Compliance
HHS Updates HIPAA Security Risk Assessment Tool
The revised resource reflects today's technology environment and evolving enforcement expectations.
October 5, 2026
The Department of Health and Human Services (HHS) has updated its interactive Security Risk Assessment Tool (SRA Tool), which helps guide regulated entities in performing and documenting Health Insurance Portability and Accountability Act (HIPAA) security risk assessments. Although HHS designed the SRA Tool for healthcare providers in small- to medium-sized offices, it may be a helpful resource for other covered entities and business associates to review their compliance with HIPAA’s safeguards for electronic protected health information (ePHI).
Risk Assessment
Conducting a risk assessment is a crucial first step in an organization’s efforts to comply with the HIPAA Security Rule. It directs what reasonable steps a regulated entity should take to protect the ePHI it creates, transmits, receives or maintains. A risk assessment helps an organization establish appropriate administrative, physical and technical safeguards for its ePHI.
Risk assessment is also an ongoing process. Regulated entities should periodically revisit their risk assessments and make appropriate updates to their ePHI safeguards. Compliance with the HIPAA Security Rule is not a one-time project, but rather an ongoing, dynamic process that will create new security challenges as organizations and technologies change.
HHS, through its Office for Civil Rights, has implemented a risk analysis initiative to focus its enforcement efforts on ensuring that regulated entities comply with the Security Rule’s risk analysis and management requirements.
Tool Updates
The enhancements to the SRA Tool are intended to make the tool easier to use and more relevant to the current cybersecurity environment. Updates include the following:
- A reminder that the SRA Tool may not identify all security risks and that organizations may need additional tools to identify technical vulnerabilities
- A new question asking if the assessment covers every facility and location that creates, receives, maintains or transmits ePHI, potentially reducing blind spots for multi-site practices
- A new question asking about remote access and whether appropriate safeguards are in place
- Updated inventory questions that cover modern technology, such as cloud/SaaS platforms, mobile devices and removable media
- Updated system-activity logging questions for the varied systems
- New guidance on when to review or update risk assessments, such as after mergers, acquisitions, new technology adoption and security incidents
Action Items
In light of heightened enforcement activity, covered entities and business associates should prioritize conducting thorough and accurate risk assessments. The SRA Tool serves as a valuable resource to assist organizations in navigating the risk assessment process and evaluating their compliance with the HIPAA Security Rule.
If you have questions, please reach out to your Hylant representative for further information. Don’t have one? Contact us here.
The above information does not constitute advice. Always contact your employee benefits broker or trusted advisor for insurance-related questions.