
If you've been told your medical practice needs a HIPAA Security Risk Assessment, you may be wondering what that actually involves.
Do they scan your network?
Review your policies?
Check your computers?
Interview your employees?
The answer is yes—to many of those things.
A HIPAA Security Risk Assessment (SRA) is a systematic evaluation of your practice's technology, security controls, and processes to identify risks that could affect the confidentiality, integrity, or availability of electronic Protected Health Information (ePHI).
More importantly, it's one of the most critical requirements of the HIPAA Security Rule—and one of the most misunderstood.
Many healthcare organizations mistakenly believe installing antivirus software or using a cloud-based Electronic Health Record (EHR) automatically makes them compliant. In reality, HIPAA requires organizations to continuously identify risks, document findings, and implement reasonable safeguards to reduce those risks.
This guide explains what happens during a HIPAA Security Risk Assessment, why it matters, and what your practice should expect from a quality assessment.
What Is a HIPAA Security Risk Assessment?
A HIPAA Security Risk Assessment is a structured review of the technology, systems, and processes your practice uses to protect electronic Protected Health Information (ePHI).
Its purpose is to answer one simple question:
"Where are the risks to our patients' information, and what should we do about them?"
A quality assessment identifies vulnerabilities before cybercriminals—or regulators—do.
Rather than checking boxes, the assessment evaluates whether your existing safeguards are appropriate for your organization.
This includes reviewing:
- Computers and laptops
- Servers
- Electronic Health Record (EHR) systems
- Microsoft 365
- Wireless networks
- Firewalls
- User access
- Backup systems
- Mobile devices
- Cybersecurity protections
- Security policies
- Documentation
The result is a prioritized roadmap that helps your practice reduce risk over time.
Is a Security Risk Assessment Required by HIPAA?
Yes.
The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of potential risks to electronic Protected Health Information (ePHI).
However, HIPAA doesn't prescribe exactly how to perform the assessment.
Instead, it expects organizations to evaluate their unique environment, identify potential threats, and implement reasonable safeguards based on those findings.
A Security Risk Assessment isn't something you perform once and forget.
It's an ongoing process of evaluating, improving, and documenting your security posture.
Security Risk Assessment vs. Vulnerability Scan vs. Penetration Test
These terms are often used interchangeably—but they're very different.
| Security Risk Assessment | Vulnerability Scan | Penetration Test |
|---|---|---|
| Reviews overall security posture | Finds known software vulnerabilities | Simulates a cyberattack |
| Includes people, processes, and technology | Focuses primarily on systems | Tests real-world exploitability |
| Required by HIPAA | Helpful security tool | Optional advanced testing |
| Produces prioritized recommendations | Produces vulnerability reports | Produces attack findings |
Think of a Security Risk Assessment as the "big picture."
Vulnerability scans and penetration tests are valuable tools, but they're only part of a complete assessment.
When Should a Medical Practice Perform a Security Risk Assessment?
Although every practice is different, most healthcare organizations should perform an assessment:
- At least annually
- After significant technology upgrades
- Before migrating to Microsoft 365
- Before opening a new office
- Following a cybersecurity incident
- Before switching Managed IT Providers
- When cyber insurance requires updated documentation
Waiting until something goes wrong usually makes remediation more expensive and disruptive.
What Happens During a HIPAA Security Risk Assessment?
A comprehensive assessment follows a structured process.
Step 1: Create an Asset Inventory
You can't protect technology you don't know exists.
The assessment begins by identifying:
- Desktop computers
- Laptops
- Servers
- Firewalls
- Wireless access points
- Mobile devices
- Network switches
- Cloud services
- Microsoft 365
- Medical devices connected to the network
This inventory forms the foundation of the assessment.
Step 2: Review Your Network Infrastructure
Next, your network is evaluated for security and reliability.
Typical review areas include:
- Firewall configuration
- Wireless security
- Network segmentation
- Remote access
- VPN configuration
- Internet redundancy
- Guest Wi-Fi separation
Weak network security often creates opportunities for attackers to move throughout an organization.
Step 3: Evaluate Microsoft 365 Security
Microsoft 365 has become a critical part of healthcare operations.
During the assessment, reviewers examine:
- Multi-Factor Authentication
- Conditional Access Policies
- Administrator accounts
- Audit logging
- Secure email configuration
- External sharing
- OneDrive settings
- Microsoft Defender
Many organizations discover security features they already own—but haven't enabled.
Step 4: Review Endpoint Security
Every computer accessing patient information should be protected.
The assessment evaluates:
- Antivirus or Endpoint Detection & Response (EDR)
- Device encryption
- Operating system versions
- Patch management
- Local administrator privileges
- Device health
Older computers often represent unnecessary security risks.
Step 5: Review Backup and Disaster Recovery
Backups aren't valuable unless they can actually be restored.
Reviewers typically examine:
- Backup frequency
- Backup success
- Offsite copies
- Recovery testing
- Recovery objectives
- Disaster recovery procedures
Many organizations have backups—but rarely test them.
Step 6: Review User Access
Not every employee should have access to every system.
The assessment reviews:
- User permissions
- Shared accounts
- Former employee accounts
- Password policies
- Administrative privileges
- Multi-Factor Authentication
Access management is one of the most effective ways to reduce internal and external risk.
Step 7: Identify and Prioritize Risks
After gathering information, each identified issue is evaluated based on:
- Likelihood
- Business impact
- Security implications
- Patient care impact
- Compliance considerations
Not every finding carries the same level of urgency.
Prioritization helps practices focus on the issues that matter most.
Step 8: Develop a Remediation Roadmap
The assessment shouldn't end with a list of problems.
It should provide a practical action plan.
Recommendations often include:
- Immediate security fixes
- Short-term improvements
- Long-term technology planning
- Budget recommendations
- Equipment replacement priorities
- Cybersecurity enhancements
The goal is continuous improvement—not perfection.
Common Risks We Find During Assessments
Although every healthcare organization is different, several issues appear repeatedly.
These include:
- Multi-Factor Authentication not enabled
- Shared employee logins
- Unsupported Windows operating systems
- Missing Endpoint Detection & Response
- Weak password policies
- Unencrypted laptops
- Former employees with active accounts
- Firewall firmware that hasn't been updated
- Backups that haven't been tested
- No documented disaster recovery plan
- Missing quarterly technology reviews
- Limited cybersecurity awareness training
Fortunately, most of these risks can be addressed with a structured improvement plan.
What Should You Receive After the Assessment?
A quality Security Risk Assessment should leave you with more than a compliance checkbox.
You should receive:
Executive Summary
A high-level overview for physicians, owners, and administrators.
Detailed Findings Report
A complete explanation of identified risks.
Risk Prioritization
Issues ranked by severity and business impact.
Remediation Recommendations
Specific actions to reduce identified risks.
Technology Roadmap
Recommendations for future improvements and lifecycle planning.
Budget Guidance
Estimated investment needed to address identified risks over time.
The assessment should help leadership make informed technology decisions—not simply highlight problems.
How Much Does a HIPAA Security Risk Assessment Cost?
Costs vary based on several factors, including:
- Number of locations
- Number of users
- Number of managed endpoints
- Complexity of the network
- Existing documentation
- Cloud services
- Regulatory requirements
Practices with multiple offices, specialized medical equipment, or complex IT environments typically require more time than smaller organizations.
Rather than focusing only on price, consider the value of receiving a thorough assessment and a clear roadmap for improving security.
Real Client Success Story
Trusted Healthcare IT Partner for Over 10 Years
Healthcare organizations need more than technical expertise—they need a partner who understands the operational and compliance challenges unique to medical practices.
For more than 10 years, Relda J. Setliff, M.D., P.A. has relied on Torch Networks for proactive IT support and technology guidance.
For over 10 years, Torch Networks has been a trusted technology partner for our medical practice. In healthcare, reliable and secure IT support is essential, and their team understands the unique technology, security, and compliance needs of healthcare providers. They are knowledgeable, responsive, and consistently provide dependable service that allows us to focus on what matters most…our patients. Their proactive approach and commitment to keeping our systems secure have earned our trust year after year. I highly recommend Torch Networks to any healthcare organization looking for an IT partner they can truly rely on.
— Dr. Relda Setliff
Relda J. Setliff, M.D., P.A.
Long-term relationships like this are built on proactive planning, responsive support, and a commitment to helping healthcare providers reduce risk while focusing on patient care.
Frequently Asked Questions
Is a HIPAA Security Risk Assessment required?
Yes. Conducting a Security Risk Assessment is a core requirement of the HIPAA Security Rule for covered entities and business associates that handle electronic Protected Health Information.
How often should a Security Risk Assessment be performed?
Most healthcare organizations perform a formal assessment annually and whenever significant technology or operational changes occur.
How long does a Security Risk Assessment take?
The timeline depends on the size and complexity of your environment. Smaller practices may complete the process in a few days, while larger or multi-location organizations may require additional time.
Can my Managed IT Provider perform the assessment?
Many Managed IT Providers can assist with the technical portions of a Security Risk Assessment. However, it's important to ensure they have experience supporting healthcare organizations and understand HIPAA Security Rule requirements.
What happens if problems are found?
Finding issues is the purpose of the assessment. A quality assessment doesn't just identify risks—it prioritizes them and provides practical recommendations for reducing them over time.
Know Your Risks Before Someone Else Does
A HIPAA Security Risk Assessment isn't about checking a compliance box—it's about understanding your technology, protecting patient information, and reducing the likelihood of costly cybersecurity incidents.
At Torch Networks, we help healthcare organizations throughout Austin and Central Texas evaluate their technology environments, identify technical risks, and build practical roadmaps for improving security. Our assessments are designed to provide clear, actionable recommendations that support your practice's operational goals while strengthening its overall cybersecurity posture.
Schedule a HIPAA Security Risk Assessment
If you're unsure when your last assessment was—or whether it addressed today's cybersecurity challenges—Torch Networks can help.
Our team will evaluate your environment, identify opportunities for improvement, and provide a prioritized action plan so you can move forward with confidence.


