Annual HIPAA Security Risk Assessment

An Annual HIPAA Security Risk Assessment documents whether a Covered Entity or Business Associate has identified risks to electronic protected health information and maintains reasonable and appropriate administrative, physical, and technical safeguards to manage those risks.

The term annual describes an assessment schedule adopted by the organization. The current HIPAA Security Rule does not prescribe a fixed twelve-month interval for completing a full risk analysis. An annual review supports regular oversight, but the organization must also reassess risks when operational, technical, environmental, or organizational changes affect electronic protected health information.

The assessment should examine how electronic protected health information is created, received, maintained, transmitted, accessed, backed up, recovered, and disposed of. It should also evaluate whether written policies reflect actual practices and whether assigned safeguards operate across the full information environment.

Annual Assessment Scope

The assessment must account for all electronic protected health information held by the organization. Limiting the review to the electronic health record can omit email, billing applications, cloud platforms, file storage, mobile devices, remote access services, medical equipment, backup systems, and vendor-managed environments.

The scope should identify the Covered Entities, Business Associates, facilities, departments, systems, applications, devices, networks, data repositories, and workforce groups included in the review. The assessment record should explain any exclusions.

Systems that do not store electronic protected health information may still require examination when they control or support access to regulated information. Identity platforms, network equipment, security consoles, software management tools, administrative workstations, and remote support applications can provide access routes into systems containing electronic protected health information.

The organization should compare the current scope with the previous assessment. New systems, acquired practices, closed facilities, replaced applications, changed data flows, new Business Associates, and expanded remote work arrangements should be recorded.

Risk Analysis and Risk Management

The risk analysis requirement appears in 45 CFR § 164.308(a)(1)(ii)(A). It requires an accurate and thorough assessment of potential risks and vulnerabilities affecting the confidentiality, integrity, and availability of electronic protected health information.

The annual process should identify where electronic protected health information is located, the threats that could affect it, the weaknesses that could be exploited, the safeguards already in place, and the possible consequences of unauthorized access, alteration, destruction, or loss of availability.

The assessment method should apply documented criteria for determining likelihood and impact. Each finding should identify the affected information, system, threat, vulnerability, current safeguard, risk rating, and supporting evidence.

Risk management is a separate requirement under 45 CFR § 164.308(a)(1)(ii)(B). The organization must implement security measures sufficient to reduce identified risks and vulnerabilities to a reasonable and appropriate level.

The annual assessment should review each unresolved finding from the prior year. The record should state whether the risk was corrected, reduced, transferred, accepted, or remains open. It should identify the responsible person, scheduled completion date, interim measures, and method used to confirm remediation.

A repeated assessment that records the same untreated findings without documented management decisions does not establish an operating risk management process.

Assessment Evidence

The review should use records that demonstrate how the security program operates. Evidence may include policies, procedures, asset inventories, data flow records, network diagrams, system configurations, access reports, training records, incident records, backup reports, restoration test results, vendor contracts, Business Associate Agreements, audit logs, risk registers, and corrective action records.

Interviews can establish how personnel perform assigned tasks, but statements should be compared with written and technical evidence. A verbal description of a safeguard does not establish that the measure has been implemented across all applicable systems.

The assessor should distinguish among documented safeguards, configured safeguards, and safeguards shown to operate. A written password policy, for example, does not prove that system settings enforce the stated requirements.

HIPAA Security Rule Training

The annual assessment should evaluate the security awareness and training program required by 45 CFR § 164.308(a)(5). The program must apply to all workforce members, including management.

The assessment should establish whether employees, executives, volunteers, trainees, contractors under the organization’s direct control, and other workforce members received instruction suited to their access and assigned responsibilities.

Training content should reflect the organization’s systems, policies, risk analysis, and incident history. Personnel who use electronic protected health information should understand approved access methods, secure transmission procedures, authentication requirements, remote work controls, device handling rules, and incident reporting procedures.

The HIPAA Security Rule identifies security reminders, protection from malicious software, log-in monitoring, and password management as addressable implementation specifications. The organization must assess each specification and implement it when reasonable and appropriate. When an alternative measure is selected, the decision and supporting reasoning should be documented.

The annual review should examine whether security reminders were provided periodically and whether their content addressed identified threats. Training may address phishing, malicious links, unexpected authentication requests, lost devices, credential theft, ransomware indicators, unauthorized software, improper disclosures, and unusual account activity.

Password and authentication instruction should explain the organization’s procedures for creating, storing, resetting, and protecting credentials. Workforce members should understand that passwords, authentication tokens, access cards, and multifactor authentication approvals cannot be shared.

Malicious software instruction should explain how to recognize and report suspicious files, messages, alerts, and system behavior. Personnel should know which actions they are authorized to take and when they must stop using a device or disconnect it from a network.

Log-in monitoring instruction should address unexpected access alerts, failed log-in notices, account lockouts, and evidence that another person may be using a workforce member’s credentials.

The current HIPAA Security Rule does not specify annual training by name. An organization may use annual training as part of its program, but additional instruction should be provided when changes to systems, policies, risks, or job responsibilities create a training need.

Training records should identify the content, date, delivery method, participants, completion status, and follow-up actions. The annual assessment should verify that records cover the full workforce and that course content matches current security procedures.

Incident Response Plan

Plan Development and Annual Review

The annual assessment should determine whether the organization has implemented procedures for identifying, responding to, mitigating, and documenting suspected or known security incidents. These duties arise under 45 CFR § 164.308(a)(6).

The HIPAA Security Rule does not require a document with the title Incident Response Plan. A written plan provides a method for assigning responsibilities and coordinating response activities.

The plan should define how personnel report events, who evaluates reports, who authorizes containment measures, how evidence is preserved, and how the organization returns affected systems to operation. It should also establish communication procedures for management, privacy personnel, legal counsel, insurers, vendors, law enforcement, and government agencies when their involvement applies.

The annual assessment should verify that contact details, escalation paths, response tools, and copies of the plan remain available when normal systems cannot be accessed. A response plan stored only on an encrypted or unavailable network may not support operations during an attack.

Incident categories should reflect the organization’s environment. The plan may address ransomware, malware, compromised credentials, unauthorized access, improper disclosures, lost equipment, malicious workforce activity, vendor incidents, data alteration, service interruption, and attacks affecting cloud platforms.

Incident Response Roles

The organization may assign incident response duties to a formal Incident Response Team or distribute them among existing functions. The HIPAA Security Rule does not prescribe a team structure.

The assessment should confirm that information technology, information security, privacy, compliance, legal, clinical operations, communications, facilities, human resources, and management functions understand their assigned duties when those functions form part of the response process.

Role assignments should refer to positions or functions rather than relying only on named employees. Alternate personnel should be designated for duties that cannot be delayed when the primary assignee is unavailable.

The assessment should compare written responsibilities with prior incidents and exercises. Delayed decisions, unclear authority, duplicate work, missing communications, and unassigned tasks should result in plan revisions.

Workforce Sanctions

The annual assessment should review the sanction process required by 45 CFR § 164.308(a)(1)(ii)(C). Appropriate sanctions must be applied against workforce members who fail to comply with security policies and procedures.

The sanction process is not limited to a workforce member who causes a reportable breach. It can apply to credential sharing, unauthorized record access, failure to follow device security procedures, installation of prohibited software, failure to report an incident, or other noncompliance with documented safeguards.

Incident procedures should direct suspected workforce violations to the designated review process. The organization should document the facts considered, applicable policy, determination, action taken, and related corrective measures.

The annual assessment should examine whether sanctions are applied consistently across workforce levels. Comparable conduct should receive comparable review under the organization’s policies.

Post-Incident Risk Review

Each material incident should be examined for information that changes the organization’s risk analysis or risk management plan. An incident may reveal an omitted system, an unknown data flow, an ineffective control, incomplete training, or an inaccurate assumption about recovery capabilities.

The HIPAA Security Rule does not require a complete enterprise assessment after every event. The organization should update the relevant parts of its risk records when incident findings change the identified risks or the measures needed to manage them.

The annual review should confirm that prior incident findings produced assigned corrective actions. It should also test whether revised policies, configurations, training, or response procedures operate as intended.

HIPAA Breach Notification Rule Review

The incident process should include procedures for determining whether an event is a reportable breach under the HIPAA Breach Notification Rule.

A security incident does not automatically create a notification duty. The organization must determine whether there was an impermissible acquisition, access, use, or disclosure of protected health information and whether the information was unsecured.

When no regulatory exception applies, the organization must presume that a breach occurred unless a documented assessment demonstrates a low probability that the protected health information was compromised. The assessment factors appear in 45 CFR § 164.402.

Individual notification must be provided without unreasonable delay and no later than 60 calendar days after discovery under 45 CFR § 164.404.

A breach affecting 500 or more individuals must be reported to HHS within the applicable notification period. Breaches affecting fewer than 500 individuals may be reported within 60 days after the end of the calendar year in which they were discovered. The HHS reporting duties appear in 45 CFR § 164.408.

Media notice is required when a breach affects more than 500 residents of one state or jurisdiction. The notice must be issued to prominent media outlets serving that area under 45 CFR § 164.406.

A Business Associate must notify the affected Covered Entity without unreasonable delay and no later than 60 calendar days after discovery. Business Associate notification duties appear in 45 CFR § 164.410.

The annual assessment should review prior breach determinations, risk assessments, notification records, mailing procedures, HHS submissions, media notices, and Business Associate communications. It should verify that the organization can identify when the notification period begins and who has authority to approve the determination.

Technical and Evidence Safeguards

Audit Controls

The annual assessment should examine the audit controls required by 45 CFR § 164.312(b). Regulated entities must implement mechanisms that record and examine activity in information systems containing or using electronic protected health information.

The review should identify which systems generate audit records and which events are recorded. Relevant activity may include successful and failed log-ins, access to patient information, changes to user permissions, privileged commands, record exports, configuration changes, account creation, account deletion, remote access events, and security alerts.

Audit coverage should extend beyond the electronic health record. Email platforms, billing applications, cloud storage, file servers, identity systems, remote access services, administrative tools, and connected devices may require logging when they create, receive, maintain, or transmit electronic protected health information.

Information System Activity Review

The annual assessment should also examine the information system activity review procedures required by 45 CFR § 164.308(a)(1)(ii)(D).

Generating audit records does not establish that the records are reviewed. The organization should identify who performs reviews, the systems examined, the review frequency, the events that require investigation, and the records retained to demonstrate that the review occurred.

Automated alerts can support the process. The assessment should confirm who receives each alert, how alerts are evaluated, how false positives are recorded, and when suspicious activity enters the incident response process.

Audit Record Protection

Audit records should be protected from unauthorized access, alteration, deletion, and premature disposal. The annual review should examine access permissions, administrative privileges, storage architecture, time synchronization, retention settings, and procedures for retrieving records during an investigation.

Centralized logging, segregated storage, write-protected repositories, and security information and event management platforms can support audit record protection. The current HIPAA Security Rule does not expressly require any one of these technologies.

The assessment should determine whether the selected controls are reasonable and appropriate for the organization’s risks. It should also test whether records remain complete and usable after the period needed to identify and investigate suspicious activity.

The six-year documentation requirement under the HIPAA Security Rule does not create a blanket six-year retention period for every technical log. Log retention periods should reflect the risk analysis, operational requirements, investigation needs, contracts, and other applicable legal duties.

External Incident Response Support

The annual review should determine whether internal personnel can perform the technical, legal, privacy, communication, and recovery tasks assigned by the incident plan.

Organizations may arrange advance access to forensic investigators, breach counsel, system restoration firms, notification vendors, communications specialists, and other outside providers. Advance agreements can define response times, rates, evidence handling, confidentiality, and contact procedures.

The current HIPAA Security Rule does not require an active retainer or pre-negotiated agreement. These arrangements are risk management measures selected by the organization.

The assessment should determine whether an outside provider will create, receive, maintain, or transmit protected health information. A Business Associate Agreement may be required before the provider receives access.

Cyber insurance notice requirements and approved provider conditions should also be reviewed. Failure to follow the insurer’s stated process can affect access to services or coverage decisions.

Business Continuity and Disaster Recovery

Contingency Plan

The annual assessment should review the contingency plan required by 45 CFR § 164.308(a)(7).

The plan should address emergencies or other events that damage systems containing electronic protected health information. Events may include fire, water damage, power failure, hardware failure, ransomware, destructive malware, cloud service interruption, facility loss, or failure of a vendor service.

The review should examine activation authority, workforce assignments, alternate communication methods, vendor contacts, recovery resources, manual procedures, and conditions for returning to normal operations.

Data Backup Plan

The HIPAA Security Rule requires procedures for creating and maintaining retrievable exact copies of electronic protected health information.

The annual assessment should identify which systems and data are backed up, how frequently backups occur, where copies are stored, how copies are protected, and who can access them. It should examine failed backup reports and verify that failures produced investigation and corrective action.

Backup records should include information held outside the main electronic health record. Cloud applications, local file storage, departmental systems, mobile devices, medical equipment, email, and vendor platforms can contain electronic protected health information that is absent from the primary backup process.

A successful backup status does not demonstrate that data can be restored. The annual assessment should examine restoration test results and confirm that recovered information is accurate, accessible, and usable.

Disaster Recovery Plan

The disaster recovery plan must establish procedures for restoring lost electronic protected health information.

The assessment should examine recovery instructions, system dependencies, hardware requirements, software sources, encryption keys, network settings, administrative credentials, vendor support, and alternate hosting arrangements.

Recovery procedures should account for the order in which systems must return to service. A clinical application may depend on identity services, databases, storage, network connectivity, interfaces, and security tools.

The annual review should compare written recovery objectives with demonstrated restoration performance. Recovery targets should reflect available personnel, equipment, data copies, and technical dependencies.

Emergency Mode Operation Plan

The emergency mode operation plan must establish procedures for continuing business processes needed to protect electronic protected health information while operating during an emergency.

The assessment should examine how authorized personnel obtain patient information, create records, communicate securely, process orders, manage medications, protect temporary records, and reconcile information after systems return to service.

Paper downtime workflows may support clinical operations during an electronic health record outage. Procedures should address access, storage, tracking, transport, disposal, and later entry of information into the electronic record.

The HIPAA Security Rule does not expressly require paper downtime procedures or network shutdown thresholds. The organization may adopt these measures when they support continued operations and protection of electronic protected health information.

Applications and Data Criticality Analysis

The assessment of applications and data criticality is an addressable implementation specification under 45 CFR § 164.308(a)(7)(ii)(E).

The organization must assess whether the specification is reasonable and appropriate. When it does not implement the specification as written, it should document the decision and apply an equivalent measure when reasonable and appropriate.

The annual assessment should review the inventory of applications, data repositories, infrastructure, interfaces, and external services used in recovery. The record should identify restoration priorities, system dependencies, acceptable outage periods, acceptable data loss, required personnel, and vendor support.

Recovery priority should account for the services needed to operate each application. A network service or identity platform that stores little electronic protected health information may require restoration before a clinical system can function.

Emergency Access Procedures

45 CFR § 164.312(a)(2)(ii) requires procedures for obtaining necessary electronic protected health information during an emergency.

The annual assessment should verify that authorized clinical and operational personnel can obtain required information when ordinary authentication services, applications, facilities, or network connections are unavailable.

Clinical break-glass functions and emergency administrator accounts serve different purposes. A clinical access function can permit authorized access to restricted patient information. An administrator account can permit technical personnel to restore infrastructure when the primary identity service is unavailable.

The review should examine who can authorize emergency access, how credentials are stored, how their use is recorded, and how activity is reviewed after the event. It should also test whether emergency credentials remain available when the normal password vault or identity platform cannot be reached.

Testing and Validation

Contingency Plan Testing

Testing and revision procedures are an addressable implementation specification under 45 CFR § 164.308(a)(7)(ii)(D).

The annual assessment should determine whether the organization evaluated the specification and documented its implementation decision. Testing may include discussion exercises, backup restorations, communication tests, application recovery tests, facility exercises, and controlled incident simulations.

Reviewing a written plan without performing assigned tasks does not establish that personnel can use the plan or that systems can be recovered.

Tabletop Exercises

A tabletop exercise can test management decisions, technical response, privacy analysis, legal review, clinical continuity, workforce communication, vendor coordination, insurance notice, evidence preservation, and breach notification procedures.

The HIPAA Security Rule does not require tabletop exercises by name. An organization may use them as one method of testing its incident response and contingency processes.

The scenario should reflect risks identified in the organization’s environment. Suitable scenarios may include ransomware, identity system failure, a compromised cloud provider, malicious workforce access, loss of the electronic health record, or failure of a Business Associate service.

The exercise record should identify participants, decisions, actions, communication failures, unavailable resources, policy conflicts, and corrective actions.

Technical Restoration Testing

Technical testing should confirm that personnel can retrieve backups, rebuild systems, restore settings, reconnect interfaces, validate data integrity, and return services to operation.

The test record should state the systems involved, data restored, time required, failures encountered, dependencies discovered, manual work needed, and differences between written procedures and actual recovery steps.

Restoration testing should also confirm that access controls, logging, authentication, encryption, and security monitoring operate after recovery. Restoring data without restoring its safeguards leaves the recovery process incomplete.

Corrective Action Validation

Exercise and test findings should produce assigned corrective actions. Each action should identify an owner, completion date, interim safeguard, and validation method.

The annual assessment should confirm that prior findings were tested after remediation. A written statement that an action was completed does not establish that the revised safeguard operates correctly.

Annual Assessment Documentation

The completed assessment should identify the scope, assessment period, methodology, participants, evidence reviewed, interviews conducted, findings, exclusions, assumptions, and limitations.

Each finding should state the condition observed, affected information or system, associated risk, applicable HIPAA Security Rule provision, selected corrective action, responsible owner, and target date.

The report should distinguish regulatory requirements from security practices selected through risk management. A recommendation for centralized logging or an external incident response retainer should not be described as an express HIPAA Security Rule requirement.

The report should identify addressable implementation specifications and record whether each was implemented, replaced by an equivalent measure, or not implemented after a documented assessment.

45 CFR § 164.316 requires regulated entities to maintain written policies, procedures, actions, activities, and assessments required by the HIPAA Security Rule. Required documentation must be retained for six years from its creation date or the date when it last remained in effect, whichever is later.

The organization should provide the assessment and related procedures to personnel responsible for implementing them. Documentation should be reviewed and updated when operational or environmental changes affect the security of electronic protected health information.

Annual Review and Event-Driven Reassessment

An annual schedule provides a recurring point for management to review risks, safeguards, incidents, training, contingency planning, testing, vendor arrangements, and corrective actions.

The annual process does not replace event-driven reassessment. A new electronic health record, cloud migration, business acquisition, facility relocation, network redesign, material software change, new Business Associate relationship, security incident, or newly discovered data repository can require review before the next annual assessment date.

The scope of the additional review should match the change. A focused technical change may support a limited reassessment. A merger or replacement of the information environment may require a wider examination of systems, data flows, policies, access controls, training, and recovery procedures.

Current and Proposed Requirements

The HIPAA Security Rule currently in effect governs present compliance obligations. Covered Entities and Business Associates should base assessment findings on the current text of 45 CFR Part 164, Subpart C.

HHS proposed amendments to the HIPAA Security Rule in January 2025. The proposal includes more prescriptive provisions for written risk analyses, asset inventories, network maps, testing, incident response, contingency planning, training, and technical safeguards.

Proposed provisions do not create current compliance duties. An assessment may include a separate readiness review, but the report should distinguish existing requirements from measures that would apply only after publication of a final rule and completion of the applicable compliance period.