Document a HIPAA Security Rule risk analysis.
Record where ePHI is stored, received, maintained or transmitted, review the Security Rule standards and implementation specifications, rate risks by likelihood and impact, assign remediation, and print a report. Runs in a browser with nothing to install, no account, and one working file.
Published by SaberGuard LLC. This workspace is not the HHS Security Risk Assessment (SRA) Tool, is not affiliated with or endorsed by HHS, and does not replace the HHS tool. Using it does not by itself make a risk analysis complete or establish compliance with the HIPAA Security Rule.
Organization & assessment scope
Define who, what, and where is included before reviewing the catalog. The entity profile decides which business associate duty applies and marks the clearinghouse and group health plan rows Not applicable with the basis recorded. These details populate the report cover, document control block, and scope section.
ePHI systems & data-flow inventory
The risk analysis covers all ePHI the organization holds (45 CFR 164.308(a)(1)(ii)(A)). Record every person, device, system, outside party, and backup that stores, receives, maintains, or transmits ePHI, then record the flows between them. Record electronic PHI only; paper records are not ePHI. Unknown is a recorded gap, not a no: a row left unclassified fails a completeness check.
Data flows
One row per connection that carries ePHI between two inventory rows. "Fax" means an electronic fax service. Direct entry is a person typing into a device. Unknown transport or encryption is a recorded gap.
| # | From | Direction | To | ePHI carried | Transport | Encrypted in transit | Notes |
|---|
ePHI flow map
Drawn from the inventory and data flows above. Three columns: people and devices in the practice, the systems that hold ePHI with their backups listed inside, and the outside parties ePHI is shared with. Direct-entry flows are not drawn. A line carries a label only when it is not encrypted or not checked. Tags are risk register references. Every row or flow flagged for a missing or unconfirmed business associate agreement, encryption, or multi-factor authentication needs a linked risk before the report leaves draft.
Review the Security Rule catalog
Review each Security Rule standard and implementation specification. Addressable does not mean optional. For each addressable specification, assess whether it is reasonable and appropriate in your environment. If it is, implement it. If it is not, document why and implement an equivalent alternative measure if one is reasonable and appropriate (45 CFR 164.306(d)(3)). Record that reason in the notes when you choose Alternative measure in place or Not implemented, decision documented. Use Not applicable only when the provision does not apply to the organization, and record the basis. Record for each row how the status was verified: observed, document reviewed, or stated by the client.
Risk register & remediation plan
Record reasonably anticipated threats and the vulnerabilities they could exploit as risk statements tied to affected systems, data flows, and catalog rows. Scoring method: inherent score = likelihood × impact, each rated 1 to 5. Low 1 to 7, Medium 8 to 14, High 15 to 25. These scales and thresholds are SaberGuard's own. Record the treatment decision, owner, target date, and the expected residual risk.
Executive summary & management attestation
Write the narrative that opens the report, then name the accountable approver. If the narrative is left blank, the report generates a factual summary from the results.
Report & completeness checks
Preview the report on screen, then use Print / PDF to produce the deliverable. Save the JSON file to keep an editable record. The checks below test whether fields are filled in. They do not test whether the risk analysis is accurate or thorough.
"Save file without evidence" writes the same file with the names and sizes of attached evidence but not the files themselves, for sharing the assessment without the attachments. Evidence stays in this tab until you save the full file.