What's actually in a HIPAA Security Risk Assessment
Why "we have antivirus" doesn't satisfy HIPAA, and what actually has to be in a Security Risk Assessment an auditor will accept.
It's a requirement, not a nice-to-have
The HIPAA Security Rule requires every covered entity — including a dental or medical practice — to conduct an accurate and thorough assessment of the risks to electronic protected health information (ePHI). This isn't optional paperwork: it's the first standard under the Rule's administrative safeguards, and it's usually the first document an auditor or a cyber-insurance carrier asks to see.
A practice that has never done one, or did one years ago and never updated it, is the single most common HIPAA gap we see — more common than any specific technical failure.
What it actually has to cover
A real SRA looks at where ePHI lives and moves — practice management software, imaging systems, email, backups, staff devices — and evaluates it across three categories the Rule names explicitly: administrative safeguards (policies, training, who can access what), physical safeguards (facility access, device security), and technical safeguards (encryption, access controls, audit logs).
For each area, it documents what could go wrong, how likely and how serious that is, what's already in place, and what isn't. That gap list becomes the practice's risk management plan — the assessment's whole value is in what it tells you to fix next, not in the document itself.
Why "we have antivirus" doesn't answer it
Antivirus is one control, on one category, out of many. An assessment that only looked at endpoint protection would miss whether backups are actually tested, whether a departing employee's access gets revoked the same day, or whether the practice management vendor itself has a signed Business Associate Agreement. A documented SRA has to show the whole picture was actually looked at — which is what "documented" is doing in "documented Security Risk Assessment": a real auditor wants to see the analysis, not just be told it happened.
Thirty minutes, no obligation.