25% off all training courses Offer ends May 8, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 8, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

New HHS Tool Released to Assist with HIPAA Risk Assessments

Conducting a thorough risk assessment is a requirement under the HIPAA Security Rule; however it can be a complex process requiring all potential security risks to be identified. The process can be a daunting task for any organization, especially when the risks of non-compliance are so severe.

Under the Security Rule, HIPAA-covered entities are required to conduct a risk assessment to determine any potential vulnerabilities and take the appropriate actions to reduce and, as far as is possible, eliminate data security risks. Incorporating the necessary safeguards, software systems and data encryption services is essential under HIPAA regulations in order to keep electronic health records private and confidential.

The HHS understands the issues faced by healthcare organizations and has developed a tool to help organizations conduct thorough risk analyses and ensure they are fully HIPAA-compliant. Any organization about to conduct a risk analyses under HIPAA should use the new tool provided by the HHS on its website.

The tool takes the user through a series of questions which need to be answered as part of the risk assessment, with a step by step approach taken to ensure no important areas are overlooked. According to the HHS, the tool will not only help to highlight any security risk that exists, but it will also help organizations gain a better understanding of their IT security systems as a whole.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The new tool is a standalone application which can be run on Windows PCs and laptops, while iPad users can download the tool from the Apple App Store.

The tool asks a series of 156 questions which allows the user to determine any areas which require immediate attention and correction. The tool includes supplemental information to help the user answer the questions accurately and provides assistance to explain the context of the question and the potential impact on PHI records.

The SRA Tool User Guide can be downloaded from the HHS website. For information on the use of the tool visit: http://www.healthit.gov/providers-professionals/security-risk-assessment-tool.

The use of the tool is not a requirement under the HIPAA Security Rule and it is is not a definitive source of information on HIPAA compliance, which should be obtained from the Health Information Privacy section of the HHS Office for Civil Rights website.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist