HIPAA Security Risk Analysis: Already Required by Law

If you run a small medical or dental practice, the emails about the 2026 HIPAA Security Rule keep coming, and most of them are selling urgency. Here is the part they skip: a HIPAA security risk analysis is already required by law, has been for years, and is the single most common gap the government finds when it investigates a practice. That is the requirement worth your attention this month, not the proposal.

A training certificate proves your staff sat through a course. A risk analysis is a written document of your actual risks. The government only asks for one of them.

Is a HIPAA Security Risk Analysis Required Right Now?

Yes. The security risk analysis requirements sit at 45 CFR 164.308(a)(1)(ii)(A), and they are marked Required, not addressable. Every covered entity, including a solo or small practice, has to conduct and document an accurate and thorough assessment of the risks to its electronic patient data. This is current law, not the 2026 proposal.

You will also hear it called a HIPAA risk assessment or an SRA. Same thing. The confusion comes from the proposed 2026 rule, which would change a lot of other safeguards and is still exactly that: proposed. It was published in January 2025, the comment window closed that March, and as of mid-2026 there is no final rule and no deadline. We covered the honest status of the whole proposal in our 2026 HIPAA Security Rule explainer. The risk analysis is different. It does not need the new rule. It has been enforceable this whole time.

What Does a Real Risk Analysis Actually Include?

A real one is a written document specific to your practice. It identifies where patient data lives, the threats and vulnerabilities that apply to your actual office, how likely and how damaging each one is, and what you are doing about each. A generic template with your practice name typed at the top does not qualify.

An inventory of where patient data actually is. The EHR, email, the front desk workstations, the tablets in exam rooms, the backup drive, the third party portals. You cannot assess risks to data you have not located.
The risks that exist in your office, not a textbook. Shared front desk logins. A former employee whose access was never removed. Backups nobody has test restored. Passwords written where patients can see them. These are the findings that show up in real small practices, and they are the kind of thing a practice usually does not realize is a violation until someone points at it.
What you are doing about each risk. The rule does not stop at finding problems. 45 CFR 164.308(a)(1)(ii)(B) requires you to actually reduce the risks you found to a reasonable level, and the government has publicly shifted its attention from whether you looked to whether you acted.
A date, and a next date. The Security Rule expects periodic re-evaluation, especially when something changes: a new system, a move, a departure. An SRA from 2021 sitting in a drawer is closer to evidence against you than evidence for you.

What Happens When a Practice Skips It?

The short version: a breach starts an investigation, the missing document is what settles it, and small practices have not been exempt. Cyber insurers now ask the same question on applications and renewals, and answering it honestly is uncomfortable when the answer is no.

We broke down the full enforcement pattern, the settlement ranges, and the multi-year corrective action plans in the section of our 2026 Security Rule explainer called The Part That Is Already the Law. If you want the case for taking this seriously, it is there. This post is about what the document itself has to be.

Does Annual HIPAA Training Count as a Risk Analysis?

No. Training satisfies a different obligation. A training certificate proves your staff sat through a course. A risk analysis is a written assessment of your specific environment. Plenty of practices pay a compliance vendor for annual training and assume the risk analysis is handled. Ask to see the document. Often there is not one.

This is the trap in how HIPAA compliance for small practices usually gets bought: training plus a policy binder, renewed every year, and everyone assumes the box is checked. But a remote training vendor cannot see the password taped to the monitor, the shared login the whole front desk uses, or the account that still works for someone who left in March. Those things only show up when someone actually looks at your office, and a risk analysis that never looked at your office is not an analysis of your risks.

What Should a Small Practice Do Now?

Ask one question first: can we produce our written risk analysis today, and is it less than a year old? If yes, check that it names real risks in your actual office and real follow-up on each. If no, that is the gap to close before anything in the 2026 proposal deserves a minute of your attention.

Pull whatever your current vendor has on file and read it. If it is specific to your office, current, and paired with evidence you acted on it, you are ahead of most practices. If it is generic, stale, or missing, get a real one done. And when the analysis surfaces gaps like missing MFA or unencrypted laptops, most of the fixes are configuration inside tools you already pay for. We walked through that work in what small practices should do about MFA and encryption now.

If you want a fast, honest starting read on where your practice stands before anyone sells you anything, the PracticeReady assessment takes about ten minutes and gives you a risk score and a prioritized list. Or take fifteen minutes with me and I will tell you straight where your real gaps are.

Serving small medical practices across Nassau and Suffolk County, Long Island.