Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

The Government is Here to Help: HHS Releases HIPAA Security Risk Assessment Tool for Small Providers

By Elizabeth F. Hodge on March 31, 2014
Email this postTweet this postLike this postShare this post on LinkedIn

The U.S. Department of Health and Human Services (“HHS”) has just released a new security risk assessment (“SRA”) tool to assist small and medium sized health care practices (one to ten providers) conduct a HIPAA risk assessment of their organization.

The HIPAA Security Rule requires that all health care organizations that are HIPAA covered entities or business associates must conduct a thorough and accurate risk assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information. The results of the HIPAA audits conducted by the HHS Office for Civil Rights and recent HIPAA breach settlement agreements highlight the importance OCR places on HIPAA risk assessments. However, many smaller physician practices do not know how to complete a risk assessment that meets the HIPAA Security Rule requirement.

The SRA tool is a free software application for Windows operating systems and iOS iPad that a health care practice can download and use to assist in reviewing its implementation of the HIPAA Security Rule. The 156-question tool addresses the implementation specifications included in the HIPAA Security Rule and covers basic security practices, security failures, risk management, and personnel issues. The tool also identifies issues to consider in responding to the questions, possible threats and vulnerabilities, and examples of safeguards the organization may adopt. HHS says that the tool allows providers to “conduct and document a risk assessment in a thorough, organized fashion at their own pace.” The application produces a report that the practice can later provide to auditors. Because the practice downloads the application, the government will not have access to assessment results unless the practice chooses to share that information. The SRA tool is solely for the purpose of conducting an internal HIPAA risk assessment as required by the HIPAA Security Rule and does not produce a statement of compliance and does not assess compliance with provisions of the HIPAA Privacy Rule.

The Office of National Coordinator for Health Information Technology is soliciting comments on the new SRA tool until June 2, 2014. Comments may be submitted to this address: http://www.healthit.gov/security-risk-assessment.

Photo of Elizabeth F. Hodge Elizabeth F. Hodge

A former president of the Florida Academy of Healthcare Attorneys, Betsy Hodge concentrates her practice on compliance and regulatory issues affecting health care providers and payers and employer-sponsored health plans. Betsy has significant experience with HIPAA and the HITECH Act and assists covered…

A former president of the Florida Academy of Healthcare Attorneys, Betsy Hodge concentrates her practice on compliance and regulatory issues affecting health care providers and payers and employer-sponsored health plans. Betsy has significant experience with HIPAA and the HITECH Act and assists covered entities and business associates in complying with these laws through the development of policies and procedures, workforce training, analysis and notification of breaches, and assisting with government audits and investigations.  In addition, she counsels her clients on regulatory issues, including state and federal fraud and abuse laws.

Read more about Elizabeth F. HodgeEmail
Show more Show less
  • Posted in:
    Health Care and Life Sciences
  • Blog:
    Health Law Rx
  • Organization:
    Akerman LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo