Conducting a thorough HIPAA Risk Assessment ensures your organization identifies and addresses risks to protected health information, verifying that current safeguards are effective. It is not a generic IT audit and it is not optional. The HIPAA Security Rule requires it, and the most common way organizations fall short is not skipping it entirely but treating it as a one-time document filed away to satisfy an auditor. The rule actually calls for a living process, revisited whenever you adopt new technology or change how you work. This guide explains what a HIPAA risk assessment covers, exactly who is required to perform one, how often, and what happens if you get it wrong, so you can tell whether your organization is genuinely covered or just believes it is.
The Key Points Up Front
If your organization touches protected health information, start with these facts:
- A HIPAA risk assessment identifies risks to protected health information and tests whether your safeguards are adequate.
- Both covered entities and their business associates are required to perform one.
- It is required by the HIPAA Security Rule, not a best-practice suggestion.
- It is not a one-time task; it must be repeated regularly and after significant changes.
- Skipping or faking it is a leading cause of HIPAA penalties after a breach.
What a HIPAA Risk Assessment Actually Involves
A HIPAA risk assessment involves systematically finding where protected health information lives, identifying the threats to it, evaluating your current safeguards, and determining the likelihood and impact of each risk. The Department of Health and Human Services lays this out in its guidance on risk analysis, which is the authoritative description of what the Security Rule expects. In practice it means mapping every place data is stored or moves, from servers and laptops to cloud services and email, then documenting the threats and vulnerabilities to each, assessing whether existing controls are sufficient, and recording the reasoning.
Many organizations mistakenly believe a simple vulnerability scan can replace a HIPAA Risk Assessment, but the assessment involves a comprehensive analysis of PHI exposure and safeguards. It does not. A scan finds technical weaknesses, which is useful input, but the risk assessment is the broader analytical exercise of weighing those weaknesses against the data they expose and the safeguards in place. The federal government even offers a free security risk assessment tool to help smaller organizations work through the process, which underscores that the assessment is a structured analysis, not a single product you can purchase. Our cybersecurity compliance work treats it as exactly that kind of analysis, grounded in where your data actually is.
The Difference Between a Risk Assessment and an IT Audit
Unlike a general IT audit, a HIPAA Risk Assessment specifically evaluates PHI-related controls against the Security Rule, ensuring compliance and targeted protection. This matters because organizations sometimes assume their routine IT review covers HIPAA, then discover during an investigation that it never analyzed PHI risk in the terms the rule requires. The two are complementary, not interchangeable. A solid IT risk assessment provides much of the technical groundwork, but it has to be framed around protected health information to meet the HIPAA obligation.
Who Is Required to Conduct One
Two groups are required to conduct a HIPAA risk assessment: covered entities and business associates. Understanding which one you are, and that the obligation can reach you indirectly, is where many organizations are caught off guard.
Covered Entities
Covered entities are the organizations most people associate with HIPAA: healthcare providers who transmit health information electronically, health plans, and healthcare clearinghouses. If you are a medical practice, a hospital, a dental office, or a health insurer, you are a covered entity and the risk-assessment requirement applies directly to you. There is little ambiguity here, and the obligation is long-standing. The trap for covered entities is not whether the rule applies but whether their assessment is current and genuine rather than a stale document from years ago. A practice that completed a thorough assessment when it opened, then added a new patient portal, switched cloud vendors, and onboarded a telehealth platform without revisiting it, has an assessment that no longer describes reality, which in an investigation is treated much like having none at all.
Business Associates
Business associates are the group most likely to be surprised, because they are not healthcare organizations themselves but handle protected health information on behalf of one. Business associates must also perform a HIPAA Risk Assessment when handling PHI on behalf of a covered entity to remain compliant and safeguard sensitive data. This sweeps in IT providers, cloud hosts, billing companies, law firms, and many others. The obligation flows down by contract through a business associate agreement, and a company can carry it without ever thinking of itself as being in healthcare. We see this often with technology vendors who serve a medical client and do not realize HIPAA now applies to them. For these companies, handling PHI in the cloud raises specific obligations we cover in our look at HIPAA-compliant cloud solutions.

How Often and What Happens If You Skip It
To stay compliant, your organization should repeat a HIPAA Risk Assessment regularly and update it whenever new technology, processes, or events affect protected health information. While HIPAA does not name a fixed calendar interval, the Department of Health and Human Services makes clear that assessments must be ongoing, reviewed periodically and updated whenever you introduce new technology, change business processes, or experience an event that affects PHI. In practice, most organizations treat it as at least an annual exercise, with additional reviews triggered by significant changes. Treating it as a once-and-done task is the failure mode that the living-process framing is meant to prevent. Continuous approaches, including AI-driven risk monitoring for HIPAA compliance, are emerging precisely because point-in-time assessments leave gaps between reviews.
The consequences of skipping or faking the assessment are serious. When a breach occurs and federal investigators examine what happened, the absence of a thorough, current risk assessment is one of the most common findings behind significant penalties. The objection that a small practice is unlikely to be investigated misjudges the trigger: investigations frequently follow a breach or a complaint, not a random check, and small organizations breach too. The honest position is that the assessment is both a legal requirement and the practical foundation for actually protecting patient data, which is the point of the rule in the first place.
Frequently Asked Questions
Is a HIPAA risk assessment legally required?
Yes, a HIPAA risk assessment is legally required under the HIPAA Security Rule for both covered entities and business associates. It is not a best practice you can choose to skip. The Department of Health and Human Services treats it as a foundational obligation, and its absence is a leading factor in penalties assessed after breaches, so meeting the requirement genuinely is both a legal and a practical necessity.
Does my IT company need to do a HIPAA risk assessment?
If your IT company creates, receives, stores, or transmits protected health information on behalf of a healthcare client, then yes, it is a business associate and must conduct its own HIPAA risk assessment. The obligation flows down through a business associate agreement and applies even though the IT company is not itself a healthcare provider. Many technology vendors are surprised to learn HIPAA reaches them this way.
How often should a HIPAA risk assessment be done?
A HIPAA risk assessment should be done regularly and updated whenever you adopt new technology, change processes, or experience an event affecting protected health information. HIPAA does not set a fixed interval, but most organizations treat it as at least annual, with extra reviews after significant changes. The key is that it is an ongoing process, not a one-time document filed away and forgotten.
Is a vulnerability scan the same as a HIPAA risk assessment?
No, a vulnerability scan is not the same as a HIPAA risk assessment. A scan finds technical weaknesses and is useful input, but the risk assessment is the broader analysis of where protected health information lives, what threatens it, and whether your safeguards are adequate. Relying on a scan alone leaves the core analytical requirement unmet, which is a common and costly misunderstanding.
Talk to a Team About Your HIPAA Risk Assessment
A HIPAA risk assessment is the structured analysis that finds the risks to your protected health information and tests whether your safeguards actually hold, and it is required of both healthcare organizations and the business associates who serve them. The mistake that catches organizations is not ignoring it outright but treating it as a one-time checkbox, when the rule expects a living process kept current as your systems and workflows change. Getting it right protects your patients and your organization at the same time, which is exactly what the requirement intends. If you want help conducting a genuine, defensible HIPAA risk assessment or confirming whether the obligation applies to you, book a free strategy call with the Mindcore team.
HIPAA Risk Assessment and Healthcare Compliance Expertise from Matt Rosenthal
Matt Rosenthal, CEO of Mindcore Technologies, has over 30 years of experience helping healthcare organizations and their business associates conduct HIPAA risk assessments that satisfy federal requirements as a living, current analysis rather than a stale document filed away after a one-time review. He has seen firsthand how covered entities that completed thorough assessments years ago, then added patient portals, switched cloud vendors, and onboarded telehealth platforms without revisiting them, carry assessments that no longer describe reality, which investigators treat as equivalent to having none at all. Matt leads a team that maps protected health information across every system and workflow, evaluates safeguard adequacy against the Security Rule, and builds the documentation that holds up when an investigation or audit follows a breach.

