The HIPAA security risk assessment, explained for small practices
Every practice that handles electronic patient information must complete a security risk analysis. Most small practices have never done one, and a missing or incomplete risk analysis is one of the findings HHS cites most often in enforcement actions.
Free preview before you pay. Editable Word files. 14 day refund.
What the risk analysis must cover
- Every place electronic patient information lives or travels: EHR, email, workstations, laptops, phones, backups, the network, printers and fax, portals, and telehealth platforms
- The threats and weaknesses for each, such as phishing, ransomware, lost devices, weak passwords, unpatched systems, and former staff who still have access
- How likely each risk is and how much harm it would cause
- What you will do about each medium or high risk, who owns it, and by when
- A record of the analysis, kept for six years and repeated at least once a year or after a big change
Why small practices get this wrong
The analysis is not a one time IT scan and it is not a vendor certificate. It is a written record, in your own words, of your own systems. A generic template with blank rows is where most practices stop. The worksheet in the kit starts from your answers, listing your EHR, portal, telehealth, and messaging tools as assets, and pre filling the common risks so you rate them rather than invent them.
Glendale area practices
Practices in Glendale, Burbank, and Pasadena can also ask for a free review of how the office handles patient data, with a written gap summary. Request a free review.
Questions
Is a risk assessment required for small practices?
Yes. The HIPAA Security Rule requires every covered entity to conduct an accurate and thorough risk analysis, regardless of size.
Can I use the free HHS tool instead?
The HHS Security Risk Assessment Tool is a good companion. The kit's worksheet works alongside it, and the kit adds the written policies the analysis refers to.
Full HIPAA Policy Kit, $129
- Notice of Privacy Practices, updated for the 2026 rules, plus the acknowledgment form
- 22 Privacy policies and procedures
- 19 Security policies mapped to the Security Rule
- Breach Notification policy with a risk assessment form and log
- Business Associate Agreement for your vendors
- Workforce confidentiality agreement, training log, and access checklist
- Security Risk Analysis worksheet, pre filled from your answers
- Patient request forms, plus a California addendum for California practices
More guides
- HIPAA compliance for dental offices: what auditors actually check
- HIPAA compliance checklist for small medical practices in California
- Notice of Privacy Practices template, updated for 2026
- HIPAA policies for chiropractic offices
- HIPAA policies for physical therapy practices
- HIPAA policies for mental health and behavioral health practices
- HIPAA policies for optometry practices
- HIPAA for med spas and aesthetics practices
- HIPAA policies and procedures for small medical practices
Templates, not legal advice. Eaglizer IT is not a law firm and does not certify HIPAA compliance. Using templates does not by itself make a practice compliant; follow the policies, train your staff, and keep records.