The HIPAA Security Risk Analysis: your Montana practice's #1 must-do task
Every practice that handles patient data needs a HIPAA Security Risk Analysis. What a real one includes, how often to do it, and why a one-time report isn't enough.
By Big Sky Support

If OCR ever looks closely at your practice, one of the first requests will be your most recent risk analysis and how you used it.
A HIPAA Security Risk Analysis isn't a paperwork exercise. It's the task that tells you, in black and white, whether your practice would hold up through a cyber incident or an OCR investigation. OCR consistently names failure to conduct an accurate and thorough risk analysis as one of the most common Security Rule violations it finds.
For a practice manager or physician-owner, the risk analysis is your practice's annual physical for cybersecurity and HIPAA. Skip it, and the silent problems eventually show up in the worst possible way.
Why the risk analysis is non-negotiable
HHS and OCR have been clear for years that an accurate and thorough risk analysis is the foundation of Security Rule compliance.
- OCR has called inadequate risk analysis one of its top enforcement issues, and it has led to settlements and corrective action plans for practices of every size.
- HHS has proposed a major update to the Security Rule that would make risk analysis requirements more specific. It hasn't been finalized, and the current rule, which already requires a thorough risk analysis, remains fully in force.
- Guidance and industry practice point to at least an annual risk analysis, plus a reassessment after major changes or incidents.
In plain language: if OCR ever looks closely at your practice, one of the first requests will be to see your most recent risk analysis and how you used it.
What a real risk analysis includes
A compliant risk analysis isn't a spreadsheet of computers, and it isn't a vulnerability scan. A scan finds technical weaknesses on your network. A risk analysis is a structured review of how your practice actually handles patient data across administrative, physical, and technical safeguards, and where things can go wrong. At a minimum, it has to:
- Identify where ePHI lives and moves. Your EHR, practice management system, imaging, patient portal, email, cloud services, mobile devices, backups, business associates, and remote access.
- Assess threats and vulnerabilities. For each system and process, look at realistic threats, like phishing, ransomware, lost laptops, misconfigurations, and vendor failures, and at weaknesses, like missing MFA, weak access controls, and outdated software.
- Estimate likelihood and impact. Not all risks are equal. Consider how likely each threat is and what it would mean for patients, operations, and compliance if it happened.
- Evaluate existing controls. Review how your administrative, physical, and technical safeguards actually perform against those risks, not just whether they exist on paper.
- Document remediation plans. For each significant risk, define what you'll do, who owns it, and by when. Then track completion and reassess.
OCR is clear that this isn't a one-time project. It's part of an ongoing risk management process.
Why practices struggle to do it alone
If you run a small or mid-sized clinic, you're not imagining it: a real risk analysis is a lot of work. The common pain points are no dedicated compliance or security staff, trouble mapping everywhere patient data lives (especially in the cloud, on mobile devices, and with vendors), technical frameworks that read like a foreign language, and reports that show problems without helping you prioritize or fix them.
So many practices either skip the risk analysis and hope nobody asks, or pay for a one-time assessment that goes out of date quickly and leaves them with a long list and no help working through it.
Neither approach meets OCR's expectation of ongoing, documented risk management.
How we approach the risk analysis
We treat the risk analysis as the first step in a continuous cycle, not a box to check.
- Mapping patient data as it really exists. We inventory every device, system, and vendor that touches PHI, including the ones nobody remembers signing up for, plus shadow IT and informal workarounds.
- External exposure testing. We check what's reachable from the internet, so the analysis reflects real exposure, not just what's on paper.
- Written findings ranked by risk. Plain-English findings tied to real threats like phishing, ransomware, EHR downtime, and vendor breaches, so leadership can see which fixes matter most.
- Kept current, not rebuilt when someone asks. Your risk analysis is refreshed annually and whenever something material changes, with policies written to match how your practice operates, training tracked by name, BAAs calendared with renewal dates, and a quarterly 30-minute review with a one-page status you can hand to your board, insurer, attorney, or a payer.
- Remediation you approve first. Your own IT team can work from the fix list. If you'd rather we do the fixing, that work is scoped and quoted separately, and nothing starts until you approve it.
- Evidence ready for scrutiny. If you face OCR, an insurer review, or a breach investigation, you'll have a dated trail of risk analysis, remediation, and training records that shows continuous compliance effort.
The goal is a risk analysis that strengthens your practice, not one you dread.
Common questions
Short answers to the questions we hear most about this topic.
Does a small clinic really have to do a HIPAA Security Risk Analysis?
Yes. The HIPAA Security Rule applies to every covered entity and business associate, regardless of size. OCR has fined small practices for failing to conduct a proper risk analysis, and it has focused enforcement on this area specifically because it's missing so often.
Is a self-assessment tool enough for a HIPAA risk analysis?
Self-assessment tools, including the one from HHS, can be a useful starting point. But they don't automatically meet regulatory expectations, they're easy to leave incomplete, and they often miss risks specific to your environment unless someone experienced helps apply them.
OCR holds you responsible for the quality and completeness of your risk analysis, whether or not you used a tool.
How often should we perform a HIPAA Security Risk Analysis?
Current guidance and industry practice point to at least once every 12 months, and again after significant changes like a new EHR, a major cloud move, a merger, or new vendors, or after a serious incident. Once every few years isn't enough given how quickly threats and technology change.
What's the difference between a HIPAA risk analysis and a vulnerability scan?
A HIPAA Security Risk Analysis looks at all of your safeguards (administrative, physical, and technical) and how threats could affect patient data. A vulnerability scan is a technical test that looks for known weaknesses in systems and applications.
An effective HIPAA program uses scan results as input to the broader risk analysis, with remediation and retesting tied to what the scans find.
We paid for a HIPAA risk analysis last year. Are we covered?
You're better off than if you had nothing, but you're not done. OCR expects risk analysis to be ongoing, with periodic updates and evidence you acted on the findings. If your environment, threats, or vendors have changed since then, your risk picture has changed too.
A single static report, especially without a remediation plan, won't meet the continuous risk management standard OCR and insurers look for.
Terms used in this article
Plain definitions, so nothing above needs a second search.
Turn your risk analysis into a plan you can actually work.
Same day onsite for contract clients. Everyone else pays $165 an hour, with no emergency surcharge, and gets forensic imaging before remediation.
See HIPAA servicesAll articles