
HIPAA Security Risk Analysis · Polk County & the I-4 corridor
The Security Risk Analysis is not optional. The rule uses that word.
Most HIPAA requirements are written as things you should address. This one is marked Required. I perform the analysis, fix what it finds, write it down, and sign a Business Associate Agreement, so your HIPAA posture is documented evidence instead of a verbal assurance.
What the rule says
Two required specifications, not one
The HIPAA Security Rule marks each implementation specification either required or addressable. At 45 CFR 164.308(a)(1)(ii)(A) the risk analysis is marked Required, and it reads: conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate.
The specification immediately after it is also Required, and it is the one people forget. 164.308(a)(1)(ii)(B), risk management, is to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. An analysis that finds problems and changes nothing satisfies the first half and fails the second.
That pairing is the whole reason this page exists. Plenty of people will sell you the document. The obligation is to do something about what the document says.
A risk analysis in a drawer is not evidence. A dated record of what you found, what you fixed, and when, is.
If you report MIPS, this is the same requirement
The measure that zeroes a whole category
The MIPS Promoting Interoperability Security Risk Analysis measure asks you to attest that you conducted or reviewed a security risk analysis and acted on what it found. It points at the same regulation, 45 CFR 164.308(a)(1).
CMS is unusually blunt about the consequence: failing to do what the measure requires scores the entire Promoting Interoperability category at zero, no matter how well every other measure in it went. One unticked box takes the category down with it.
What you get
The analysis, the fixes, and the paper trail
- An accurate and thorough assessment of where your electronic patient information actually lives, including the places nobody meant to put it
- The risks and vulnerabilities against each of confidentiality, integrity, and availability, which is what the rule names
- The gaps fixed, not just listed, because risk management is a second required specification
- A written record in plain English, dated, that you can hand to an auditor, an insurer, or a patient's attorney
- A signed Business Associate Agreement, offered up front
- A review when the practice changes, so the document keeps describing the network you actually run
The day-to-day IT underneath all of this, the workstations, the network, the backups and the machines your practice software runs on, is on the medical and dental page. If your practice also prepares tax documents or you run a separate business that does, the equivalent obligation there is the IRS written information security plan.
Straight answers
What practices actually ask
Is the Security Risk Analysis actually required, or is it optional?
Required, and the rule says so in that word. At 45 CFR 164.308(a)(1)(ii)(A) the implementation specification is labelled Risk analysis (Required), and it reads: conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate. Some HIPAA specifications are labelled addressable. This one is not.
We bought compliance software. Is that the analysis?
Not by itself. Software can organise the work and hold the record, and the free Security Risk Assessment Tool from ONC and OCR does the same job at no cost. What none of them do is look at your actual network, your actual backups, and the actual way your front desk works. The analysis is the looking. The tool is where you write down what you found.
Is this a one-time project?
No. The rule pairs the analysis with a second required specification, Risk management at 164.308(a)(1)(ii)(B), which is to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. An analysis that finds problems and changes nothing satisfies the first half and fails the second. It also needs revisiting when the practice changes, because a document describing a network you no longer run is not evidence of anything.
Our EHR vendor says they are HIPAA compliant. Does that cover us?
It covers their software, not your office. The obligation at 164.308 sits with the covered entity, and the analysis has to cover all the electronic protected health information you create, receive, maintain and transmit. That includes the workstations, the network, the backups, the email, and the machines your practice software happens to run on.
Does this have anything to do with our MIPS attestation?
It is the same requirement under a different name. The MIPS Promoting Interoperability Security Risk Analysis measure requires you to attest that you conducted or reviewed a security risk analysis and acted on what it found, and CMS states that failing it scores the entire Promoting Interoperability category at zero regardless of how the other measures went. The measure points at 45 CFR 164.308(a)(1).
Will you sign a Business Associate Agreement?
Yes, and I offer it up front rather than waiting to be asked. An IT provider that can reach your electronic protected health information is a business associate, and 164.308(b) requires you to obtain satisfactory assurances before that happens. Note what that means for me as well as for you: the same Security Rule that applies to your practice applies to mine.
Do you make our practice HIPAA compliant?
No, and anyone who tells you otherwise is selling something. Compliance includes how your team works every day, which no outside company controls. What I do is perform the analysis, fix what it finds, write it down, and keep the record current, so that your HIPAA posture is documented evidence instead of a verbal assurance.

Start with a look at where you actually stand.
The assessment is a relaxed conversation about how the practice really runs, and you get a plain-English picture either way. No obligation, no jargon, no scare statistics.
Sources: 45 CFR 164.308(a)(1)(ii)(A) and (B) and 164.308(b), and the CMS MIPS Promoting Interoperability Security Risk Analysis measure specification.