The security risk analysis, solo edition
Summary
You can do it yourself with the free Security Risk Assessment Tool that ONC and OCR publish for small practices. The analysis is a repeatable method, not a certificate you buy: inventory everywhere electronic PHI lives, name the threats to it, rate each risk by likelihood and impact, document your findings, and build a plan to fix the gaps. Then redo it after any significant change and keep every dated version.
By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.
What the security risk analysis is, and why you can't skip it
The security risk analysis is the assessment at the center of the Security Rule: a documented review of the risks to your electronic protected health information and the safeguards that address them, scaled to a practice of your size 1Ref 1HHS Office for Civil Rights (2026).Summary of the HIPAA Security Rule.The Security Rule requires a risk analysis and administrative, physical, and technical safeguards, plus a risk management process, scaled to practice size.. It is a requirement, not a recommendation — the operative rule text makes the risk analysis the first thing you do before you can reasonably choose the rest of your safeguards 2Ref 2Office of the Federal Register (2026).45 CFR Part 164 — Security and Privacy.The operative Security Rule text makes the risk analysis a required, foundational step before other safeguards are selected..
You can genuinely do it yourself. ONC and OCR publish a free Security Risk Assessment Tool built for small practices, which structures the whole exercise so you do not start from a blank page 3Ref 3Office of the National Coordinator / ASTP (2026).Security Risk Assessment Tool.ONC and OCR publish a free, small-practice Security Risk Assessment Tool that guides the analysis and produces a saved, dated report.. What the analysis is not: a product you purchase. No vendor's 'HIPAA certified' badge substitutes for performing and documenting the analysis, because the analysis is about your practice's specific data, devices, and gaps — not a generic checklist someone sells you.
Step 1 — inventory every place ePHI lives
Step one is an honest inventory of every place electronic PHI lives, because you cannot protect data you have not located. For a solo practice that list is longer than it feels: your EHR, your laptop and phone, your email — including how you handle email and sms with patients — your telehealth platform, cloud storage and backups, any scanning app, and the thumb drive in a drawer. Walk each one and note what PHI it holds and who can reach it.
Inventory surfaces a subtlety worth catching early: not every tool you use is covered by HIPAA. A consumer app or vendor that holds health data but is not a business associate can fall under the FTC's Health Breach Notification Rule instead, which reaches non-HIPAA health tools 4Ref 4Federal Trade Commission (2026).Health Breach Notification Rule.Health tools that fall outside HIPAA can be covered by the FTC's Health Breach Notification Rule, which matters when inventorying non-business-associate apps.. The point of naming these now is that a tool outside HIPAA is not a tool outside all rules — it just answers to a different one, and you want to know which before an incident, not after.
Step 2 — name the threats and vulnerabilities
With the inventory in hand, step two names what could go wrong for each location — the threats, and the vulnerabilities that let them land. Threats are the events: a lost or stolen device, a phishing email, ransomware, an unlocked screen, a misdirected message, a vendor breach. Vulnerabilities are the weaknesses that let a threat cause harm: no encryption, a shared password, an untrained habit, a missing auto-lock.
You do not need a security background to do this well. For each item in your inventory, ask two plain questions — what bad thing could happen to this data, and what about my current setup would let it happen. Writing the pairs down is the work; a laptop with no disk encryption paired with the threat of theft is exactly the kind of finding the analysis exists to surface before the theft does it for you.
Step 3 — rate likelihood and impact, and document it
Step three rates each risk you found by how likely it is and how much harm it would cause, then records the result. A stolen unencrypted laptop is high likelihood over a career and high impact; a stolen encrypted one is far lower impact because the data is unreadable. You are not aiming for a precise score — you are sorting risks into rough tiers so you know what to fix first and what can wait.
Documentation is not the afterthought here; it is the deliverable. The analysis only counts if it exists on paper, or in the tool's saved file, with a date — because in an investigation an undocumented analysis is treated as no analysis. Record what you inventoried, the threats and vulnerabilities you identified, your rating, and the date. That dated record is exactly what you produce if anyone ever asks to see the analysis.
Step 4 — turn findings into a risk management plan
The analysis tells you where the risk is; the risk management plan is where you reduce it, and the Security Rule requires both 1Ref 1HHS Office for Civil Rights (2026).Summary of the HIPAA Security Rule.The Security Rule requires a risk analysis and administrative, physical, and technical safeguards, plus a risk management process, scaled to practice size.. This is the step practices skip: they run the assessment, file it, and never act on the high-risk items. For a solo practice the plan is short — a list of the top gaps, the fix for each, and a target date — and most fixes are cheap: turn on disk encryption, enable multi-factor authentication, set devices to auto-lock, sign the missing BAAs.
Think of it as the 30-minute hardening you schedule off the back of the analysis. Address the highest-likelihood, highest-impact gaps first, and note what you decided to accept and why. A documented decision to accept a small residual risk is defensible; an unaddressed high risk you clearly identified and ignored is the opposite. The contingency plan for when a device fails or data is lost belongs here too, as part of the required safeguards rather than an optional extra.
Use the free SRA Tool rather than a blank page
If the four steps feel abstract, the free SRA Tool turns them into a guided questionnaire. It walks you through the inventory, the threats and vulnerabilities, and the safeguards question by question, flags likely gaps, and produces a saved, dated report you can keep as your documentation 3Ref 3Office of the National Coordinator / ASTP (2026).Security Risk Assessment Tool.ONC and OCR publish a free, small-practice Security Risk Assessment Tool that guides the analysis and produces a saved, dated report.. It runs on your own computer, so your answers are not sent anywhere, and it is built to the scale of a small practice rather than a hospital system.
Using the tool does not outsource your judgment — it structures it. You still answer honestly about your own devices and habits, and you still act on what it surfaces. But it removes the two things that stall solo practices most: the blank page, and the fear that you are doing it wrong. Following the tool end to end is itself a defensible analysis, and the report it saves is the record that proves you did it.
When to redo it — after changes, and the ransomware trap
Redo the analysis after anything that changes your risk picture — a new EHR, a move to telehealth, a lost device, a new vendor — and on a regular cadence even without a triggering event. A risk analysis from three EHRs ago is not current, and OCR treats a stale or missing analysis as the root failure behind most enforcement actions, including against very small practices 5Ref 5HHS Office for Civil Rights (2026).HIPAA Compliance and Enforcement.OCR treats a stale or missing risk analysis as a root failure behind many enforcement actions, including against very small practices..
Ransomware is the sharpest illustration of why the analysis matters both before and after an incident. OCR's guidance treats a ransomware encryption of ePHI as a presumed breach unless a documented risk assessment shows a low probability that the data was compromised 6Ref 6HHS Office for Civil Rights (2016).FACT SHEET: Ransomware and HIPAA.A ransomware encryption of ePHI is a presumed breach unless a documented risk assessment shows a low probability of compromise.. In other words, the assessment you keep current is also the document that can keep an incident from automatically becoming a reportable breach — the lost laptop and the ransomware case both turn on whether you can show what protection was in place.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThe Security Rule requires a risk analysis and administrative, physical, and technical safeguards, plus a risk management process, scaled to practice size.
- 2.Office of the Federal Register (2026). 45 CFR Part 164 — Security and Privacy. eCFR. link ✓The operative Security Rule text makes the risk analysis a required, foundational step before other safeguards are selected.
- 3.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. link ✓ONC and OCR publish a free, small-practice Security Risk Assessment Tool that guides the analysis and produces a saved, dated report.
- 4.Federal Trade Commission (2026). Health Breach Notification Rule. Federal Trade Commission (FTC). link ✓Health tools that fall outside HIPAA can be covered by the FTC's Health Breach Notification Rule, which matters when inventorying non-business-associate apps.
- 5.HHS Office for Civil Rights (2026). HIPAA Compliance and Enforcement. U.S. Department of Health and Human Services. linkOCR treats a stale or missing risk analysis as a root failure behind many enforcement actions, including against very small practices.
- 6.HHS Office for Civil Rights (2016). FACT SHEET: Ransomware and HIPAA. U.S. Department of Health and Human Services. link ✓A ransomware encryption of ePHI is a presumed breach unless a documented risk assessment shows a low probability of compromise.
https://www.gale.care/for-providers/hip-security-risk-analysis-diy · 6 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.