HIPAA Security Risk Assessment Template, 2026 Edition
A working risk assessment template aligned to 45 CFR §164, covering ePHI asset inventory through a risk register and remediation tracker.
What this covers
The most-cited HIPAA Security Rule violation in every year of OCR enforcement is not a failed access control. It is inadequate or absent risk analysis documentation: the assessment itself. This template exists to close that gap. It walks an organization from scope definition and ePHI asset inventory through administrative, physical and technical safeguards, and ends in a risk register with owners, target dates and status, which is the artifact OCR actually asks to see.
Key figures
What is inside
- Section 1 · Organizational scope and assessment metadata
- Establishes what is in scope and who performed the assessment. An assessment with no defined scope is not defensible.
- Section 2 · ePHI asset inventory
- Aligned to 45 CFR §164.308(a)(1). You cannot assess risk to data you have not inventoried.
- Sections 4–6 · Administrative, physical and technical safeguards
- Walks §164.308, §164.310 and §164.312 in turn, with a rating per control rather than a pass/fail on the section.
- Section 9 · Risk register and remediation tracker
- Each finding gets an ID, a CFR citation, a priority, an owner, a target date and a status. This is the section that turns an assessment into evidence of a program.
The point most teams miss
OCR does not penalize organizations for having risk. It penalizes them for being unable to show they looked. A completed register with owners and dates is worth more at audit than a clean-looking assessment with no follow-through.
Provided as a practitioner resource. It does not constitute legal advice.
Common questions
Who needs to complete a HIPAA security risk assessment?
Both covered entities and business associates. Section 1 of the template asks the organization to declare which it is, because the scope of the assessment differs and an assessment with no declared scope is not defensible at audit.
How often should the risk assessment be repeated?
The Security Rule requires it to be kept current rather than performed once. In practice that means an annual cycle plus a refresh whenever systems, vendors or workforce arrangements change materially.
What does OCR actually look for?
Documentation that the analysis happened and that findings were tracked to closure. Inadequate or absent risk analysis is the most-cited HIPAA violation in every year OCR enforces, which is why the template ends in a risk register with IDs, CFR citations, owners, target dates and status.
Get the full document
This page summarizes the guide. The full 12-page PDF includes the complete tables, checklists and worked detail.