What a real risk analysis contains, and what the SRA Tool produces
A completed HHS Security Risk Assessment Tool questionnaire is not a risk analysis. OCR settlements have said so repeatedly. Here is the difference.
The free Security Risk Assessment Tool from HHS and ASTP is genuinely useful. It is well built, it is free, and it will structure your thinking. It is also not a risk analysis, and a completed export of it has repeatedly failed to satisfy investigators.
This is worth being precise about, because a lot of practices believe they have discharged the requirement and have not.
What the requirement actually says
Section 164.308(a)(1)(ii)(A) requires an "accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate."
Three words in there do most of the work. Accurate means it reflects the environment as it is, not as a questionnaire assumed. Thorough means all of it — every location, every system, every repository. And held by means everywhere the data actually lives, including the places nobody put on the list.
What a real one contains
- A complete inventory of ePHI repositories. Not the systems you meant to inventory. The imaging server, the scanned-document share, the spreadsheet on the office manager's desktop, the vendor portal, the backup destination, the departed employee's OneDrive.
- Data-flow mapping. Where ePHI enters, where it moves, where it leaves, and to whom. This is the part that surfaces the business associates nobody remembered.
- Threat and vulnerability identification per asset. Threats are what could happen; vulnerabilities are what makes it possible. They are different lists and both are required.
- Likelihood and impact, assessed and documented. With reasoning. "High" with no rationale is not an assessment.
- Current controls, as implemented rather than as intended. The gap between the policy and the tenant configuration is where most findings live.
- Risk determination per finding, mapped to a Security Rule citation.
- Method and scope, stated. Ours are conducted against NIST SP 800-66 Rev. 2. An analysis that does not say how it was conducted cannot be evaluated.
What the questionnaire produces
A structured set of self-reported answers about whether you have addressed each standard, and a summary. It does not enumerate your systems, it does not map your data flows, it does not test whether the control you said was in place is actually in place, and it does not produce a prioritized remediation plan with owners.
Those are not criticisms of the tool. It was never intended to be the deliverable.
And now the second half
Section 164.308(a)(1)(ii)(B) requires risk management: implementing security measures sufficient to reduce risks to a reasonable and appropriate level. In practice that means a dated, prioritized remediation plan with an owner per item and evidence of completion.
OCR's Risk Analysis Initiative launched in October 2024 and, per Director Paula Stannard, expands in 2026 to cover risk management rather than just risk analysis. A completed analysis with no evidenced remediation is now its own exposure.
Practically: if you have a risk analysis in a drawer and nothing happened afterward, you have documented that you knew.
What OCR actually asks for in a data request
Eleven document categories, taken from a real request. Go down the list and mark which ones you could produce this week.
Read it Dental · 10 Jun 2026Eaglesoft, dba, and sql
A practice management system that shipped with hardcoded database credentials, and what to actually do about it in a live operatory.
Read it