The HIPAA risk assessment is the single most important, and most-cited, part of compliance. Here is what it is, how to run one properly, and how to keep it alive.
TL;DR
A HIPAA risk assessment, often called a risk analysis, is a documented evaluation of the threats to your electronic protected health information. It is an explicit HIPAA requirement and the deficiency regulators flag most often in enforcement.
Run it in five steps: inventory where ePHI lives, identify threats, assess likelihood and impact, prioritise, and document. Then keep it current. Everything else in your compliance program depends on getting this right first.
On this page
Why the HIPAA risk assessment matters most
Of everything HIPAA asks for, one requirement sits above the rest: the risk assessment. It is not just another box to tick. It is the foundation that tells you which safeguards you actually need, and it is the failing that appears again and again in enforcement actions. Get it right and the rest of your program has direction. Skip it, and you are securing your systems by guesswork.
What a HIPAA risk assessment actually is
A HIPAA risk assessment is a structured evaluation of the risks to the confidentiality, integrity, and availability of your electronic protected health information. In plain terms: you work out where your health data is, what could go wrong with it, how likely and serious each of those things is, and what you will do about it. The output is a prioritised, documented view of your risks, kept current as your systems change.
The five steps to run one
A defensible risk assessment follows a clear sequence. Each step produces what the next one needs.
Start by inventorying every place ePHI is created, stored, or transmitted. Identify the threats and vulnerabilities to each. Assess how likely each risk is and how much harm it would cause. Prioritise by that rating. Then document the whole thing, and the decisions you made, so it can be maintained and shown.
How to rate each risk
Rating does not need to be complicated. A simple two-factor model, how likely a risk is and how much impact it would have, gives you a consistent, defensible way to rank what to fix first.
Risks in the high-likelihood, high-impact corner are addressed first; low-likelihood, low-impact risks can wait or be accepted with documented reasoning. The point is not precision, it is a repeatable ranking you can justify to an auditor.
Common risk assessment mistakes
- Treating it as a one-page form. A checklist is not an assessment. Regulators expect a genuine, thorough evaluation.
- Doing it once. A risk assessment must be kept current as systems, vendors, and threats change.
- Missing where ePHI lives. An incomplete inventory means an incomplete assessment. Backups, logs, and third parties count.
- Not acting on it. An assessment that does not drive remediation is just documentation.
The lean-team path to a living risk assessment
The hardest part of a risk assessment is not the first pass, it is keeping it accurate as your environment changes, and being able to show the controls that address each risk actually operate. Doing that across scattered tools is where the assessment goes stale and the gaps reopen.
Keep your risk assessment alive, not on a shelf.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Tie each risk to controls that run on one platform and evidence themselves, so your assessment stays current. No security team required.
Frequently asked questions
What is a HIPAA risk assessment?
A documented evaluation of the risks to the confidentiality, integrity, and availability of your electronic protected health information. You identify where ePHI lives, what could go wrong, how likely and serious each risk is, and how you will address it, then keep it current.
Is a risk assessment required by HIPAA?
Yes. The Security Rule explicitly requires an accurate and thorough assessment of potential risks to ePHI. It is also the deficiency regulators cite most often, which makes it the first thing to get right.
What is the difference between a risk assessment and a risk analysis?
In practice, none. The terms are used interchangeably for the same anchor requirement: a thorough, documented evaluation of risks to ePHI that drives your safeguards.
How often should a HIPAA risk assessment be done?
At least annually, and whenever your systems, vendors, or threats change materially. It is meant to be a living document, not a one-time exercise, because an outdated assessment misses new risks.
What are the steps in a HIPAA risk assessment?
Inventory where ePHI lives, identify threats and vulnerabilities, assess likelihood and impact, prioritise the risks, and document everything, then maintain it. Each step feeds the next, ending in a ranked list of what to fix.
What is the most common risk assessment mistake?
Treating it as a one-page form or doing it only once. Regulators expect a genuine, thorough, and current assessment that actually drives remediation, not a filed checklist.

