible in minutes by a practice that has been keeping them, and by no one else.

What it looks like when the answer is no

None of this is hypothetical, and the public record is more specific than most practices realize. On 29 July 2026 the Office for Civil Rights published a resolution agreement with OSF Healthcare System. The facts are in the document: ransomware found on 23 April 2021, the stolen records of 53,907 patients, notification on 1 October 2021, and a resolution amount of $552,250.

The part worth reading closely is the order of the findings. The first item of covered conduct, before the breach itself, is that the organization failed to conduct an accurate and thorough risk analysis of the risks to the electronic health information it held. The breach is item two. Late notice to patients and to the Secretary are three and four. That ordering is the whole subject of this guide in one paragraph: the ransomware is what happened, and the missing analysis is what OCR wrote down first.

Then look at the dates. The attack was April 2021 and the agreement was July 2026. Over five years passed, and what was examined was the state of the documentation on the day of the breach. That is the uncomfortable thing about a risk analysis: it is the one control you cannot put in place after you need it. Everything else on a remediation list can be fixed next week and still count. This one is judged at a date that has already gone by.

Nor is this reserved for health systems. The same public list of resolution agreements runs to a neurology practice, an ambulatory surgery center, and a surgical group that settled for $10,000. OCR publishes every one of them, which means you can read the covered conduct in a real case rather than take anyone's word for what matters.

What a good one looks like for a small practice

Sized to the practice, scored control by control against the rule's actual citations, written in plain language, and ending in a prioritized plan with dates, which becomes the risk management plan OCR asks about. Performed by an outside party, it must be done under a signed business associate agreement, because the assessor is handling information about your patient data systems; that is how we deliver it. And it should be refreshed annually or when the practice changes, because an analysis describes a moment, and practices do not hold still. What it never includes is a certificate, a seal, or a promise of compliance, because none of those exist to give. How an engagement starts is on the healthcare page, and a first conversation costs nothing and decides nothing.

FAQ

Is there such a thing as HIPAA certified?

No. There is no government HIPAA certification, for a practice or for a vendor, and completing an assessment does not by itself make anyone compliant. A seal or badge that says HIPAA Certified is a marketing product. What actually exists is documented compliance work: a current risk analysis, a plan that addresses it, and records that show both.

How often does the risk analysis need to be redone?

The rule requires it to be kept current rather than naming a date, and in practice that means reviewing it annually and after any significant change: a new EHR, a move, new equipment, or a security incident. An analysis from several years ago describes a practice that no longer exists, which is how it reads to an investigator too.

Our EHR vendor says they are HIPAA compliant. Does that cover us?

No. The vendor's obligations cover their platform. Yours cover your practice: the devices in your office, your staff and their training, your access decisions, your backups, your other vendors and their agreements, and your procedures when something goes wrong. A compliant EHR inside a practice with no risk analysis is still a practice with no risk analysis.

Does OCR really pursue small practices, or only big health systems?

Both. The public list of resolution agreements includes a neurology practice, an ambulatory surgery center, and a surgical group that settled for $10,000, alongside the health systems. The more useful pattern is not the size of the organization but the timing: OCR settled with OSF Healthcare System in July 2026 over a ransomware attack from April 2021, and the first item of covered conduct was failure to conduct an accurate and thorough risk analysis. What gets examined is the state of your documentation on the day of the breach, which is why this is the one control you cannot put in place after you need it.

Who should perform it, and what does it cost?

HHS publishes a free self-assessment tool, and a practice with the time and expertise can work through it internally. Most small practices have neither, which is where an outside provider comes in; we perform the assessment under a signed Business Associate Agreement, and the deliverable is built to support the risk analysis the rule requires. On our Managed IT + HIPAA plan, $185 per user per month, the analysis is redone annually as part of the plan rather than quoted each time. Standalone work for a practice not on a plan is billed at $125 per hour, quoted up front so you approve the number before the work starts. What the rule obligates your practice to do remains a question for qualified healthcare counsel.

Attested to a risk analysis you are not sure exists? You are far from the only practice in that position, and the fix is a process, not a panic. The healthcare page explains how we work with small practices, delivered under a Business Associate Agreement, priced before work starts.

About the author

Mario Del Mazo is the owner of IT First Response, a managed IT and security practice in Fort Myers serving Lee County, Florida. His background is corporate IT for a healthcare organization operating under HIPAA and HITRUST standards. He publishes his prices, and every client environment is documented so nothing has to be explained twice. More about Mario.