The HIPAA Risk Assessment: What It Is and How a Small Clinic Runs One
It is the single most required and most skipped item in HIPAA compliance. Here is what the risk assessment is, why once a year is the standard, and how to run one without hiring a consultant.

What the risk assessment actually is
The HIPAA Security Rule requires you to conduct an accurate and thorough assessment of the potential risks to your electronic patient information. In plain English: write down where your patient data lives, what could go wrong with it, how likely that is, how bad it would be, and what you are doing about it.
It is the foundation the entire Security Rule stands on. You cannot choose “reasonable and appropriate” safeguards if you have never documented the risks. Auditors ask for it first because everything else — your policies, your training, your technical controls — is supposed to flow from it.
Why “annually” is the practical standard
The rule does not stamp a calendar date on it. It says the assessment must be accurate and thorough, which means it must reflect your current reality — and reality changes. New EHR, new billing company, new front-desk PC, a move across town in Corpus Christi, three staff turnovers: each one changes the risk picture.
In practice, “once a year, plus whenever something significant changes” is the standard every auditor expects. An assessment from 2022 sitting in a drawer does not describe your clinic today, and everyone in the room knows it.
How a small clinic actually runs one
You do not need a consultant and a six-figure engagement. You need a structured afternoon with the right people in the room — the owner or office manager, whoever runs the computers, and your IT provider. Work through it in this order:
- Inventory where ePHI lives. List every system: EHR, billing software, email, the shared drive, laptops, phones, tablets, the old PC in the back nobody uses anymore, cloud backups. If patient data touches it, it goes on the list.
- Identify threats to each one. Ransomware, theft, a disgruntled ex-employee with a still-active login, an email phishing attack, a flood — Coastal Bend clinics should take hurricane season seriously on this line.
- Assess current safeguards and gaps. For each threat, what is already in place? MFA on email? Encrypted laptops? Tested backups? Be honest — “we think so” is a gap until verified.
- Rate likelihood and impact. Simple high/medium/low for each. A ransomware hit on the EHR server: high impact. A stolen encrypted laptop with remote wipe: lower.
- Document it all in writing. The assessment only exists if it is written down. Date it, note who participated, and keep it where you can find it.
- Build the fix list. Every gap becomes an action item with an owner and a deadline. Critical items — untested backups, no MFA on email — go first.
The mistakes that waste the effort
Treating it as a checkbox. A risk assessment that concludes “everything is fine” in a clinic that has never tested a backup is not an assessment — it is fiction, and it will read that way.
Leaving IT out of the room. The office manager knows the workflows; the IT provider knows what the systems actually do. You need both halves to see the real picture.
No follow-through. The assessment’s job is to produce the fix list. An assessment with no remediation plan is a very expensive way to learn nothing.
Forgetting it exists. File it where the next one starts. When the auditor, the new hire, or the ransomware asks, “where is your risk assessment,” the answer should take thirty seconds.
What to do Monday morning
Schedule the afternoon. Pick a date within the next 30 days, invite your IT provider, and print the inventory checklist above. The hardest part of a risk assessment is starting it — and a dated, honest, documented assessment puts you ahead of the large majority of clinics your size.
Block a full afternoon and treat it like a patient appointment — phones covered, door closed. Work the list in order: inventory first, because you cannot assess risks to systems you have not named. Invite your IT provider; the office manager brings the workflows, IT brings the technical reality, and the gaps show up where the two do not match. End the afternoon with the fix list assigned and dated — an assessment that produces no action items was a meeting, not an assessment. File the finished assessment where the next one begins — you will thank yourself in twelve months.
Not sure where your practice stands?
Our free network assessment reviews your computers, backups, and security — and gives you a plain-English read on what's solid and what isn't. No scare tactics.
Call (361) 704-1373 or request yours online.
Request your assessment →Not ready to book? Start with the checklist.
Our 10-Point Small Business IT Security Checklist walks you through the ten things that matter most — in plain English, no jargon. Work through it at your own pace. No sales call, no pitch — just the checklist.
Frequently asked questions
Is the HIPAA risk assessment actually required, or just recommended?
Required. The Security Rule’s administrative safeguards mandate an accurate and thorough risk analysis. It is one of the most frequently cited failures in HIPAA enforcement — not because it is hard, but because so many organizations never do it.
How often does it need to be done?
The rule requires it to stay accurate and thorough, which in practice means at least annually and again whenever something significant changes — new systems, new vendors, staff turnover, a move, or an incident.
Can we do it ourselves, or do we need to hire someone?
A small clinic can run its own assessment following a structured process, especially with its IT provider in the room. What matters is that it is honest, documented, and followed by actual remediation — not who held the pen.
What happens if we have never done one?
Then the next one you do is the most important document in your compliance file. Start now, date it, and keep it current going forward. Regulators care far more about a real assessment today than a perfect history.
Does the risk assessment cover paper records too?
The Security Rule’s risk analysis covers electronic PHI specifically. But the same exercise applied to paper — where charts live, who can reach them — strengthens your Privacy Rule position and costs nothing extra to include.