Guide

The security risk analysis, solo edition

Summary

You can do it yourself with the free Security Risk Assessment Tool that ONC and OCR publish for small practices. The analysis is a repeatable method, not a certificate you buy: inventory everywhere electronic PHI lives, name the threats to it, rate each risk by likelihood and impact, document your findings, and build a plan to fix the gaps. Then redo it after any significant change and keep every dated version.

By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.

What the security risk analysis is, and why you can't skip it

The security risk analysis is the assessment at the center of the Security Rule: a documented review of the risks to your electronic protected health information and the safeguards that address them, scaled to a practice of your size 1. It is a requirement, not a recommendation — the operative rule text makes the risk analysis the first thing you do before you can reasonably choose the rest of your safeguards 2.

You can genuinely do it yourself. ONC and OCR publish a free Security Risk Assessment Tool built for small practices, which structures the whole exercise so you do not start from a blank page 3. What the analysis is not: a product you purchase. No vendor's 'HIPAA certified' badge substitutes for performing and documenting the analysis, because the analysis is about your practice's specific data, devices, and gaps — not a generic checklist someone sells you.

Step 1 — inventory every place ePHI lives

Step one is an honest inventory of every place electronic PHI lives, because you cannot protect data you have not located. For a solo practice that list is longer than it feels: your EHR, your laptop and phone, your email — including how you handle email and sms with patients — your telehealth platform, cloud storage and backups, any scanning app, and the thumb drive in a drawer. Walk each one and note what PHI it holds and who can reach it.

Inventory surfaces a subtlety worth catching early: not every tool you use is covered by HIPAA. A consumer app or vendor that holds health data but is not a business associate can fall under the FTC's Health Breach Notification Rule instead, which reaches non-HIPAA health tools 4. The point of naming these now is that a tool outside HIPAA is not a tool outside all rules — it just answers to a different one, and you want to know which before an incident, not after.

Step 2 — name the threats and vulnerabilities

With the inventory in hand, step two names what could go wrong for each location — the threats, and the vulnerabilities that let them land. Threats are the events: a lost or stolen device, a phishing email, ransomware, an unlocked screen, a misdirected message, a vendor breach. Vulnerabilities are the weaknesses that let a threat cause harm: no encryption, a shared password, an untrained habit, a missing auto-lock.

You do not need a security background to do this well. For each item in your inventory, ask two plain questions — what bad thing could happen to this data, and what about my current setup would let it happen. Writing the pairs down is the work; a laptop with no disk encryption paired with the threat of theft is exactly the kind of finding the analysis exists to surface before the theft does it for you.

Step 3 — rate likelihood and impact, and document it

Step three rates each risk you found by how likely it is and how much harm it would cause, then records the result. A stolen unencrypted laptop is high likelihood over a career and high impact; a stolen encrypted one is far lower impact because the data is unreadable. You are not aiming for a precise score — you are sorting risks into rough tiers so you know what to fix first and what can wait.

Documentation is not the afterthought here; it is the deliverable. The analysis only counts if it exists on paper, or in the tool's saved file, with a date — because in an investigation an undocumented analysis is treated as no analysis. Record what you inventoried, the threats and vulnerabilities you identified, your rating, and the date. That dated record is exactly what you produce if anyone ever asks to see the analysis.

Step 4 — turn findings into a risk management plan

The analysis tells you where the risk is; the risk management plan is where you reduce it, and the Security Rule requires both 1. This is the step practices skip: they run the assessment, file it, and never act on the high-risk items. For a solo practice the plan is short — a list of the top gaps, the fix for each, and a target date — and most fixes are cheap: turn on disk encryption, enable multi-factor authentication, set devices to auto-lock, sign the missing BAAs.

Think of it as the 30-minute hardening you schedule off the back of the analysis. Address the highest-likelihood, highest-impact gaps first, and note what you decided to accept and why. A documented decision to accept a small residual risk is defensible; an unaddressed high risk you clearly identified and ignored is the opposite. The contingency plan for when a device fails or data is lost belongs here too, as part of the required safeguards rather than an optional extra.

Use the free SRA Tool rather than a blank page

If the four steps feel abstract, the free SRA Tool turns them into a guided questionnaire. It walks you through the inventory, the threats and vulnerabilities, and the safeguards question by question, flags likely gaps, and produces a saved, dated report you can keep as your documentation 3. It runs on your own computer, so your answers are not sent anywhere, and it is built to the scale of a small practice rather than a hospital system.

Using the tool does not outsource your judgment — it structures it. You still answer honestly about your own devices and habits, and you still act on what it surfaces. But it removes the two things that stall solo practices most: the blank page, and the fear that you are doing it wrong. Following the tool end to end is itself a defensible analysis, and the report it saves is the record that proves you did it.

When to redo it — after changes, and the ransomware trap

Redo the analysis after anything that changes your risk picture — a new EHR, a move to telehealth, a lost device, a new vendor — and on a regular cadence even without a triggering event. A risk analysis from three EHRs ago is not current, and OCR treats a stale or missing analysis as the root failure behind most enforcement actions, including against very small practices 5.

Ransomware is the sharpest illustration of why the analysis matters both before and after an incident. OCR's guidance treats a ransomware encryption of ePHI as a presumed breach unless a documented risk assessment shows a low probability that the data was compromised 6. In other words, the assessment you keep current is also the document that can keep an incident from automatically becoming a reportable breach — the lost laptop and the ransomware case both turn on whether you can show what protection was in place.

Common questions

No. A solo practice can perform its own risk analysis using the free SRA Tool, which is built for exactly that. You are welcome to hire help, and some practices do for the first one, but the obligation and the documentation remain yours. What you cannot do is skip the analysis or treat a purchased product as a substitute for actually assessing your own setup.

No. No product makes you compliant, and a 'HIPAA compliant' or 'HIPAA certified' badge on software does not perform your risk analysis. Compliant tools make it easier to build safeguards, but the analysis is about your specific data, devices, and habits — where ePHI lives in your practice and what could go wrong. Only you can inventory that, and only a documented, dated assessment satisfies the requirement.

Redo it after any change that shifts your risk — a new EHR, a move to telehealth, a lost device, a new vendor — and on a regular cadence, such as annually, even when nothing dramatic happens. There is no substitute for currency: an analysis from several systems ago is treated in an investigation as no analysis at all. Keep each dated version rather than overwriting the last.

The risk analysis finds and rates the risks to your ePHI; risk management is the plan and the actions that reduce them. The Security Rule requires both, and skipping the second is the common failure — practices run the assessment, file it, and never fix the high-risk gaps. Treat the analysis as the diagnosis and the management plan as the treatment you actually carry out.

If you are a covered entity that creates, receives, maintains, or transmits electronic PHI, yes — even a small cash-pay practice. The Security Rule scales its expectations to your size, so your analysis can be short and your safeguards modest, but the analysis itself is not optional. If you genuinely handle no electronic PHI at all, confirm your covered-entity status first, because that is the threshold question.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThe Security Rule requires a risk analysis and administrative, physical, and technical safeguards, plus a risk management process, scaled to practice size.
  2. 2.Office of the Federal Register (2026). 45 CFR Part 164 — Security and Privacy. eCFR. linkThe operative Security Rule text makes the risk analysis a required, foundational step before other safeguards are selected.
  3. 3.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. linkONC and OCR publish a free, small-practice Security Risk Assessment Tool that guides the analysis and produces a saved, dated report.
  4. 4.Federal Trade Commission (2026). Health Breach Notification Rule. Federal Trade Commission (FTC). linkHealth tools that fall outside HIPAA can be covered by the FTC's Health Breach Notification Rule, which matters when inventorying non-business-associate apps.
  5. 5.HHS Office for Civil Rights (2026). HIPAA Compliance and Enforcement. U.S. Department of Health and Human Services. linkOCR treats a stale or missing risk analysis as a root failure behind many enforcement actions, including against very small practices.
  6. 6.HHS Office for Civil Rights (2016). FACT SHEET: Ransomware and HIPAA. U.S. Department of Health and Human Services. linkA ransomware encryption of ePHI is a presumed breach unless a documented risk assessment shows a low probability of compromise.

https://www.gale.care/for-providers/hip-security-risk-analysis-diy · 6 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)