Your HIPAA security risk assessment likely focuses on electronic protected health information (ePHI). That's what the HIPAA Security Rule explicitly requires under 45 CFR § 164.308. But if you're stopping there, you're creating compliance gaps that could trigger enforcement actions and erode patient trust.
This checklist covers the full scope of HIPAA risk assessment obligations, including the often-overlooked requirements for non-electronic PHI and breach risk assessments. Each item includes the specific regulatory reference and what successful implementation looks like.
What This Checklist Covers
This is a compliance verification tool for organizations subject to the Health Insurance Portability and Accountability Act. It addresses:
- Security risk assessment requirements under the HIPAA Security Rule
- Breach risk assessment obligations under the HIPAA Breach Notification Rule (45 CFR § 164.402)
- Non-electronic PHI vulnerabilities that fall outside the Security Rule's scope
- Business Associate Agreement requirements that extend assessment responsibilities
Use this to verify you're meeting all assessment obligations, not just the electronic ones.
Prerequisites
Before you start, confirm:
- You've identified all PHI formats in your environment (electronic, paper, verbal, faxed)
- You have current Business Associate Agreements with all vendors handling PHI
- You've designated a senior individual responsible for security oversight (required under 45 CFR § 164.308(a)(2))
- You understand the difference between addressable and required implementation specifications
HIPAA Security Risk Assessment Checklist
Core Assessment Requirements
1. Conduct an accurate and thorough assessment of risks to ePHI confidentiality, integrity, and availability (45 CFR § 164.308(a)(1)(ii)(A), Required)
Evaluate where ePHI is created, received, maintained, and transmitted across your organization. Don't limit this to obvious systems like your EHR. Include email, file shares, backup systems, and cloud applications.
Good looks like: A documented inventory of all ePHI-containing systems with identified threat scenarios, likelihood ratings, and impact assessments for each.
2. Implement risk management measures to reduce identified risks to reasonable and appropriate levels (45 CFR § 164.308(a)(1)(ii)(B), Required)
Prioritize remediation based on risk severity. The "flexibility of approach" clause lets you tailor controls to your organization's size and complexity, but you must address all identified risks.
Good looks like: A prioritized remediation plan with assigned owners, timelines, and documentation showing why you chose specific controls over alternatives.
3. Apply sanctions to workforce members who violate security policies (45 CFR § 164.308(a)(1)(ii)(C), Required)
Document your sanctions policy and enforce it consistently. This isn't optional even though enforcement is uncomfortable.
Good looks like: A written sanctions policy with documented enforcement actions when violations occur (anonymized in your records).
4. Review information system activity via audit logs and access reports (45 CFR § 164.308(a)(1)(ii)(D), Required)
Implement audit controls under 45 CFR § 164.312(b) and actually review the logs. Collecting logs you never examine doesn't meet the requirement.
Good looks like: Scheduled log reviews with documented findings and follow-up actions for anomalous access patterns.
Physical and Technical Safeguards Assessment
5. Verify facility access controls prevent unauthorized physical access to ePHI (45 CFR § 164.310(a)(1), Addressable)
Assess how visitors, cleaning crews, and unauthorized staff could access areas where ePHI is stored or displayed. "Addressable" doesn't mean optional; it means you must implement it or document an equivalent alternative.
Good looks like: Facility access logs, visitor sign-in procedures, and locked server rooms with restricted badge access.
6. Confirm workstations are positioned to prevent unauthorized viewing (45 CFR § 164.310(b), Required)
Walk your facility. Can reception staff see patient information on clinician screens? Are workstations visible through windows?
Good looks like: Privacy screens on monitors in public-facing areas, workstations angled away from patient traffic, and automatic screen locks after brief inactivity periods.
7. Validate unique user identification for all ePHI access (45 CFR § 164.312(a)(2)(i), Required)
No shared logins. Ever. This includes "clinic" accounts or "front desk" credentials.
Good looks like: Every user has a unique ID tied to their identity, with access permissions matching their job responsibilities.
8. Test encryption implementation for data at rest and in transit (45 CFR § 164.312(a)(2)(iv) and 164.312(e)(2)(ii), Addressable)
If you're not encrypting, document why it's not reasonable and appropriate for your environment, then implement equivalent alternative measures.
Good looks like: Encrypted databases, TLS for email containing PHI, and encrypted backups with documented key management procedures.
Business Associate and Organizational Requirements
9. Review all Business Associate Agreements for HIPAA Security Rule compliance language (45 CFR § 164.308(b)(1), Required)
Your BAAs must require associates to comply with applicable HIPAA Security Rule provisions and report security incidents, not just breaches.
Good looks like: Current BAAs with all vendors handling ePHI, including language requiring incident reporting and allowing you to audit their security practices.
10. Assess contingency planning effectiveness through testing (45 CFR § 164.308(a)(7)(ii)(iv), Addressable)
Test your data backup plan, disaster recovery plan, and emergency mode operations. Untested plans fail when you need them.
Good looks like: Annual testing with documented results, identified gaps, and plan updates based on test findings.
Non-Electronic PHI Risk Assessment
11. Identify risks to non-electronic PHI confidentiality, integrity, and availability
The HIPAA Security Rule only covers ePHI, but risks exist when medical reports are left on printers, conversations occur in hallways, or paper records are disposed of improperly.
Good looks like: A documented assessment covering verbal disclosures, printed materials, faxed documents, and physical record storage with identified controls for each format.
12. Evaluate individuals' access rights to their PHI across all formats
Patients have rights to access their information whether it's electronic or paper. Assess whether you can fulfill Data Subject Access Requests within required timeframes.
Good looks like: Documented procedures for responding to access requests, with tested retrieval processes for both electronic and paper records.
Breach Risk Assessment Process
13. Establish a breach risk assessment process for impermissible PHI acquisitions, access, use, or disclosures
Under 45 CFR § 164.402, any impermissible PHI incident is presumed to be a breach unless you can demonstrate a low probability of compromise through a risk assessment.
Good looks like: A documented process evaluating the nature and extent of breached PHI, the unauthorized person involved, whether PHI was actually viewed, and mitigation effectiveness.
Common Mistakes
Treating addressable specifications as optional. Addressable means you must implement the specification or document why an alternative is more appropriate. You can't simply skip it.
Conducting risk assessments only when required for compliance reviews. Risk assessments should be ongoing, triggered by system changes, new threats, or security incidents.
Limiting assessments to IT systems. Your assessment must cover administrative processes, physical security, and workforce behavior, not just technical controls.
Failing to document assessment methodology. When OCR asks how you conducted your risk assessment, "we looked at our systems" isn't sufficient documentation.
Ignoring Business Associate security incidents. Your BAA should require associates to report security incidents (not just breaches), and you should assess whether those incidents affect your risk profile.
Next Steps
After completing this checklist:
- Document gaps with specific remediation plans and owners
- Schedule your next assessment (annually at minimum, or when significant changes occur)
- Update your risk register based on new findings
- Brief your senior leadership on residual risks and budget needs for remediation
- Review your Business Associate Agreements to ensure they require security incident reporting
Your risk assessment isn't a one-time compliance exercise. It's the foundation for every security decision you make about protecting patient information.



