SaberGuard SRA Workspace
Runs in your browser. No assessment data is sent to a server.
This is not the HHS Security Risk Assessment (SRA) Tool. SaberGuard SRA Workspace is published by SaberGuard LLC, is not affiliated with or endorsed by HHS, and does not replace the HHS tool.
HIPAA Security Rule · 45 CFR Part 164, Subpart C

Document a HIPAA Security Rule risk analysis.

Record where ePHI is stored, received, maintained or transmitted, review the Security Rule standards and implementation specifications, rate risks by likelihood and impact, assign remediation, and print a report. Runs in a browser with nothing to install, no account, and one working file.

Published by SaberGuard LLC. This workspace is not the HHS Security Risk Assessment (SRA) Tool, is not affiliated with or endorsed by HHS, and does not replace the HHS tool. Using it does not by itself make a risk analysis complete or establish compliance with the HIPAA Security Rule.

0%Assessment complete
Catalog rows reviewed
0Risks recorded
0Evidence files
Step 1 of 7

Organization & assessment scope

Define who, what, and where is included before reviewing the catalog. The entity profile decides which business associate duty applies and marks the clearinghouse and group health plan rows Not applicable with the basis recorded. These details populate the report cover, document control block, and scope section.

Required foundation
Covered entity, business associate, or both.
No marks 45 CFR 164.308(a)(4)(ii)(A) Not applicable with the basis recorded.
No marks 45 CFR 164.314(b)(1) and (b)(2) Not applicable with the basis recorded.
Name, title, and firm as it should appear on the report. The report names this person or firm as its preparer.
The official identified under 45 CFR 164.308(a)(2).
Set by the organization. The Security Rule sets no fixed interval. The analysis is also updated when environmental or operational changes affect the security of ePHI (45 CFR 164.306(e) and 164.316(b)(2)(iii)).
Include locations, workforce, systems, ePHI flows, vendors, and explicit exclusions.
EHR, cloud services, endpoints, facilities, network, and vendors.
Interviews, document review, technical validation, sampling, and who took part.
Step 2 of 7

ePHI systems & data-flow inventory

The risk analysis covers all ePHI the organization holds (45 CFR 164.308(a)(1)(ii)(A)). Record every person, device, system, outside party, and backup that stores, receives, maintains, or transmits ePHI, then record the flows between them. Record electronic PHI only; paper records are not ePHI. Unknown is a recorded gap, not a no: a row left unclassified fails a completeness check.

No ePHI systems or locations recorded. Include people, EHRs, email, endpoints, file shares, backups, medical devices, cloud vendors, outside parties, and physical locations.

Data flows

One row per connection that carries ePHI between two inventory rows. "Fax" means an electronic fax service. Direct entry is a person typing into a device. Unknown transport or encryption is a recorded gap.

#FromDirectionToePHI carriedTransportEncrypted in transitNotes
No data flows recorded. Add the connections between people, devices, systems, vendors, outside parties, and backups.
Step 3 of 7

ePHI flow map

Drawn from the inventory and data flows above. Three columns: people and devices in the practice, the systems that hold ePHI with their backups listed inside, and the outside parties ePHI is shared with. Direct-entry flows are not drawn. A line carries a label only when it is not encrypted or not checked. Tags are risk register references. Every row or flow flagged for a missing or unconfirmed business associate agreement, encryption, or multi-factor authentication needs a linked risk before the report leaves draft.

Step 4 of 7

Review the Security Rule catalog

Review each Security Rule standard and implementation specification. Addressable does not mean optional. For each addressable specification, assess whether it is reasonable and appropriate in your environment. If it is, implement it. If it is not, document why and implement an equivalent alternative measure if one is reasonable and appropriate (45 CFR 164.306(d)(3)). Record that reason in the notes when you choose Alternative measure in place or Not implemented, decision documented. Use Not applicable only when the provision does not apply to the organization, and record the basis. Record for each row how the status was verified: observed, document reviewed, or stated by the client.

Step 5 of 7

Risk register & remediation plan

Record reasonably anticipated threats and the vulnerabilities they could exploit as risk statements tied to affected systems, data flows, and catalog rows. Scoring method: inherent score = likelihood × impact, each rated 1 to 5. Low 1 to 7, Medium 8 to 14, High 15 to 25. These scales and thresholds are SaberGuard's own. Record the treatment decision, owner, target date, and the expected residual risk.

No risks recorded yet. Add risks identified during interviews, evidence review, or the catalog review, or start from the risk scenario library.
Step 6 of 7

Executive summary & management attestation

Write the narrative that opens the report, then name the accountable approver. If the narrative is left blank, the report generates a factual summary from the results.

Overall posture, most significant risks, notable strengths, and the recommended priorities for leadership.
Printed under the approver's signature line. Approval is recorded by signature and date on the printed report, not by this field.
Step 7 of 7

Report & completeness checks

Preview the report on screen, then use Print / PDF to produce the deliverable. Save the JSON file to keep an editable record. The checks below test whether fields are filled in. They do not test whether the risk analysis is accurate or thorough.

Draft
Not scoredImplementation score: met plus alternative measure plus half of partial, over applicable rows reviewed. Not a compliance score.
0Rows met or with an alternative measure
0Rows partially met or not met
0High risks (score 15 to 25)
    The report prints as Draft, with a watermark, until every check passes and you set Final here.

    "Save file without evidence" writes the same file with the names and sizes of attached evidence but not the files themselves, for sharing the assessment without the attachments. Evidence stays in this tab until you save the full file.

    Print tips: in the print dialog choose Save as PDF, paper size Letter, and turn off Headers and footers so the browser's URL and timestamp do not print. Backgrounds and status colors are forced on by the report styles.
    Retention: the Security Rule requires documentation to be kept for 6 years from the date it was created or the date it was last in effect, whichever is later (45 CFR 164.316(b)(2)(i)). Keep the final analysis and the records that support it at least that long. State law or contracts may require longer. The saved JSON file can contain sensitive security information. Store it only on an approved, encrypted device.
    Not saved during this session.
    This preview matches the printed report. Turn off browser headers and footers in the print dialog for a clean PDF.