Description
The Security Risk Analysis is the most foundational requirement of the HIPAA Security Rule and the most frequently cited violation in OCR enforcement actions. Organizations without a current, documented risk analysis have no defense when OCR comes asking.
The HIPAA Risk Assessment Worksheet provides a structured, practical tool for completing the risk analysis required under 45 CFR 164.308(a)(1). It walks your organization through a systematic process of identifying assets, threats, vulnerabilities, existing controls, likelihood, impact, and residual risk, producing a documented, audit-ready risk register aligned to OCR guidance and NIST SP 800-30 methodology. This same structure also supports the risk analysis component of value-based care and grant compliance reviews that many FQHCs and community health centers face in addition to HIPAA.
This worksheet is designed for organizations that need to complete a thorough, credible risk analysis without starting from a blank page. It provides the structure and the prompts. Your team provides the knowledge of your own environment. Whether you are completing your organization’s first formal risk analysis or refreshing one that has gone stale, this worksheet keeps the process consistent, repeatable, and easy to hand off if compliance responsibilities change hands.
What This Template Covers
- ePHI asset inventory and scoping methodology
- Threat and vulnerability identification framework aligned to NIST SP 800-30
- Current control documentation and effectiveness assessment
- Likelihood and impact rating scales with scoring guidance
- Risk level calculation using a likelihood and impact matrix
- Risk prioritization and remediation planning fields
- Risk register format for tracking findings over time
- Summary section for executive reporting and attestation
Considerations for Federally Qualified Health Centers (FQHCs) and Small Practices
Federally qualified health centers face the same Security Rule risk analysis requirement as any other covered entity, but often with fewer dedicated IT and compliance resources. This worksheet is built to scale down: an FQHC or small practice can complete it using existing staff knowledge of their systems and vendors, without needing to hire a separate security consultant just to get started. HHS also publishes a free Security Risk Assessment Tool that smaller organizations sometimes start with; this worksheet provides a more detailed, narrative risk register format for organizations that need documentation beyond that tool’s built-in report. For a deeper look at how the requirement applies to smaller and safety-net organizations, see our HIPAA Security Risk Analysis guide. Organizations that also need a lighter-weight tool for evaluating individual breach incidents should pair this worksheet with our Breach Risk Assessment Form.
Common Risk Analysis Documentation Gaps
OCR’s enforcement history shows the same gaps repeatedly: a risk analysis that covers only one system instead of the full inventory of ePHI locations, an analysis that was never updated after a new EHR, cloud vendor, or remote work policy was adopted, and a risk analysis that identifies risks but never documents a remediation plan or timeline. A risk analysis that cannot show its scope, methodology, and outcomes in writing is difficult to defend during an audit or after a breach. This worksheet is structured so each of these elements, scope, methodology, findings, and remediation planning, is documented in one place and can be updated on a recurring cycle rather than treated as a one-time project.
Who This Is For
Security officers, compliance professionals, IT managers, and practice administrators at covered entities and business associates who need a practical, structured tool for completing and documenting the Security Risk Analysis, whether for the first time or as part of an annual review cycle. This includes federally qualified health centers, rural health clinics, small group practices, and multi-site organizations that need a consistent risk analysis format across every location.
Delivered as an editable Microsoft Word (.docx) file. Available immediately after purchase.







