Free compliance & forms tool

HIPAA Security Risk Assessment Questionnaire

A HIPAA risk assessment is an accurate and thorough look at the risks to the confidentiality, integrity and availability of electronic patient information, and the Security Rule requires it. This free HIPAA security risk assessment tool asks 37 questions across administrative, physical and technical safeguards, then prints a prioritized list of gaps. It is a screening aid; the official free SRA Tool is the next step.

Prepared by Prospyr · Reviewed October 3, 2026 · Free, no sign-up, runs in your browser

How the HIPAA security risk assessment works

A risk analysis has four jobs. Use them as the frame when you move from this questionnaire to your full assessment.

  1. Inventory. List where electronic PHI lives: EHR, email, phones, backups, vendors. The checkboxes at the top of the tool start that list.
  2. Find weaknesses. Compare each place to the Security Rule safeguards. The questions below do this at a screening level.
  3. Rate the risk. For each gap, judge how likely a problem is and how much harm it would cause.
  4. Act and document. Assign an owner and a date, then keep the paperwork for six years.

The tool covers step two and gives you a head start on steps one and four. Steps three and four are yours, which is why the printed summary has room for follow-up.

HIPAA risk assessment questions: the five areas this tool covers

  • Administrative safeguards (14 questions). Security official, risk analysis and management, access, training, incident response and backup plans.
  • Physical safeguards (7). Facility access, workstations, device disposal and reuse.
  • Technical safeguards (8). Unique logins, automatic logoff, encryption, audit controls, authentication and transmission security.
  • Business associates (4). Vendor list, signed agreements and what they must report to you.
  • Policies and documentation (4). Written policies, six-year retention and review.

Each question shows its 45 CFR citation and whether the specification is required or addressable, so the printout can go straight into your compliance binder.

Worked example: reading your gap list

A practice answers all 37 questions and marks 3 not applicable, leaving 34. It answers "in place" on 26, so 26 ÷ 34 = 76% in place. The 8 gaps sort like this:

  • High (3): no documented risk analysis, no risk management plan, and unsure whether anyone reviews audit logs. All three are required.
  • Medium (4): the sanction policy and business associate agreements are only partly done (required), and nobody has tested a backup restore or turned on encryption for laptops (addressable).
  • Low (1): automatic logoff covers desktops but not tablets.

The first two high items are the same requirement, so the practice starts there: run the SRA Tool, record the results, and write the plan. The percentage is a progress marker, not a compliance score.

HIPAA risk assessment tool vs. the official SRA Tool

The HHS and ONC Security Risk Assessment Tool is free and built for small and medium providers. It walks through multiple-choice questions, threats and vulnerabilities, and asset and vendor management. It takes longer than this questionnaire and produces the detailed record an auditor expects. Use this page when you want a ten-minute read on where the gaps are, or a one-page printout for your team. Use the SRA Tool for the analysis itself.

Pair this with the HIPAA compliance checklistfor the Privacy and Breach rules, and see how Prospyr's aesthetic EMR handles access and records for your practice.

Frequently asked questions

What is a HIPAA security risk assessment?

It is the risk analysis required by 45 CFR 164.308(a)(1)(ii)(A): an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of the electronic PHI your practice holds. You list where electronic PHI lives, identify threats and weaknesses, rate the risk, and write down what you will do about it. The Security Rule marks this specification as required.

Is there a free HIPAA risk assessment tool?

Yes. HHS and the Office of the National Coordinator for Health IT publish a free Security Risk Assessment (SRA) Tool for small and medium providers, as a Windows application or an Excel workbook. This page's questionnaire is a faster first pass that follows the same safeguard groupings. Use it to see where you stand, then do the full analysis in the SRA Tool.

How often should a HIPAA risk assessment be done?

The Security Rule does not set a fixed interval. It requires an ongoing process and says to evaluate your safeguards periodically and when operations change. Many practices repeat the analysis every year and after changes such as a new EHR, a new location, a new vendor or a security incident. Put the date on each printed summary and keep it.

What does a HIPAA risk assessment cover?

It covers every place electronic PHI is created, received, stored or sent, and the administrative, physical and technical safeguards around each one. That includes your EHR, email, text messages, laptops, phones, backups, cloud storage and the vendors that touch the data. The questionnaire above walks through those safeguard groups, using the sections of 45 CFR 164.308, 164.310 and 164.312.

Does completing this questionnaire make me HIPAA compliant?

No. It is a screening aid and does not satisfy the risk analysis requirement on its own. The SRA Tool itself states that it is neither required by nor a guarantee of compliance. Compliance means you can show you identified your risks, acted on them and documented both.

What do the priority labels mean?

They are this tool's triage rule, not an OCR scoring method. A required safeguard that is missing, or that you are not sure about, is high. A required safeguard that is only partly in place, or an addressable safeguard that is missing, is medium. An addressable safeguard that is partly in place is low. Fix high items first, then use your own judgment about likelihood and impact.

What is the difference between required and addressable?

Required specifications must be implemented. Addressable ones must be implemented if reasonable and appropriate, or you document why an equivalent alternative is. Addressable does not mean optional. The labels on each question follow the Security Rule text.

Sources and scope

A screening aid, not the risk analysis required by 45 CFR 164.308(a)(1)(ii)(A) and not legal advice. It does not certify HIPAA compliance. State law may add requirements; confirm with your attorney or compliance officer.

Report a correction

Run your practice on one system