HHS Updates Security Risk Assessment Tool
The U.S. Department of Health and Human Services (HHS) Office of the National Coordinator for Health IT (ONC) and Office for Civil Rights (OCR) have released an updated version of the Security Risk Assessment (SRA) Tool. The tool can be used by HIPAA-regulated entities to guide them through the risk analysis process, and it is especially useful for small and medium-sized regulated entities, including HIPAA-covered entities and business associates.
In order for risks to be managed and reduced to a low and acceptable level, a HIPAA-regulated entity must first identify all risks and vulnerabilities to ePHI. In order to do that, HIPAA-regulated entities are required to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the organization.
OCR’s investigations of data breaches and HIPAA compliance audits frequently show that regulated entities have conducted incomplete risk analyses, and in some cases, have not conducted a risk analysis. If the risk analysis is not conducted or if it is incomplete, regulated entities will not be able to effectively reduce risk. It is not possible to effectively reduce risks and vulnerabilities to ePHI if regulated entities do not know where the risks and vulnerabilities are.
To help small and medium-sized regulated entities complete this important Security Rule requirement, the HHS developed its SRA tool. The SRA Tool is a downloadable desktop application – an Excel workbook version is also available – that guides regulated entities through the security risk assessment process. The application uses a simple, wizard-based approach, incorporating multiple choice questions, threat and vulnerability assessments, and asset and vendor management, with guidance and references provided throughout.
The latest version of the tool (September 2026 – version 3.7) contains content improvements in its questions, responses, and education to ensure it remains relevant in an evolving cybersecurity environment. The latest version includes new questions to address persistent risk areas such as remote access and telehealth; the assessment scope has been increased to account for every location that creates, receives, maintains, and transmits ePHI; and the system activity logging question has been modernized to cover the technologies that practices are now using.
The latest version also features expanded asset examples to include newer technologies and includes potential review triggers for when to update security assessments. The HHS has also made several minor improvements in response to comments from users, fixed bugs, and updated software libraries. While the SRA Tool may not identify all risks and vulnerabilities to ePHI by itself, it is a valuable tool to help regulated entities complete their risk analyses and identify risks and vulnerabilities to guide their risk management processes.
It should be noted that the risk analysis is not a one-time task; it is an ongoing process. Risk analyses should be completed regularly – at least every 12 months – and following any material changes to regulated entities’ electronic environments. In addition to the tool, regulated entities should follow HHS guidance on risk analyses.
OCR currently has an enforcement initiative targeting noncompliance with the risk analysis implementation specification of the Security Rule, and has so far imposed 14 financial penalties under the initiative. This year, the initiative has been expanded to cover risk management. In addition to requiring evidence that HIPAA-compliant risk analyses have been conducted, OCR will request evidence that regulated entities have acted on the findings of their risk analyses and have reduced risks in a timely manner.
