
Many healthcare leaders believe their organization has completed a HIPAA Security Risk Analysis because someone reviewed the firewall, installed antivirus software, or completed an online questionnaire.
That is not a comprehensive Security Risk Analysis.
A valid HIPAA Security Risk Analysis, commonly called an SRA, is a documented assessment of how electronic protected health information is created, received, maintained, transmitted, accessed, and protected throughout your organization.
It examines technology. But it must also examine your people, physical environment, daily workflows, vendors, policies, documentation, and decision-making processes.
When those areas are overlooked, the organization may have cybersecurity tools in place while still operating with serious compliance gaps.
That is why the SRA is the foundation of the HIPAA Security Rule.
The SRA Is a Legal Requirement
The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities affecting the confidentiality, integrity, and availability of electronic protected health information, or ePHI.
This is not an optional cybersecurity exercise.
It is a required component of the security management process.
The SRA should help your organization answer several critical questions:
Where does ePHI exist?
Who can access it?
How does it move through the organization?
Which systems, devices, facilities, vendors, and employees interact with it?
What threats could expose, alter, destroy, or make the information unavailable?
Which safeguards are currently in place?
Are those safeguards reasonable and effective?
What corrective actions are still needed?
Who is responsible for completing those actions?
How will remediation be documented and monitored?
The Security Rule does not prescribe one mandatory format for every organization. However, the assessment must be accurate, thorough, appropriately documented, and tailored to the organization’s actual operations.
A generic template that does not reflect your organization’s environment is not enough.
Why an SRA Is Not Just an IT Project
Information technology is an important part of the assessment, but technology represents only one portion of your risk.
An effective SRA evaluates administrative, physical, and technical safeguards. The Security Rule uses all three because healthcare information can be compromised through far more than a computer attack.
A comprehensive assessment should consider areas such as:
Workforce Practices
Your employees and contractors interact with sensitive information every day.
The SRA should examine:
Employee onboarding and offboarding
Access authorization
Role-based permissions
Security awareness training
Password practices
Remote work procedures
Sanction policies
Terminated employee access
Use of personal devices
Reporting of suspected security incidents
A sophisticated firewall cannot protect information when former employees retain access or current employees share passwords.
Operational Workflows
Your written policies may look compliant while your actual workflows tell a different story.
The assessment should evaluate how information is handled during:
Patient registration
Scheduling
Billing
Telehealth appointments
Clinical documentation
Email communication
Prescription management
Records requests
File transfers
Remote access
Mobile device use
Data disposal
Emergency operations
Compliance depends on what your workforce actually does, not only what your policy manual says it should do.
Physical Security
Electronic information can be exposed through physical access to equipment, workstations, server rooms, mobile devices, and facilities.
Your SRA should consider:
Workstation placement
Screen visibility
Facility access
Visitor controls
Server and network equipment security
Device storage
Laptop transportation
Lost or stolen devices
Paper records containing system credentials
Disposal or reuse of electronic equipment
Third-Party Vendors
Healthcare organizations increasingly depend on outside companies for hosting, billing, communications, data storage, analytics, telehealth, software support, and other critical services.
Every vendor relationship can introduce risk.
A comprehensive SRA should examine:
Which vendors create, receive, maintain, or transmit ePHI
Whether appropriate Business Associate Agreements are in place
Whether subcontractors are involved
How vendor access is authorized and terminated
Whether vendors have experienced security incidents
Whether contracts include security responsibilities
How vendors notify your organization of incidents
Whether vendor security practices are reviewed
Whether data can be retrieved if the vendor becomes unavailable
The federal SRA tool developed by federal health information technology officials and the HHS Office for Civil Rights includes asset and vendor management because these areas are integral to understanding an organization’s risk.
Why So Many SRAs Fail
Most failed SRAs do not fail because the organization did nothing.
They fail because the organization did something incomplete and believed it was enough.
Common problems include:
The Assessment Only Covers the EHR
Electronic protected health information may exist in email accounts, cloud storage, billing platforms, mobile devices, diagnostic equipment, backup systems, shared drives, text messages, spreadsheets, and vendor systems.
Reviewing only the electronic health record leaves major portions of the environment unassessed.
The Organization Uses a Generic Checklist
A checklist may help begin the process, but it does not automatically demonstrate an accurate and thorough analysis.
The assessment must reflect your organization’s actual systems, locations, workforce, workflows, threats, vulnerabilities, and safeguards.
The SRA Is Assigned Entirely to IT
Your IT provider may understand your network, devices, and technical controls.
It may not know whether terminated employees are removed promptly, whether staff members use personal email, whether vendor agreements are current, or whether employees bypass approved workflows.
The process requires participation from leadership, compliance, operations, human resources, clinical staff, information technology, and other relevant departments.
The Organization Identifies Risks but Does Not Manage Them
An SRA is not complete simply because risks were listed.
The Security Rule also requires organizations to implement security measures sufficient to reduce identified risks and vulnerabilities to a reasonable and appropriate level.
That means the organization needs a documented risk-management plan containing:
Identified deficiencies
Corrective actions
Assigned responsibility
Target completion dates
Priority levels
Progress updates
Supporting evidence
Leadership oversight
An unresolved risk that remains on the same report year after year may demonstrate that the organization knew about the problem but failed to address it.
The Assessment Is Outdated
HIPAA does not establish one universal rule stating that every regulated entity must conduct a completely new SRA on the same date each year.
However, risk analysis is an ongoing process. It should be reviewed and updated when there are environmental or operational changes that affect ePHI.
Examples include:
Opening or closing a location
Changing an EHR
Adding a new software platform
Beginning telehealth services
Expanding remote work
Changing vendors
Experiencing a security incident
Merging with another organization
Adding connected medical devices
Changing network infrastructure
Discovering new vulnerabilities
Making significant workforce changes
Many organizations use an annual review as their minimum internal compliance cycle. Certain federal programs also require eligible participants to complete and attest to Security Risk Analysis activities during the applicable calendar-year performance period.
An old SRA that no longer reflects your organization’s current operations cannot provide a reliable basis for decision-making.
The Difference Between an SRA and a Vulnerability Scan
A vulnerability scan uses technology to identify potential weaknesses in networks, devices, software, or configurations.
It can be an important part of the process.
It is not the entire SRA.
A scan may identify:
Missing software updates
Unsupported operating systems
Open ports
Weak configurations
Known vulnerabilities
Unprotected devices
A comprehensive SRA places those findings within the larger operational environment.
It determines:
Whether ePHI is affected
How likely the vulnerability is to be exploited
What the potential impact would be
Which safeguards already exist
Whether the remaining risk is acceptable
What corrective action is required
Who will complete that action
How completion will be verified
Technology identifies certain vulnerabilities. Risk analysis evaluates what those vulnerabilities mean to your organization.
The High Stakes of an Inadequate SRA
The Office for Civil Rights has repeatedly emphasized that risk analysis is foundational to HIPAA Security Rule compliance.
OCR has also established a Risk Analysis Initiative focused on investigations involving failures to perform accurate and thorough assessments. In April 2026, OCR announced four ransomware-related settlements under its enforcement activities, including matters associated with that initiative.
OCR has warned that failing to conduct a risk analysis can foreshadow a future breach because the organization may not know where its information is located or which safeguards are needed.
The consequences of an inadequate SRA may include:
Regulatory investigations
Corrective action plans
Financial settlements or civil monetary penalties
Breach-notification expenses
Business interruption
Ransomware recovery costs
Loss of patient confidence
Contractual disputes
Insurance complications
Increased legal exposure
Federal-program attestation concerns
The SRA often becomes one of the first documents requested after a breach, complaint, audit, or compliance review.
At that point, the organization is no longer preparing its story.
It is defending it.
When a Compliance Attestation Creates Additional Risk
Some federal healthcare programs require eligible participants to attest that Security Risk Analysis activities were completed during the applicable reporting period.
For example, current Medicare Promoting Interoperability and MIPS requirements include Security Risk Analysis and risk-management attestations for participating organizations or clinicians.
An attestation should never be treated as a routine checkbox.
A federal investigation involving a Kansas hospital alleged that the hospital falsely attested that it had conducted or reviewed required security risk analyses for federal EHR incentive-program reporting periods. The matter resulted in a $250,000 False Claims Act settlement.
This does not mean that every incomplete SRA automatically constitutes fraud.
It does mean that knowingly making an inaccurate compliance attestation can create exposure far beyond an ordinary documentation deficiency.
Leadership should be able to support every attestation with current, complete, and credible evidence.
Seven Signs Your Current SRA May Not Be Defensible
Your organization may need immediate assistance if:
Your SRA is only a few pages long and consists mainly of yes-or-no answers.
The assessment was completed without input from operations, human resources, compliance, or leadership.
The scope does not identify every location where ePHI is created, received, maintained, or transmitted.
Vendors, cloud platforms, mobile devices, remote workers, and connected equipment are missing.
The report lists risks but does not include a documented remediation plan.
The assessment has not been reviewed since major operational or technology changes occurred.
Leadership has attested to compliance but cannot produce documentation supporting the organization’s conclusions.
The presence of any one of these problems does not automatically prove noncompliance.
It does indicate that your SRA deserves a closer review.
What an Effective SRA Should Produce
A professional Security Risk Analysis should leave your organization with more than a completed questionnaire.
It should produce a clear and defensible record of:
The assessment’s scope
The systems and information evaluated
The methods used
The individuals involved
The threats identified
The vulnerabilities identified
Existing safeguards
Likelihood and impact determinations
Assigned risk levels
Recommended corrective actions
Remediation priorities
Responsible parties
Target completion dates
Supporting evidence
Leadership review
Ongoing monitoring expectations
The final report should help leadership understand where the organization is exposed, what should be corrected first, and how available resources should be allocated.
Why Outside Review Matters
Internal teams understand the organization’s daily operations.
That familiarity is valuable, but it can also create blind spots.
Organizations frequently accept inherited workflows because “that is how we have always done it.” Employees may not recognize that routine practices create risk. IT providers may focus on technical controls while missing operational or contractual concerns. Leadership may assume that a completed questionnaire represents full compliance.
An independent assessment adds structure, objectivity, and accountability.
Taino Consultants Inc. helps healthcare organizations evaluate the full operational environment surrounding ePHI.
Our approach considers:
Technology and cybersecurity
Workforce access
Human resources practices
Physical safeguards
Clinical and administrative workflows
Vendor relationships
Business Associate Agreements
Policies and procedures
Incident-response readiness
Risk-management documentation
Leadership oversight
Federal-program attestation support
The goal is not to create another document that sits in a folder.
The goal is to provide a practical roadmap your organization can use to reduce risk and demonstrate a reasonable, organized compliance process.
Do Not Wait for an Incident to Test Your Foundation
A breach is one of the worst times to discover that your Security Risk Analysis was incomplete.
By then, regulators, attorneys, insurers, patients, business partners, and leadership may all be asking the same questions:
Where was the information?
What risks had been identified?
What safeguards were in place?
What corrective actions were taken?
Who was responsible?
Where is the documentation?
A comprehensive SRA helps your organization answer those questions before they become part of an investigation.
Your organization may already have strong security measures. It may also have risks that have gone unnoticed because no one has examined the entire environment.
The only responsible way to know is to conduct a thorough assessment.
Schedule Your Security Risk Analysis
Do not rely on assumptions, outdated reports, generic checklists, or incomplete technical reviews.
Taino Consultants Inc. can help you determine whether your current Security Risk Analysis accurately reflects your systems, workforce, vendors, facilities, and daily operations.
Schedule your SRA consultation today.
Our team will help you:
Define the appropriate scope
Identify operational and technical blind spots
Evaluate existing safeguards
Prioritize high-risk deficiencies
Develop a practical remediation roadmap
Strengthen your compliance documentation
Prepare for audits, investigations, attestations, and security incidents
Your HIPAA compliance program is only as strong as the risk analysis supporting it.
Build the foundation before someone else tests it.
Schedule your Security Risk Analysis with Taino Consultants Inc. today!
#BusinessAssociates #HealthcareLaw #VendorRiskManagement #HIPAA2026 #ExecutiveLeadership
About Dr. Jose I. Delgado
Dr. Jose I. Delgado is the founder and CEO of Taino Consultants, a veteran-owned, 8(a) graduate healthcare IT consulting firm based in St. Augustine, Florida. With over 30 years of experience in healthcare compliance and government contracting, Dr. Delgado has helped organizations navigate HIPAA, MACRA/MIPS, and federal IT security requirements.
Need help with healthcare compliance?
Taino Consultants provides HIPAA compliance consulting, MACRA/MIPS compliance support, and healthcare IT modernization services for government and private healthcare organizations.
Schedule a consultationRelated articles

The Four Compliance Phrases Shielding Your Practice from Reality—And Leaving You Exposed to Federal Audits

The $10 Million Wake-Up Call: Lessons for Healthcare Providers from the Watson Clinic Breach
