Compliance & regulations
What is a HIPAA security risk assessment, and do you need one?
Reviewed by the Privacy Horizon team · Last reviewed
Quick answer
A HIPAA security risk assessment is a structured review of how electronic protected health information (ePHI) is created, received, stored, and transmitted, identifying threats, vulnerabilities, and the likelihood and impact of a breach. It is mandatory under the HIPAA Security Rule for covered entities and business associates that handle ePHI, including non-US vendors and SaaS firms serving US healthcare clients. If you touch US patient data, you almost certainly need one.
On this page
What is a HIPAA security risk assessment?
A HIPAA security risk assessment (often called a security risk analysis) is a systematic process for identifying where electronic protected health information (ePHI) lives in your organization, what could go wrong, and how serious the consequences would be. It is the foundational requirement of the HIPAA Security Rule's administrative safeguards: every other security control you implement should flow from what the assessment reveals.
In practice, the assessment maps the full lifecycle of ePHI (how it is created, received, maintained, and transmitted), then evaluates the threats and vulnerabilities affecting that data and rates the likelihood and potential impact of each risk. The goal is not a perfect score; it is a documented, defensible understanding of your risks so you can prioritise remediation. The US Department of Health and Human Services (HHS) treats the risk analysis as ongoing rather than a one-time checkbox, and expects it to be revisited whenever your systems, vendors, or operations change materially.
Who needs a HIPAA security risk assessment?
You need a HIPAA security risk assessment if you are a covered entity or a business associate that handles ePHI. The obligation does not stop at the US border; it follows the data.
- Covered entities: US healthcare providers, health plans, and healthcare clearinghouses that handle protected health information electronically.
- Business associates: any vendor that creates, receives, maintains, or transmits ePHI on behalf of a covered entity, including cloud hosting providers, SaaS platforms, analytics firms, billing services, and IT contractors.
- Subcontractors: a business associate's own vendors that touch ePHI inherit the same obligations through the business associate agreement (BAA) chain.
- Non-US organizations: a Canadian software, hosting, or services company serving US hospitals, clinics, or health plans is typically a business associate and is contractually and legally expected to meet the Security Rule, including the risk analysis.
What does a HIPAA security risk assessment cover?
A defensible HIPAA security risk assessment covers far more than antivirus and firewalls. It examines the administrative, physical, and technical safeguards required by the Security Rule and ties each identified risk to a realistic likelihood and impact rating, so remediation can be prioritised by exposure rather than guesswork.
- Scope and data flow: every system, application, device, and third party that creates, receives, stores, or transmits ePHI, including backups, mobile devices, and SaaS tools.
- Threats and vulnerabilities: realistic threat sources (external attackers, insiders, lost devices, vendor failures) paired with the weaknesses they could exploit.
- Existing controls: access controls, encryption at rest and in transit, audit logging, authentication, and physical security already in place.
- Likelihood and impact: a rating of how probable each risk is and how damaging a resulting breach of ePHI would be.
- Administrative safeguards: workforce training, sanction policies, contingency planning, and BAAs with vendors.
- Documentation: a written record of the analysis, decisions, and remediation plan, which HHS expects to be retained and updated over time.
Is a HIPAA security risk assessment the same as a Canadian PIA or TRA?
No, but they are complementary, and the underlying methodology overlaps heavily. A HIPAA security risk assessment is a US legal requirement focused specifically on the security of electronic protected health information. A Canadian Privacy Impact Assessment (PIA) is broader: the federal Office of the Privacy Commissioner describes a PIA as a risk-management process that helps institutions ensure they meet legislative requirements and identify how a program or activity affects individuals' privacy, assessed against privacy principles such as accountability, limiting collection, retention, safeguards, and individual access. A Threat and Risk Assessment (TRA) focuses on security threats and controls and is often paired with a PIA.
If your organization handles both Canadian personal information (under PIPEDA, PHIPA, or Quebec's Law 25) and US ePHI, you may need all three. The good news is that the evidence collected for one (data flow mapping, control inventories, threat analysis) feeds directly into the others, so a well-run programme avoids duplicating effort. Note that most private-sector organizations are not legally bound by the government PIA mandates that apply to federal and provincial public bodies, but the same methodology is widely treated as best practice and is increasingly demanded by healthcare and enterprise buyers.
What does a HIPAA security risk assessment cost and how is it scoped?
Cost varies widely and depends on scope rather than any fixed price, so the honest answer is that it should be quoted after a short scoping conversation. The size of the assessment is driven by how complex your environment is, not by a published rate card.
The main cost and effort drivers are the number of systems and applications that touch ePHI, the number of third-party vendors and subcontractors in scope, the maturity of your existing documentation and controls, whether the work is a one-time analysis or an ongoing managed programme, and whether you also need remediation support afterward. A small SaaS vendor with a single application and a modern cloud stack is a very different exercise from a multi-system hospital integrator. Rather than fixating on price, scope the assessment to your actual ePHI footprint and treat it as a recurring activity, since HHS expects the risk analysis to be reviewed and updated as your systems and risks change. Book a consultation for a tailored quote based on your environment.
Frequently asked questions
Yes. The risk analysis is an explicit requirement of the HIPAA Security Rule's administrative safeguards for every covered entity and business associate that handles ePHI. Failing to perform and document one is among the most frequently cited issues in HHS Office for Civil Rights enforcement actions.
There is no fixed calendar interval in the rule, but HHS treats the risk analysis as ongoing. Most organizations review it at least annually and always after a significant change, such as new systems, new vendors, a merger, or a security incident, to keep it accurate and defensible.
Almost always, yes. A Canadian software, hosting, or services company that creates, receives, stores, or transmits ePHI for US healthcare clients is typically a business associate and is expected, both contractually through the BAA and under the Security Rule, to perform a risk analysis.
The security risk analysis under the Security Rule focuses on safeguarding electronic PHI. HIPAA's separate Privacy Rule governs the use and disclosure of PHI more broadly. A complete compliance programme addresses both, and the data mapping from the security assessment supports privacy work as well.
Beyond increased breach risk, the absence of a current, documented risk analysis is a common finding in enforcement reviews and can lead to penalties and remediation obligations. It also undermines vendor security reviews, since healthcare buyers routinely ask to see evidence that the assessment has been performed.
Keep exploring
All Compliance & regulationsDoes HIPAA apply to my software or business?
HIPAA applies to covered entities and the business associates that handle protected health information (PHI) on their behalf. Find out whether that includes your business.
ReadPrivacy & security assessmentsPIA vs TRA: which assessment do you need (or do you need both)?
PIA vs TRA: a PIA assesses privacy risk to individuals; a TRA assesses security threats to systems. Learn which assessment you need, or whether you need both.
ReadCompliance & regulationsWhat is a cybersecurity risk assessment, and how often should we do one?
A cybersecurity risk assessment identifies threats to your data and systems and how to manage them. Do one at least annually and after any significant change.
ReadCompliance & regulationsWhat is PIPEDA, and does it apply to my business?
What is PIPEDA, and does it apply to my business? A plain-language guide to Canada's federal private-sector privacy law: who it covers, exemptions, and what you must do.
ReadCompliance & regulationsDoes GDPR apply to my business if we're outside Europe?
The GDPR can apply to organizations anywhere if they offer goods or services to, or monitor, people in the EU/EEA. Learn when it reaches your business and what to do.
ReadCompliance & regulationsHow do we prepare for a customer security questionnaire?
Customer security questionnaires (SIG, CAIQ, and custom) gate enterprise deals. Prepare with a control framework, ready evidence, a reusable answer library, and an owner.
Read