When a practice files a breach report, the Office for Civil Rights usually responds with a data request letter. Near the top of that letter — often item one or two — is a demand for your most recent risk analysis and the risk management plan that followed it. Not your training logs. Not your privacy notice. The risk analysis.

That single document is where the annual HIPAA risk assessment requirement stops being an abstraction and starts being evidence. This article is for the practice owner, administrator, or privacy officer who has to produce that evidence: who owns the work, what the finished artifact contains, how long it takes, and what auditors treat as inadequate. If your last risk analysis is a two-page vendor checklist from 2023, you have a gap you can close this quarter.

Does HIPAA Actually Require an Annual Risk Assessment?

Short answer: the Security Rule requires a risk analysis and requires you to keep it current, but the word "annual" comes from a different place.

45 CFR 164.308(a)(1)(ii)(A) requires every covered entity and business associate to conduct "an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information." This is a required implementation specification, not an addressable one. There is no small-practice exemption.

45 CFR 164.308(a)(8) separately requires periodic technical and nontechnical evaluation whenever environmental or operational changes affect ePHI security. New EHR module, new billing vendor, new office location, ransomware incident — each triggers a review.

The hard annual deadline comes from CMS. Clinicians reporting the Promoting Interoperability performance category under MIPS must attest that a security risk analysis was conducted or reviewed during the calendar year in which the performance period occurs. Answering "yes" without a dated, completed analysis is a false attestation, and CMS audits that measure.

So: HIPAA says current and thorough. CMS says once per calendar year. Practices that do both settle on twelve months as the operating rhythm. That is the practical shape of the annual HIPAA risk assessment requirement.

Who Owns This Inside Your Practice

Assign it by name, in writing, before you start. Diffuse ownership is the single most common reason a risk analysis stalls in month two.

The Security Official

Section 164.308(a)(2) requires you to designate one. In a fifteen-provider group this is usually the practice administrator or IT director. In a four-provider clinic it is frequently the office manager. That person owns the schedule, the final document, and the sign-off.

The IT Provider

Your managed service provider supplies the technical inputs: device inventory, patch status, firewall configuration, backup test results, encryption state of each laptop and workstation. They do not own the analysis. An MSP vulnerability scan is one input among many — it says nothing about your paper fax workflow, your front-desk screen angles, or whether the scheduler's home laptop touches ePHI.

Department Leads

Front desk, billing, clinical, and medical records each answer questions about how ePHI actually moves. This is where the real findings surface. The biller who emails claim attachments from a personal address is a risk your scanner will never detect.

The Signing Owner

A physician-owner or executive signs and dates the completed analysis and the accompanying risk management plan. Unsigned, undated documents carry almost no weight in an investigation.

Scope First: You Cannot Assess What You Have Not Inventoried

HHS guidance is explicit that the analysis must cover ePHI the organization creates, receives, maintains, or transmits — all of it, across all locations, systems, and media. Scoping failures are the most frequent substantive defect OCR identifies.

Build the inventory before the assessment. At minimum, list:

  • Every server, workstation, laptop, tablet, and phone that touches ePHI, including personally owned devices used for after-hours charting
  • Every cloud application: EHR, practice management, e-prescribing, patient portal, secure messaging, telehealth platform, transcription, e-fax, appointment reminders, online scheduling, payment processing
  • Every removable media type still in use — ultrasound USB exports, backup drives, imaging CDs
  • Physical records locations: chart rooms, offsite storage, the box of superbills in the back closet
  • Every business associate with a signed BAA, and every vendor with access but no BAA (that second list is your first finding)

A two-provider clinic typically lands somewhere between 40 and 80 line items. Groups running multiple sites routinely exceed 200. The January 2025 proposed update to the Security Rule would make a written technology asset inventory and network map explicit requirements rather than implied ones — track that rulemaking, but build the inventory now regardless, because you cannot produce a defensible analysis without it.

The Nine Elements Your Documented Analysis Must Contain

HHS Guidance on Risk Analysis Requirements under the HIPAA Security Rule identifies the elements of a compliant analysis. Structure your document around them and an investigator can follow your reasoning.

  1. Scope of the analysis — all ePHI in all forms and media, with the boundary stated
  2. Data collection — where ePHI is stored, received, maintained, and transmitted, documented rather than assumed
  3. Identify and document potential threats and vulnerabilities — human, natural, and environmental
  4. Assess current security measures — what controls exist today, technical and administrative
  5. Determine likelihood of threat occurrence
  6. Determine potential impact
  7. Determine the level of risk — likelihood combined with impact, ranked
  8. Finalize documentation — written, dated, signed
  9. Periodic review and updates — the schedule that makes it ongoing rather than one-time

NIST SP 800-66 Revision 2 maps these elements to concrete practices and is the reference most auditors expect you to have consulted. It is not a mandate; it is the vocabulary the people reviewing your work already use.

A Worked Example: One Finding, Start to Finish

Abstract risk registers are useless. Here is what one row should look like.

Asset: Refill request e-fax service, cloud-hosted, receives roughly 300 pages weekly containing patient names, DOB, and medication lists.

Threat: Unauthorized access to the vendor's web console through credential compromise.

Vulnerability: Three staff share one login. Multi-factor authentication is available but not enabled. No BAA on file — the account was opened by a departed office manager in 2022.

Existing controls: Password rotation every 180 days. Nothing else.

Likelihood: High. Impact: High — a console breach exposes months of fax history. Risk level: High.

Remediation: Individual accounts by 09/30. MFA enabled by 09/15. Executed BAA by 10/15. Owner: Practice administrator. Status tracked monthly.

That row does three things a checkbox cannot: it names the gap, it assigns a human, and it sets a date. Repeat it forty times and you have a risk analysis.

The Risk Management Plan Is the Half Everyone Skips

Section 164.308(a)(1)(ii)(B) requires you to "implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level." OCR has publicized an enforcement initiative focused specifically on risk analysis failures, and the recurring pattern in resolution agreements is not the absence of a document — it is an assessment that identified real risks that nobody then fixed.

An analysis without a remediation plan is arguably worse than no analysis. You have documented that you knew.

Your plan needs a ranked list of findings, a named owner per item, a target date, an interim compensating control where remediation takes months, and a monthly or quarterly status entry showing movement. Keep the closure evidence: the ticket, the screenshot, the signed BAA, the invoice for the replacement firewall.

If the documentation burden is what has stalled you — the register, the policies that must reference the findings, the version history, the signature pages — generating your risk analysis report and the supporting policy set from a structured assessment removes the blank-page problem and gives you dated artifacts you can actually hand to an investigator.

A Twelve-Month Cycle That Survives a Busy Clinic

Weeks 1–2: Refresh the asset and vendor inventories. Reconcile against the BAA binder. Every vendor with ePHI access and no agreement goes straight onto the findings list — and if you need to close that gap quickly, a signature-ready business associate agreement is faster than routing a redline through counsel for a low-risk vendor.

Weeks 3–4: Department walkthroughs. Twenty minutes with each lead. Watch the workflow instead of asking about it — screen positions, printer locations, who logs in as whom.

Weeks 5–6: Technical inputs from IT. Encryption status per device, patch levels, backup restore test results, access log review sampling, offboarding verification for anyone who left in the past year.

Week 7: Score and rank. Draft the register.

Week 8: Owner review, signature, dated distribution. Build the remediation plan with target dates.

Months 3–11: Monthly status updates against the plan. Log any environmental change — new EHR module, new site, new vendor — as a trigger for interim review under 164.308(a)(8).

Month 12: Attest for MIPS Promoting Interoperability if applicable, archive the prior version, and open the next cycle. Retain everything six years per 164.316(b)(2).

Four Failures That Turn a Real Analysis Into a Finding

A vulnerability scan submitted as the risk analysis. Scans cover networks. Risk analysis covers ePHI wherever it lives, including paper and process.

Scope limited to the EHR. The portal, the payment processor, the telehealth platform, and the imaging exports all hold ePHI.

No prior versions retained. One undated PDF proves nothing about continuity. Keep the archive.

Findings with no closure evidence. "Completed" in a spreadsheet cell is not proof. Attach the artifact.

Worth an hour of your time: read through recent entries on the OCR breach portal filtered to practices your size. The recurring causes — unsecured email, unencrypted laptops, vendor incidents, misconfigured cloud storage — are exactly the categories a properly scoped analysis surfaces before they become reportable.

Start the Cycle This Month

The annual HIPAA risk assessment requirement is not satisfied by intent, and it is not satisfied by a scan report. It is satisfied by a dated, signed, scoped document plus visible evidence that you acted on what it found.

If your current file is stale, thin, or missing, pick a start date in the next two weeks, name the owner, and pull the vendor list first. When you're ready to produce the report, policies, and remediation tracking as a single documented set, build your risk analysis and compliance documentation in one pass and put a defensible artifact in the binder before anyone asks for it.