Home / Services / Security Assessments / HIPAA HITECH Risk Assessment

HIPAA HITECH Risk Assessment

A plain-English security risk analysis that satisfies the HIPAA Security Rule and shows you exactly where your patient data is exposed — and how to fix it.

If your business creates, stores, or transmits protected health information, the HIPAA Security Rule requires you to conduct an accurate and thorough risk analysis. This is not optional, and it is not a checkbox exercise. It is the single most-cited failing in enforcement actions, and for good reason: you cannot protect patient data you have not mapped, and you cannot prioritize fixes for risks you have not measured. Our HIPAA HITECH Risk Assessment gives you that map and that measurement, in language you and your staff can actually act on.

We assess your organization against the administrative, physical, and technical safeguards defined in the HIPAA Security Rule (45 CFR Part 164), using the risk-assessment methodology described in NIST Special Publication 800-66 as our guide. That means we look at more than firewalls. We look at how PHI flows through your practice — where it enters, where it lives, who touches it, which vendors and business associates handle it, and where it leaves. Then we identify the threats and vulnerabilities that put it at risk and rate each one by likelihood and impact, so you know what to fix first.

The HITECH Act raised the stakes by strengthening breach notification requirements and expanding enforcement, including direct liability for business associates. A serious, documented risk analysis is your foundation for meeting those obligations. It also protects you in a very practical way: if an incident ever occurs, regulators and cyber-insurance carriers will ask for evidence that you assessed your risks and acted on them. This engagement produces exactly that evidence.

We are a senior-led firm, which means an experienced assessor does your work — not a junior analyst running a scanner and handing you a raw export. We translate technical findings into business risk, prioritize remediation by what actually moves the needle, and give you a corrective action plan you can execute with the staff and budget you have. The goal is a practice that is genuinely more secure, with the documentation to prove it.

What you get

  • Security Rule gap analysis a safeguard-by-safeguard review against 45 CFR Part 164 covering administrative, physical, and technical controls.
  • PHI data-flow mapping a clear picture of where protected health information is created, received, stored, and transmitted across your systems and vendors.
  • Risk register a prioritized list of identified threats and vulnerabilities, each rated by likelihood and potential impact to your patients and practice.
  • Corrective action plan specific, sequenced remediation steps with plain-English guidance on who does what and in what order.
  • Business associate review an assessment of how your vendors and partners handle PHI and whether your agreements reflect their obligations.
  • Written risk-analysis report the documented analysis auditors, regulators, and cyber-insurance carriers expect to see, retained as evidence of due diligence.
  • Findings review session a walkthrough with your team so the results are understood and the next steps are clear, not just filed away.

Get started

// How we work

Our methodology

  1. 1Scoping & PHI discoveryWe start by defining what is in scope and mapping how protected health information flows through your practice — the systems, applications, devices, locations, and vendors that create, receive, store, or transmit it.
  2. 2Safeguard review & interviewsWe evaluate your administrative, physical, and technical safeguards against the Security Rule, combining documentation review, configuration checks, and interviews with the people who run your systems and workflows.
  3. 3Threat & vulnerability analysisWe identify the realistic threats to your PHI and the vulnerabilities that would let them succeed, drawing on the NIST SP 800-66 methodology to keep the analysis structured and thorough.
  4. 4Risk rating & prioritizationWe rate each identified risk by likelihood and potential impact, producing a risk register that separates the issues demanding immediate attention from those you can plan for over time.
  5. 5Reporting & corrective action planWe deliver the documented risk analysis and a sequenced remediation plan, then walk your team through the findings so you leave with clear priorities and a realistic path to close them.
// FAQ

Frequently asked questions

Do we really need a HIPAA risk assessment if we are a small practice?
Yes. The Security Rule applies to every covered entity and business associate that handles PHI, regardless of size. A solo practice and a hospital have the same obligation to conduct a risk analysis, though the scope and effort scale with your environment. Small practices are frequently targeted precisely because attackers assume their defenses are thinner, so the assessment is as much about real protection as it is about compliance.
Is a risk assessment the same as being HIPAA compliant?
No, and this is a common and costly misunderstanding. The risk analysis is one required element of the Security Rule, and it is the foundation for the rest. It tells you where your gaps are so you can build policies, implement safeguards, train staff, and manage risk over time. We deliver the analysis and a clear action plan; compliance is the ongoing program you build on top of it, and we can help you get there.
How often should we do this?
The Security Rule requires the risk analysis to be accurate and current, which in practice means it should be reviewed and updated regularly and whenever something material changes — a new electronic health record system, a move to the cloud, a merger, or a significant change in how you handle PHI. Many practices conduct a full assessment annually and revisit it after major changes. We will recommend a cadence that fits your environment.
Will this satisfy an auditor or the Office for Civil Rights?
Our assessment is built around the Security Rule requirements and the NIST SP 800-66 methodology that regulators reference, and it produces the documented, dated risk analysis and corrective action plan that demonstrate due diligence. We cannot speak for any specific auditor's judgment, but we deliver the substance and the paper trail that these reviews look for.
What is the difference between a risk assessment and a penetration test?
They answer different questions. A risk assessment is broad: it evaluates your policies, procedures, safeguards, and data flows against a standard to find gaps in how you manage risk. A penetration test is narrow and deep: it actively tries to exploit specific technical weaknesses to prove what an attacker could do. Many practices need both, and the risk assessment usually comes first because it tells you where deeper testing is warranted.
How much of our staff's time will this take?
Less than most people fear. We do the heavy lifting. We will need some interviews with the people who manage your systems and workflows, access to review configurations and documentation, and answers to questions about how PHI moves through your practice. We schedule these to minimize disruption, and a well-run engagement asks focused questions rather than open-ended homework.
We use a cloud EHR and outside IT. Does that cover us?
It helps, but it does not transfer your obligation. You remain responsible for the risk analysis even when vendors host your data or manage your systems. Your EHR provider and IT firm are business associates, and part of this engagement is evaluating how they handle PHI and whether your agreements and their controls are adequate. Outsourcing the work does not outsource the accountability.
What happens after you deliver the report?
You get a prioritized corrective action plan, and we walk your team through it so the path forward is clear. From there you can execute internally, lean on your IT provider, or engage us to help implement and verify fixes. The point of the assessment is action, not a binder on a shelf, so we make sure the next steps are realistic for your staff and budget.
Do you handle both technical and administrative safeguards?
Yes. A common weakness of scanner-only assessments is that they only see technical issues. The Security Rule is roughly two-thirds administrative and physical safeguards — policies, training, access management, contingency planning, facility controls. We assess all three categories, because a strong firewall does not help if a laptop full of PHI walks out an unlocked door.
Is our information kept confidential?
Yes. We handle your data and findings under strict confidentiality, and we are happy to sign a business associate agreement and any additional confidentiality terms your practice requires before the engagement begins. Everything we collect is used solely to perform the assessment and is protected accordingly.
// Related services

Explore related services

Ready to see where you really stand?

Get a free, no-pressure consultation. We'll walk your environment, flag the risks that matter, and show you a clear path forward.