Service

HIPAA Risk Analysis

The most-cited gap, closed.

The Security Risk Analysis is HIPAA's foundational requirement and OCR's most-cited enforcement finding — and most health-tech startups either don't have one or have a questionnaire PDF that wouldn't survive a desk review. Customers are starting to ask for it by name.

Book a Call
How We Work
  1. 01

    Map the PHI

    Every system, vendor, and flow where PHI is created, received, stored, or transmitted — the ePHI inventory that scopes everything downstream.

  2. 02

    Assess threats and controls

    Structured threat and vulnerability assessment against the Security Rule's safeguards, scored for likelihood and impact, with current controls evaluated honestly.

  3. 03

    Deliver the analysis and plan

    The risk analysis document itself, a prioritized remediation plan with owners and dates, and the risk register entries — the package that answers OCR, auditors, and enterprise customers.

Deliverables
  • ePHI inventory and data-flow documentation
  • Security Risk Analysis document mapped to the HIPAA Security Rule
  • Prioritized remediation plan with owners and timelines
  • Risk register integration for ongoing reviews
  • Refresh cadence and trigger criteria, documented

3–4 weeks from kickoff to delivered analysis

Who It's For
  • Health-tech companies signing their first BAAs
  • Business associates whose enterprise customers request the SRA by name
  • Teams pairing HIPAA with SOC 2 on one control set
Encoded by YOU

There’s a reason we productized this one document: it’s the highest enforcement-risk gap in health-tech and the most common single ask in enterprise health-care procurement. A risk analysis done properly also does double duty — its PHI inventory and control assessment seed the rest of a HIPAA program, and map directly onto SOC 2 evidence when you run both frameworks together.

Powered by the Platform

Risk Assessments — Run structured risk assessments, maintain a living risk register with owners and treatments, and generate the risk documentation every framework demands.

Frequently Asked
Is the Security Risk Analysis legally required?

Yes — it's a required implementation specification of the Security Rule, applying to business associates as well as covered entities. It's also the first document OCR requests after a breach report, which is precisely the wrong time to be writing it.

How often does it need refreshing?

'Periodically' per the rule; in practice annually, and on trigger events — new products touching PHI, architecture changes, new material vendors. We document the cadence so the refresh is an update, not a rewrite.

Is this the same as HIPAA compliance?

It's the foundation, not the whole. The full program — safeguards, BAAs, training, breach readiness — is our HIPAA compliance service; the risk analysis is where every credible program starts and the artifact most often requested standalone.