Skip to Content

Should a small practice pay for a HIPAA risk analysis?

The free federal SRA Tool takes two afternoons, and fixing what it finds is the hard part
April 26, 2023 by

The most useful HIPAA security document a small practice can produce costs nothing, comes from the federal government, and takes about two afternoons. Most practices have never opened it. They either pay a consultant four figures for a PDF that says the same thing, or produce nothing and hope the question never comes up.

Three free public resources are worth your time. One matters far more, so start there.

The SRA Tool is the one that counts

HHS and the health IT office at healthit.gov jointly publish the Security Risk Assessment Tool, a free Windows application with a spreadsheet version for everyone else. You answer questions on the Security Rule safeguards, device and media controls, vendors, and contingency planning. It also makes you build an asset inventory and a vendor list, usually the moment somebody discovers that six SaaS products touch patient data and two never signed a business associate agreement.

What comes out is a risk report: threats and vulnerabilities, likelihood and impact ratings, and a record of what you answered and why. That is exactly what 45 CFR 164.308(a)(1)(ii)(A) requires, an accurate and thorough assessment of risks to electronic protected health information. It is also one of the first things OCR asks for when a breach investigation lands. Not your firewall model. Not your EHR vendor's certification letter. Your risk analysis, dated, with your name on it.

OCR publishes its resolution agreements and corrective action plans, and reading a handful is boring in one specific way: no risk analysis on file, or one predating half the systems the practice now runs. The breach starts the investigation. The missing risk analysis turns it into a settlement.

What the tool is genuinely bad at

It is a self-assessment questionnaire that scans nothing, tests nothing, and believes every word you type. It will not find the RDP port your last IT guy opened or the laptop where somebody switched encryption off. Answer it optimistically and you produce a clean risk analysis documenting nothing but your optimism. Answer it honestly and it is the best free thing in this category.

Running it is easy. Fixing what it finds is not.

This is the part the "free tool!" posts skip. Two afternoons of honest answering gets you a dated list of your gaps. You now know about them, and the penalty tiers top out at willful neglect left uncorrected, so a document proving you knew makes the charitable readings harder to argue.

The real project starts after the export.

  • Full disk encryption on every laptop that touches patient data. Addressable under 164.312 means implement it or document why not and do something equivalent. It does not mean optional.
  • MFA on the EHR, on email, and on the remote access path.
  • Backups an attacker with domain admin cannot delete.
  • Business associate agreements with every vendor on the list you just built.
  • An offboarding checklist that revokes access the same week somebody leaves.

None of it is exotic. All of it takes calendar time and an owner. 164.308(a)(1)(ii)(B) says finding the risk is not enough, you have to reduce it to a reasonable and appropriate level, and 164.316(b)(2)(i) says keep the documentation six years. No clause names a cadence, only ongoing review, so most practices land on annually plus after any major system change.

Where the other two actually fit

The HHS HIPAA for Professionals section is the primary source for rule text and guidance, including sample business associate agreement provisions you can adapt. Read the breach notification pages before you need them: individual notice is due within 60 days of discovery, breaches of 500 or more people also go to HHS on that clock, and passing 500 residents of one state adds media notice. Nobody reads that calmly at 9 p.m. on the day of an incident.

StaySafeOnline, run by the National Cybersecurity Alliance, is not HIPAA-specific and does not pretend to be. Its value is staff-facing material on phishing, passwords, and MFA that a front desk team will actually absorb. 164.308(a)(5) requires a security awareness and training program, and free material people read beats a policy binder nobody opens. Keep your own attendance records; nothing there documents itself.

Syncritech does this work for medical practices and device companies, usually starting from whatever the SRA Tool turned up and sorting it into urgent, this quarter, and fine for now. Run it yourself first if you would rather. You will know more about your own network by Friday.

Share this post
Zero trust rides on the ISO 9001 procedures you already wrote
Phased rollout order for a company running a QMS, and the point where that stops helping