What a HIPAA Risk Assessment Is
A HIPAA risk assessment — formally a Security Rule risk analysis — is a documented assessment of the risks to the confidentiality, integrity and availability of the electronic protected health information you hold. It covers every system that creates, receives, maintains or transmits ePHI, and it produces a rated risk register with a remediation plan.
It is not a checklist, a policy review, or a penetration test. Those are useful and they are different things. The risk analysis asks a specific question: where is ePHI, what could happen to it, how likely is that, and what are you doing about it.
Why It Is Required, Not Recommended
The Security Rule lists it as an administrative safeguard, and unlike many HIPAA specifications it is required rather than addressable. There is no path where you document why it does not apply to you.
Two practical consequences:
It is the first thing OCR asks for. In an investigation following a breach or a complaint, the request for a current risk analysis arrives early. An organization that cannot produce one has answered a question about its compliance posture before any technical detail is discussed.
Its absence is cited repeatedly in enforcement. Failure to conduct an accurate and thorough risk analysis is among the most commonly cited findings in HIPAA settlements — see HIPAA penalties and enforcement.
Risk Analysis vs Risk Management
These are two separate Security Rule specifications and organizations routinely do the first and skip the second.
| Risk analysis | Risk management | |
|---|---|---|
| Asks | What are the risks to ePHI? | What are we doing about them? |
| Produces | A rated risk register | Implemented measures, tracked to closure |
| Required or addressable | Required | Required |
| Commonly missing | Sometimes | Very often |
A risk register with no evidence of remediation is half an answer. It demonstrates you knew about a risk and does not demonstrate you addressed it, which in an investigation is a worse position than not having looked. Our engagement covers both.
What We Assess
1. ePHI mapping. Where it enters, rests and leaves — including systems the security team did not know handled it. This stage regularly changes the scope.
2. Asset and vendor inventory. Every system and third party that touches ePHI, which is also the input to your BAA review.
3. Threats and vulnerabilities. Per asset, covering technical, physical and administrative exposure.
4. Current safeguards. What is genuinely in place against the 18 standards — see HIPAA safeguards explained.
5. Likelihood and impact. Rated on a documented, repeatable scale.
6. Risk management plan. Measures, owners, dates, and how closure gets evidenced.
What You Get
The risk analysis document itself, in the form an investigator expects: scope, methodology, assets, threats, ratings and conclusions.
A rated risk register with a named owner per risk.
A costed remediation plan, sequenced so the highest-rated risks close first.
An ePHI data map showing every system in scope.
A BAA gap list — vendors touching ePHI without an agreement in place, which is a common and easily-closed exposure.
Cost and Timeline
Avantcert engagement ranges, already discounted 30–50% below typical market rates. No certification body fee, because no HIPAA certificate exists — see why that is.
| Tier | Employees | Avantcert engagement | Max duration |
|---|---|---|---|
| Startup | 5–50 | from $3,000 | 60 days |
| Mid-Market | 51–200 | around $7,500 | 60 days |
| Large Enterprise | 201–500 | up to $12,000 | 60 days |
Most assessments run two to four weeks. Full breakdown in HIPAA compliance cost.
Book a HIPAA Risk Assessment
Tell us whether you are a covered entity or business associate and roughly where ePHI sits. Scoped proposal within 24 hours.
Our form could not load. Email your role and ePHI scope and you'll get the same proposal within 24 hours.
Email your requirements Open the full quote formHIPAA Risk Assessment FAQs
What is a HIPAA risk assessment?
A documented assessment of the risks to the confidentiality, integrity and availability of the electronic protected health information you hold. It is explicitly required by the HIPAA Security Rule, it covers every system that creates, receives, maintains or transmits ePHI, and it produces a rated risk register with a remediation plan.
Is a HIPAA risk assessment required by law?
Yes. The Security Rule requires a risk analysis as an administrative safeguard, and it is a required rather than addressable specification. It is also the first document requested in an OCR investigation, and its absence appears repeatedly in enforcement actions.
How often should a HIPAA risk assessment be done?
The Security Rule requires it to be periodic rather than setting a fixed interval. Annually is the practical standard, plus whenever something material changes — a new system handling ePHI, a significant architectural change, a merger, or a breach.
What is the difference between risk analysis and risk management?
Risk analysis identifies and rates the risks to ePHI. Risk management is implementing measures to reduce them to a reasonable and appropriate level. The Security Rule requires both as separate specifications, and organizations frequently complete the first and never document the second.
How much does a HIPAA risk assessment cost?
Avantcert HIPAA engagements run from $3,000 for a 5–50 employee organization, around $7,500 at 51–200, and up to $12,000 at 201–500 or complex scope. There is no certification body fee because no HIPAA certificate exists.
Can I do a HIPAA risk assessment myself?
Nothing prohibits it, and free tools exist. What self-assessments most often miss is scope — systems that touch ePHI which nobody catalogued — and the risk management half, where identified risks are never tracked to closure. Both are exactly what an investigation examines.
What Happens Next
The risk assessment is stage one of a HIPAA programme. See the full engagement, HIPAA compliance overview, or HIPAA for SaaS companies if you are a business associate.
Official reference: HHS, Guidance on Risk Analysis.
Have the document before you need it
Two to four weeks, and you can answer the first question an investigator asks.