HIPAA Risk Register: Build One an Auditor Accepts
When the Office for Civil Rights opens an investigation after a breach report, one of the first document requests is almost always the same: your most recent risk analysis and evidence that you acted on it. The risk analysis is a snapshot. The evidence of action is a HIPAA risk register — a living list of identified risks, each with an owner, a score, a remediation decision, a due date, and a paper trail. If you have the assessment but nothing showing what you did next, you have half a compliance program and a hard conversation ahead.
This article is for the person who has to produce that register: the practice owner, privacy officer, security officer, or compliance lead. Below are the exact fields to track, how to score entries without inventing a math ritual, who owns what, how often to review, and what the documented evidence looks like when someone asks for it.
What Is a HIPAA Risk Register?
A HIPAA risk register is a maintained record of every threat and vulnerability affecting electronic protected health information in your practice, together with the assigned owner, risk rating, chosen response (remediate, mitigate, transfer, or accept), target date, and the evidence that the response happened. It is the bridge between the required risk analysis under 45 CFR 164.308(a)(1)(ii)(A) and the required risk management activity under 164.308(a)(1)(ii)(B). The register is not itself named in the regulation — the two obligations it connects are.
Practically: the risk analysis answers what could go wrong and how badly. The register answers who is fixing it, by when, and how do we prove it.
Where the Obligation Actually Comes From
The Security Rule requires an accurate and thorough assessment of potential risks to the confidentiality, integrity, and availability of ePHI, and then requires you to implement measures sufficient to reduce those risks to a reasonable and appropriate level. HHS has published guidance on risk analysis requirements that makes the sequence explicit — assessment first, then risk management, then repeat.
Two more provisions shape how the register looks. Section 164.316(b) requires you to retain policies, procedures, and required documentation for six years from creation or last effective date, whichever is later. Section 164.308(a)(1)(ii) requires the analysis and management to be ongoing, not one-time. A register that hasn't been touched in 26 months fails both tests at once.
For method, NIST published SP 800-66 Revision 2, Implementing the HIPAA Security Rule, in February 2024. It is not binding, but it maps Security Rule standards to concrete risk-management practices and gives you defensible vocabulary. Small practices without a security engineer should also look at the HHS Security Risk Assessment Tool, which walks through questions and produces an output you can feed straight into register entries.
One forward-looking note: in January 2025, HHS published a proposed rule to strengthen the Security Rule, including proposals around asset inventories and network mapping. It remains a proposal as of this writing. Do not build your register around it — but if you already track assets by owner and location, you are ahead of where the proposal points.
The Ten Fields Every Entry Needs
Spreadsheets are fine. Ticketing systems are fine. What matters is that each row carries enough to survive staff turnover and a subpoena.
- Risk ID — a stable identifier (R-2025-014). Never reuse or renumber.
- Date identified and source — annual risk analysis, incident review, vendor questionnaire, staff report, penetration test, audit log review.
- Asset or process affected — "front-desk workstation FD-02," "transcription vendor SFTP transfer," "paper superbills in billing office."
- Threat and vulnerability, stated separately — "theft of device" (threat) paired with "full-disk encryption not enabled" (vulnerability). Auditors notice when practices collapse the two.
- Likelihood and impact ratings, plus the resulting inherent risk score.
- Existing controls — what already reduces this risk today.
- Response decision — remediate, mitigate, transfer, or accept, with a one-line rationale.
- Owner — a named person, not a department. "IT" is not an owner.
- Target date and status, with the date of each status change.
- Evidence link — ticket number, screenshot, signed agreement, training roster, configuration export.
Add a residual risk score column once remediation closes. That single column is what demonstrates the register produced an actual reduction rather than activity for its own sake.
Scoring Without Pretending It's Science
Use a 1–5 scale for likelihood and 1–5 for impact, multiply, and write down what each number means so two different people rate the same risk the same way. Define impact in terms your practice understands: number of records exposed, days of downtime, whether the exposure would trigger notification under the Breach Notification Rule.
Set thresholds and stick to them. A common structure: scores of 15 and above require remediation within 30 days and a named executive sponsor; 8 through 14 require a documented plan with a target date inside 90 days; 7 and below may be accepted in writing with annual re-review. The specific numbers matter less than the fact that you wrote them down before the ratings, not after.
Three Worked Entries from a Real-Shaped Practice
Here is what a functioning HIPAA risk register looks like at the row level for a nine-provider specialty group.
R-2025-004. Identified 2025-02-11 during annual risk analysis. Asset: two laptops used by the billing manager and practice administrator. Threat: theft or loss off-site. Vulnerability: full-disk encryption unverified on both. Likelihood 3, impact 5, score 15. Existing controls: password login, screen lock at 10 minutes. Decision: remediate. Owner: practice administrator, with managed IT vendor executing. Target 2025-03-15. Status: closed 2025-03-06. Evidence: encryption status report from the device management console, exported and saved with the register version, plus vendor ticket 88214. Residual risk: likelihood 3, impact 2, score 6.
R-2025-011. Identified 2025-04-02 after a near-miss. Process: outbound faxing of records to referring offices. Threat: misdirected disclosure. Vulnerability: manual number entry, no verification step, no fax confirmation retention. Likelihood 4, impact 3, score 12. Decision: mitigate. Owner: front-desk supervisor. Actions: mandatory read-back of the destination number by a second staff member for any record containing more than one patient, pre-programmed entries for the top 20 referral destinations, confirmation sheets retained 90 days. Target 2025-05-30. Status: closed with evidence consisting of the revised workflow document, the training sign-in sheet with nine signatures, and a spot-check log from June and September.
R-2025-019. Identified 2025-06-18 during vendor inventory reconciliation. Asset: a third-party appointment-reminder service receiving patient names, phone numbers, and appointment times. Vulnerability: no executed business associate agreement on file; the practice had a signed order form only. Likelihood 5 — the exposure exists today, not hypothetically — impact 4, score 20. Decision: remediate immediately. Owner: privacy officer. Target 2025-07-02. Status: closed 2025-06-27 with a countersigned BAA stored as a PDF and a register note recording the date the vendor first began receiving PHI.
Vendor Gaps Are the Register Entries That Bite Hardest
Run your vendor list against your BAA folder and you will usually find at least two mismatches: a service that touches PHI with no agreement, or an agreement signed before 2013 that never picked up the Omnibus Rule updates. Both belong in the register as open high-severity items, because both are documentable violations of 164.308(b) and 164.502(e) that exist right now — not future risks.
The remediation is mechanical, which is why leaving it open looks so bad in an investigation. If your gap is a missing or outdated agreement, you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX the same afternoon, then attach the countersigned copy as the evidence artifact on that register row. One-time purchase, no subscription — which matters when the fix is a discrete task, not an ongoing service.
Keep a subledger inside the register for vendor risks. Columns: vendor name, service, PHI elements received, BAA execution date, BAA version, subcontractor flag, last security attestation received, next review date. When a vendor breach makes the news, you want to answer "are we affected" in four minutes, not four days.
The Cadence That Keeps the Register Alive
A register decays without a meeting attached to it. The pattern that survives audit:
- Monthly, 20 minutes. Privacy officer and security officer review open items scored 15+. Update statuses with dates. Escalate anything past its target date.
- Quarterly, 60 minutes. Full register walk-through with the practice administrator and IT vendor. Add new entries from incidents, complaints, audit log reviews, and vendor changes. Re-score anything where controls changed. Produce dated minutes naming attendees and decisions.
- Annually. Refresh the underlying risk analysis, reconcile the asset and vendor inventories, re-review every accepted risk, and archive a locked version of the register with a version number and date.
- Event-driven. New EHR module, new location, new remote-work arrangement, staff departure with elevated access, ransomware attempt, or an incident that reaches your breach risk assessment — each generates entries within five business days.
Assign the register a single accountable owner. In most practices that is the privacy officer or the security officer; in small practices it is the same person, which is permissible, but name them in writing in your policies.
What OCR Actually Looks For
Resolution agreements published on the HHS enforcement pages repeatedly cite the same two failures: no accurate and thorough risk analysis, and failure to implement risk management measures. Reviewing the breach reporting portal is a useful exercise — the recurring categories (lost devices, hacking of network servers, email compromise, improper disposal) tell you which register entries you should already have open.
The tell of a fabricated register is uniformity: every item closed, every date on the last day of a quarter, no accepted risks, no overdue items. A real register has a few stubborn entries with revised target dates and a written explanation. Document the delay and the interim compensating control. Honest and tracked beats tidy and invented.
Five Failure Modes to Check This Week
- No paper or physical entries. The Security Rule covers ePHI, but the Privacy Rule covers records in every form. Charts in an unlocked overflow room belong in your register.
- Departments as owners. Replace every "IT" or "front office" with a person's name and a date.
- Accepted risks with no signature. An accepted risk needs a named approver, a rationale, and an annual re-review date. Otherwise it reads as an ignored risk.
- Evidence stored nowhere. If the register links to a screenshot that lived on a laptop three staff members ago, the row is unsupported. Store artifacts alongside archived register versions.
- No version history. Overwriting one spreadsheet forever destroys your ability to show what you knew and when. Archive dated versions and keep them six years.
Start With the Version You Can Maintain
A ten-column spreadsheet reviewed every quarter beats a sophisticated platform nobody opens. Build the register from your most recent risk analysis this month, reconcile the vendor list against your executed agreements, assign names and dates to every row scored 15 or above, and put the quarterly review on the calendar through 2026 before you close the file.
If the underlying risk analysis and policy set are what's missing — not just the tracking layer — automated HIPAA risk analysis reports and the supporting policy documents will give you the input the register needs. And if the fastest wins on your list are vendor agreement gaps, close them first with a signature-ready BAA you can export and send today, then log the countersigned copy as evidence and move to the next row.