HIPAA Risk Analysis
The most-cited gap, closed.The Security Risk Analysis is HIPAA's foundational requirement and OCR's most-cited enforcement finding — and most health-tech startups either don't have one or have a questionnaire PDF that wouldn't survive a desk review. Customers are starting to ask for it by name.
Book a Call- 01
Map the PHI
Every system, vendor, and flow where PHI is created, received, stored, or transmitted — the ePHI inventory that scopes everything downstream.
- 02
Assess threats and controls
Structured threat and vulnerability assessment against the Security Rule's safeguards, scored for likelihood and impact, with current controls evaluated honestly.
- 03
Deliver the analysis and plan
The risk analysis document itself, a prioritized remediation plan with owners and dates, and the risk register entries — the package that answers OCR, auditors, and enterprise customers.
- ePHI inventory and data-flow documentation
- Security Risk Analysis document mapped to the HIPAA Security Rule
- Prioritized remediation plan with owners and timelines
- Risk register integration for ongoing reviews
- Refresh cadence and trigger criteria, documented
3–4 weeks from kickoff to delivered analysis
- Health-tech companies signing their first BAAs
- Business associates whose enterprise customers request the SRA by name
- Teams pairing HIPAA with SOC 2 on one control set
There’s a reason we productized this one document: it’s the highest enforcement-risk gap in health-tech and the most common single ask in enterprise health-care procurement. A risk analysis done properly also does double duty — its PHI inventory and control assessment seed the rest of a HIPAA program, and map directly onto SOC 2 evidence when you run both frameworks together.
Risk Assessments — Run structured risk assessments, maintain a living risk register with owners and treatments, and generate the risk documentation every framework demands.
Is the Security Risk Analysis legally required?
Yes — it's a required implementation specification of the Security Rule, applying to business associates as well as covered entities. It's also the first document OCR requests after a breach report, which is precisely the wrong time to be writing it.
How often does it need refreshing?
'Periodically' per the rule; in practice annually, and on trigger events — new products touching PHI, architecture changes, new material vendors. We document the cadence so the refresh is an update, not a rewrite.
Is this the same as HIPAA compliance?
It's the foundation, not the whole. The full program — safeguards, BAAs, training, breach readiness — is our HIPAA compliance service; the risk analysis is where every credible program starts and the artifact most often requested standalone.