← Back to Blog

HIPAA ComplianceSeptember 28, 2026By Mark H.

You Filled Out a HIPAA Risk Assessment Template Once: But Have You Actually Run One?

Ask most small healthcare practice owners if they've done a HIPAA risk assessment, and you'll almost always hear "yes." Ask when, and the answer is usually a lot less confident. Often it was a one-time checklist filled out when the practice opened, handed over by an EHR vendor, or completed years ago during a compliance scare that has since faded from memory.

The problem is that a Security Risk Assessment (SRA) isn't a form you fill out once and file away. It's a requirement under the HIPAA Security Rule that's meant to be revisited regularly and updated every time something meaningful changes in how your practice handles protected health information (PHI).

What the Security Rule Actually Requires

The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of PHI. That's not a one-time event. New employees, new software, a new EHR module, a new remote work arrangement, a new vendor with access to your systems — each of these changes your risk profile and should trigger a fresh look.

The Office for Civil Rights (OCR) has been explicit in enforcement actions that a "checklist" exercise does not satisfy this requirement. Assessments need to identify where PHI actually lives, how it flows through your systems, and what specific technical, physical, and administrative safeguards are or aren't in place.

Why a One-Time Checklist Isn't Enough

A generic template can't account for the reality of your specific practice: which EHR you use, whether staff access patient records from home, how your backups are configured, or whether your billing vendor has more access than they actually need. Templates are a starting point, not a substitute for looking at your actual environment.

This gap becomes painfully clear after an incident. If a breach occurs and OCR investigates, one of the first things they ask for is your most recent risk assessment and the remediation plan that followed it. A three-year-old generic template with no follow-through is not a defensible answer, and it can turn a manageable incident into a much more expensive one.

What a Real Risk Assessment Looks Like

A proper SRA maps out where PHI is created, received, stored, and transmitted across your practice, evaluates the safeguards protecting it at each point, and documents specific, prioritized gaps with a plan to close them. It should cover technical controls like encryption and access management, physical safeguards like device security, and administrative pieces like policies and workforce training. Just as important, it needs to be revisited at least annually and any time your systems or workflows change.

The Cost of Skipping It

Skipping ongoing risk assessments doesn't just create compliance risk — it means real vulnerabilities go unnoticed for years. Practices that treat this as a one-time exercise often discover, only after a breach or an audit, that they had unencrypted laptops, former employees with active logins, or vendors handling PHI without a signed Business Associate Agreement. These are exactly the kinds of gaps a current risk assessment is designed to catch before they become expensive problems.

How Consolidated IT Solutions Can Help

Most small healthcare practices don't lack the intent to be HIPAA-compliant — they lack the time, in-house expertise, and dedicated IT resources to keep up with it. Consolidated IT Solutions helps practices like yours close this gap with:

Schedule your free HIPAA Gap Assessment and find out exactly where your practice stands before a breach or an audit forces the question.