HHS Releases HIPAA Security Risk Assessment Tool
Healthcare Alert | 2 min read
Apr 14, 2014
Recognizing the challenges facing providers in conducting risk assessment under HIPAA, the federal Department of Health and Human Services has released a security risk assessment tool (the "SRA") to help providers with HIPAA compliance.
The SRA is the result of a collaborative effort by the HHS Office of the National Coordinator for Health Information Technology and Office for Civil Rights, and is particularly designed for providers in small- to medium-sized offices to help them conduct and document a security risk assessment under HIPAA in a thorough, organized fashion. The tool, which is available as an application for Windows and for iOS iPads, also produces a report that can be provided to auditors.
Under HIPAA, covered entities and business associates must conduct regular risk assessments of the administrative, physical and technical safeguards they have in place to protect the security of protected health information. Risk assessments can help providers uncover potential weaknesses in their security policies, processes and systems and hopefully anticipate and prevent health data breaches and other adverse security events. Risk assessment is a key requirement of the HIPAA Security Rule and a core requirement for providers seeking payment through the Medicare and Medicaid EHR Incentive Program, also known as the Meaningful Use Program. If you are a provider, in order to comply with HIPAA, it is essential that you conduct risk assessments and document your results. Once you have identified gaps and vulnerabilities, you should take whatever steps are required to address the gaps and vulnerabilities identified, and document what you have done to address those issues. As software and hardware are added and new issues identified, you should also conduct a similar process. The risk assessment is not a one-time action, but is an ongoing process that should become part of your operations.
The security risk assessment tool's website contains a User Guide and Tutorial video to help you begin using the risk assessment tool. The website also includes videos on risk analysis and contingency planning.
The HIPAA risk assessment process can be daunting. To assist you in conducting the risk assessment and advise you on compliance with HIPAA, it is important to assemble a team of IT experts and experienced legal counsel. Hinshaw attorneys are ready and willing to assist you.
Should you have questions or need further information, please contact Michael Dowell in our Los Angeles office or your regular Hinshaw attorney.
This alert has been prepared by Hinshaw & Culbertson LLP to provide information on recent legal developments of interest to our readers. It is not intended to provide legal advice for a specific situation or to create an attorney-client relationship.
Related People
Related Capabilities
Featured Insights

Event
Apr 23, 2026
Driving Ahead: Insights from Industry Leaders Auto Finance Seminar

Consumer Crossroads: Where Financial Services and Litigation Intersect
Mar 13, 2026
DOJ Settlement with Car Retailer Highlights SCRA Repossession Risks

Privacy, Cyber & AI Decoded Alert
Mar 11, 2026
Compliance Considerations for GDPR Consent in Biotech Clinical Research

Press Release
Mar 4, 2026
Marcia Mueller Named the 2026 Mentorship Award Winner by YWCA Northwestern Illinois

Press Release
Mar 3, 2026
Hinshaw Announces New Administrative Leadership Appointments

In The News
Feb 27, 2026
Hinshaw Partners Examine Implications for Nursing Homes of New Illinois Aid-in-Dying Law

In The News
Feb 24, 2026
Lucy Wang Authors Law360 “Expert Analysis” on Why Attorney Civility Means More in 2026

Press Release
Feb 13, 2026
Hinshaw Team Wins Appeal in Criminal Indictment of Waukegan City Clerk Janet Kilkelly

Press Release
Feb 10, 2026
Hinshaw Trial Team Secures $0 Defense Verdict in $15 Million Auto Accident Trial

Press Release
Feb 5, 2026
Hinshaw Legal Team Secures Directed Verdict in Florida Equine Fraud Case

Press Release
Feb 4, 2026
Hinshaw Celebrates 17 Consecutive Years of Being Named an Equality 100 Award Winner

![[Video] New Regulatory Priorities Under Mayor Mamdani’s NYC Department of Consumer and Worker Protection](/a/web/oHiTWa7kRy3Ht1brq6k4BT/bkMx39/new-york-city-skyline.jpg)
