Contact Us

ARTICLE + CHECKLIST · 6-MINUTE READ

The HIPAA Security Risk Assessment most practices get wrong.

Nearly every practice believes they've "done their SRA." Most have a template, a checkbox, or a one-time PDF from years ago. Here's what the rule actually requires - and how to tell if yours would hold up.

START HERE

What the SRA actually is

The HIPAA Security Rule requires every covered practice to conduct an accurate and thorough assessment of the risks to the confidentiality, integrity, and availability of the protected health information (PHI) it holds. It's also tied to Medicare - if you attest to MIPS, you're attesting this was done.

Two words do all the work: accurate and thorough. A generic template filled in once meets neither. And it isn't a document you file and forget - it's a process you keep current as your environment changes. That gap, between "we have an SRA" and "we have an accurate, current, thorough one," is where most practices quietly sit. In 2025, that gap is exactly what OCR's multimillion-dollar penalties have centered on.

THE 5 MISTAKES

Where "we did our SRA" falls apart

1

Treating it as one-and-done

An SRA from three years ago doesn't describe the practice you run today. New staff, apps, and devices moved the risk picture - the document didn't.

2

A template instead of a review

A downloaded checklist filled from memory isn't "accurate and thorough." It documents what you assumed, not what's on your network.

?
3

Missing the shadow systems

The cloud tools and AI note-takers staff signed up for - often with no Business Associate Agreement - never make it into the analysis.

AI
4

Analysis with no remediation

Finding risks and doing nothing is arguably worse than not looking. The rule expects you to act on what you find - and document it.

5

Confusing it with a list of products

"We have antivirus and a firewall" isn't a risk analysis. And the security you're billed for isn't always what's actually running.

The throughline

Every one of these comes from never actually looking at the real environment. You can't assess risk you haven't seen.

What "didn't look" looks like

"One practice had attested to their SRA every single year. When we finally inspected the environment, a former IT vendor still had active admin access more than a year after leaving - and the endpoint security they were paying for wasn't installed on a third of their machines. None of it was in the SRA. Nobody had ever actually looked."

Portrait of Dmitry Rudman, CTO and Co-Founder of SafePoint IT

Dmitry RudmanCTO & Co-Founder, SafePoint IT

THE GUT CHECK

Would yours hold up?

Answer each one honestly. Anything you mark No or Not sure is a gap - we'll total them up at the bottom.

It was updated within the last year and reflects your current systems.

It covers every system, app, and device that touches PHI - including cloud and AI tools.

Every vendor touching PHI is under a signed Business Associate Agreement.

It produced a remediation plan, and you can show what you fixed.

Someone actually inspected the environment - it isn't a template.

WHAT TO DO ABOUT IT

How to close the gaps for good

The good news: every one of these gaps is fixable, and none of it asks you to become an IT expert. Here is the path from "we think we're covered" to "we can prove it."

1

Start by actually looking

Before anything else, have someone inspect every system, app, and device that touches PHI - your network, your endpoints, the cloud tools, and the AI apps staff signed up for on their own. A real inventory of what you actually have is the foundation an accurate, thorough SRA is built on. You cannot fix risk you have not seen.

2

Get every PHI vendor under a BAA

List every vendor and tool that touches patient data, and confirm each one is covered by a signed Business Associate Agreement. Where there is no agreement, put one in place or stop using the tool. This single step closes one of the most common - and most penalized - HIPAA gaps.

3

Turn findings into a written remediation plan

For every risk you uncover, write down the fix, who owns it, and the date it is due. This is the part OCR looks for: evidence that you acted on what you found, not just a list of problems. Finding risks without a plan is treated as worse than never having looked.

4

Fix the highest-risk gaps first

Revoke old admin and former-vendor access, confirm your endpoint security is truly installed and running on every machine, and patch what is exposed. Work in order of impact, so the biggest risks are gone first, not last.

5

Keep it current, and keep the proof

Refresh the assessment whenever staff, apps, or devices change - and at least once a year - so it always reflects the practice you run today. Store the assessment, the plan, and a record of what you fixed, so you can show your work at a renewal, an audit, or a MIPS attestation.

An operations manager reviewing a healthcare IT assessment checklist with two SafePoint IT technicians

THE BIGGER PICTURE

Your SRA is one piece of a much bigger story

A HIPAA Security Risk Assessment is really a window into your whole IT infrastructure - your network, endpoints, vendors, backups, and the everyday tools your team relies on. A SafePoint IT Healthcare IT & Infrastructure Assessment checks all of it, HIPAA included, and hands you a plain-English picture of exactly where your practice stands.

If everything checks out, you'll have the proof in hand. If it doesn't - give us a week, and we'll build the plan to fix it.

Assess your practice →

This article is general education, not legal or compliance advice. Consult a qualified professional for your practice's specific obligations under HIPAA.

chevron-down linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram