Back to BlogHIPAA Updates

Do I need a HIPAA Risk Assessment every year?

August 22, 2026
Darren Speed, MS, CHC
Do I need a HIPAA Risk Assessment every year?

Yes—most covered entities and business associates should perform and document a HIPAA Security Rule risk analysis at least annually, and sooner whenever there is a material change to systems, operations, vendors, or threats. HIPAA does not use the phrase “every year” in the regulation itself, but the rule requires an accurate and thorough assessment of risks to electronic protected health information (ePHI), and regulators consistently expect risk analysis to be ongoing, reviewed periodically, and updated when conditions change.

What does HIPAA actually require?

The HIPAA Security Rule requires covered entities and business associates to conduct a risk analysis under 45 CFR 164.308(a)(1)(ii)(A). The regulation states that organizations must conduct an “accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability” of ePHI they create, receive, maintain, or transmit.

HIPAA also requires organizations to implement security measures sufficient to reduce identified risks and vulnerabilities to a reasonable and appropriate level under 45 CFR 164.308(a)(1)(ii)(B).

Importantly, the regulation does not say, “perform a risk assessment once and keep it forever.” OCR guidance has long made clear that risk analysis is an ongoing process, not a one-time project.

Do I need a HIPAA risk assessment every year?

Yes, annual review is the practical minimum for most organizations. While HIPAA does not prescribe a specific 12-month deadline, an annual risk analysis or annual comprehensive review is widely treated as the baseline expectation because:

  • Threats change over time, including ransomware, phishing, and unauthorized access risks.
  • Systems change, such as EHR upgrades, cloud migrations, remote access tools, and new medical devices.
  • Workflows change, including staffing, office moves, and acquisitions.
  • OCR enforcement regularly focuses on whether the organization performed a recent, documented, enterprise-wide risk analysis.

For that reason, many compliance programs adopt an annual enterprise-wide risk analysis with additional targeted updates whenever significant changes occur.

What do regulators say about timing?

OCR has stated in guidance that risk analysis should be conducted “as needed” to account for changes in the environment and operations, and that it should be reviewed and updated regularly. That means waiting several years between assessments can create compliance risk, even if the organization completed one in the past.

The Office of Inspector General and OCR enforcement actions have repeatedly identified failures where organizations either:

  • Never performed a proper risk analysis,
  • Performed one that was too narrow, or
  • Failed to update it after major changes or known incidents.

In practice, if an organization cannot show a current and documented analysis of risks to all ePHI systems, regulators may conclude that the Security Rule has not been met.

What counts as a “real” HIPAA risk analysis?

A HIPAA risk analysis is more than a vulnerability scan, checklist, or generic policy review. OCR guidance indicates that a compliant analysis should identify where ePHI is stored, received, maintained, or transmitted and evaluate threats and vulnerabilities affecting that information.

At a minimum, the process should address:

  • Scope: All systems, devices, applications, data flows, locations, and vendors involving ePHI.
  • Data inventory: Servers, EHRs, laptops, mobile devices, cloud platforms, email, backups, copiers, and medical equipment that store or transmit ePHI.
  • Threats and vulnerabilities: Hacking, stolen devices, insider misuse, weak access controls, unpatched systems, insecure remote access, and vendor exposure.
  • Likelihood and impact: The probability of occurrence and the potential effect on confidentiality, integrity, and availability.
  • Existing safeguards: Encryption, MFA, audit logs, training, backup controls, facility access, and incident response measures.
  • Risk ratings and remediation: Clear prioritization of corrective actions with timelines and accountability.

A risk analysis should also be documented. If it was not documented, it will be difficult to prove it happened.

When should I update the risk analysis before the year is over?

You should not wait for the next annual cycle if there is a meaningful change in your risk environment. A mid-year update is appropriate when events affect how ePHI is protected.

Common examples include:

  • Implementing a new EHR or practice management system
  • Moving data to a cloud hosting environment
  • Opening a new clinic or closing an office
  • Starting or expanding remote work arrangements
  • Adding a new billing company, managed service provider, or other business associate
  • Experiencing a security incident, ransomware event, or unauthorized access
  • Deploying patient texting, telehealth, or portal technologies
  • Merging with another practice or acquiring another entity

For example, if a physician practice completed a risk analysis in January but moved to a cloud-based EHR in July, relying only on the January assessment would likely be insufficient. The migration changes data flows, vendor dependencies, authentication methods, backup procedures, and access risks. That change should trigger an updated review.

What are common mistakes that cause compliance problems?

Organizations often believe they are compliant because they completed some type of “assessment,” but OCR distinguishes between a true risk analysis and other activities.

Frequent problems include:

  • Only assessing one location or one application instead of the full enterprise
  • Ignoring vendors and cloud services that create, receive, maintain, or transmit ePHI
  • Confusing a gap analysis with a risk analysis
  • Failing to inventory all ePHI, including backups, mobile devices, and shared drives
  • Not updating the analysis after major operational changes
  • Not following through on remediation after risks are identified

Another common problem is performing the assessment only for Meaningful Use, MIPS, or an insurance questionnaire and assuming that satisfies HIPAA indefinitely. Those programs may require security review activities, but the HIPAA Security Rule still requires an accurate and current analysis of organizational risk.

Q&A: real regulatory answers to common questions

Is an annual HIPAA risk assessment explicitly required by the regulation?

No, not by that exact phrase. The Security Rule requires a risk analysis under 45 CFR 164.308(a)(1)(ii)(A), and OCR says the process must be ongoing and updated as needed. Because of that, annual review is the accepted best practice and often the safest compliance position.

Can I skip this year if nothing changed?

Usually no. Even if your internal environment seems stable, external threats change constantly. An annual review helps confirm whether prior assumptions, safeguards, and vendor arrangements are still accurate.

Does a small medical practice have the same obligation as a hospital?

Yes, but the scale differs. HIPAA applies to both, and both must assess risks to ePHI. A small practice may have a simpler environment, but it still must conduct and document a thorough analysis appropriate to its operations.

Is a vulnerability scan enough?

No. A vulnerability scan can be one useful input, but a HIPAA risk analysis must also evaluate data locations, threats, safeguards, likelihood, impact, and remediation across the organization.

If I had a breach, do I need a new risk assessment?

Yes, in most cases. A breach or security incident is a strong signal that risks should be reassessed. The organization should evaluate what failed, whether the prior analysis missed relevant threats, and what safeguards now need to be added or strengthened.

What is the best compliance approach?

A sound approach for most healthcare organizations is to treat the HIPAA risk analysis as a living process:

  1. Conduct a documented, enterprise-wide assessment at least annually.
  2. Update it when major technology, vendor, operational, or threat changes occur.
  3. Track remediation items with owners and deadlines.
  4. Retain documentation showing methodology, scope, findings, and corrective actions.
  5. Coordinate the risk analysis with policies, training, incident response, and vendor management.

This approach aligns more closely with OCR expectations than a one-time checklist completed years ago.

Conclusion

So, do you need a HIPAA risk assessment every year? In practical compliance terms, yes. Although HIPAA does not set a strict annual calendar requirement in the regulatory text, OCR expects risk analysis to be accurate, thorough, documented, and updated regularly and whenever conditions change. For most covered entities and business associates, an annual enterprise-wide assessment is the clearest way to meet that expectation.

#HIPAA#Privacy#Security#Healthcare

Frequently Asked Questions

Does HIPAA literally say I must do a risk assessment every 12 months?

No. The HIPAA Security Rule requires an accurate and thorough risk analysis and OCR says it must be ongoing and updated as needed. Annual review is the practical minimum most organizations follow.

What regulation requires a HIPAA risk analysis?

The requirement appears at 45 CFR 164.308(a)(1)(ii)(A), which requires a risk analysis of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.

Do I need to update the assessment if I change EHRs or move to the cloud?

Yes. Major technology or operational changes can alter data flows, access controls, vendor risks, and backup processes, so the risk analysis should be updated when those changes occur.

Is a vulnerability scan the same as a HIPAA risk assessment?

No. A vulnerability scan is only one input. A HIPAA risk analysis must also identify where ePHI exists, assess threats and safeguards, rate risks, and document remediation steps.

Do small practices need a HIPAA risk assessment too?

Yes. Small practices, hospitals, and business associates all have obligations under the HIPAA Security Rule, although the complexity of the assessment will vary based on the organization’s size and environment.

Ready to Strengthen Your Compliance Program?

Schedule a free consultation with our compliance experts and discover how we can help protect your healthcare organization.