Utopia Tech
Healthcare4 min read

HHS Updates Security Risk Assessment Tool

The HHS has released an updated version of the Security Risk Assessment (SRA) Tool ( v3.7 ). The tool is ideally suited for small- and medium-sized entities to guide them through the risk analysis process, help them identify risks and vulnerabilities to electronic protected health information (ePHI), and comply with the risk analysis implementation specification of the Security

UT

Utopia Tech

September 11, 2026 · 4 min read

Share

The HHS has released an updated version of the Security Risk Assessment (SRA) Tool ( v3. 7 ). The tool is ideally suited for small- and medium-sized entities to guide them through the risk analysis process, help them identify risks and vulnerabilities to electronic protected health information (ePHI), and comply with the risk analysis implementation specification of the Security Management Process standard of the HIPAA Security Rule.

The SRA Tool was developed by the Department of Health and Human Services Office of the National Coordinator for Health Information Technology (ONC) in collaboration with the Office for Civil Rights (OCR). The downloadable tool was first released in March 2014 to help small- and medium-sized HIPAA-regulated entities navigate the risk analysis requirement of the HIPAA Security Rule.

The tool guides regulated entities through the process of conducting and documenting risk analyses, the aim of which is to identify potential weaknesses and gaps in security policies and all risks and vulnerabilities to ePHI. Only by conducting a comprehensive and accurate risk analysis will HIPAA- regulated entities be able to identify all risks and vulnerabilities to ePHI.

If risks and vulnerabilities remain unknown, regulated entities will not be able to take the necessary steps to reduce them to a low and acceptable level and comply with the Risk Management standard of the HIPAA Security Rule. The SRA Tool has received many upgrades over the years to improve usability and add compliance features. The latest release –September 2026 –includes content improvements in questions, responses, and education, expanding the tool to make it more comprehensive and ensure it remains relevant in an evolving cybersecurity environment.

Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy Key updates include the addition of new technologies that have been adopted by regulated entities; a new assessment-scope question to ensure that risk assessments account for every location that creates, receives, maintains, or transmits ePHI; new remote access and telework questions; modernization of the asset inventory to cover technologies that practices are now using; and an update to the system-activity logging question to reflect the varied systems used by regulated entities.

The new version also includes updated software libraries, bug fixes, and tweaks in response to feedback to make the application and Excel workbook easier to use. OCR Actively Enforcing Risk Analysis and Risk Management Compliance HIPAA-regulated entities have long struggled with conducting risk analyses, and 12 years after the tool was first released, OCR still frequently identifies noncompliance in this area.

OCR often finds that risk analyses have never been completed, that they are incomplete or inaccurate, or that there is a lack of documentation of risk analysis processes and procedures. Widespread noncompliance with this vital Security Rule implementation specification prompted OCR to launch a new risk analysis enforcement initiative in 2024 to encourage and improve compliance.

To date, OCR has imposed 14 financial penalties under this initiative, which remains a key enforcement priority for OCR. Further, the planned update to the HIPAA Security Rule, which now has a July 2027 proposed release date, will increase the risk analysis requirements further. The risk analysis is only the first step in the risk management process.

HIPAA-regulated entities must ensure that the identified risks and vulnerabilities are managed effectively and reduced to a low and acceptable level. At the 2026 NIST/OCR conference, Safeguarding Health Information: Building Assurance through HIPAA Security 2026 , OCR Director Paula Stannard explained that many regulated entities appear to be confusing risk management with the cybersecurity performance goals (CPGs) issued by OCR in January 2024.

While the CPGs can be adopted by regulated entities to improve their security posture and prevent cyberattacks and data breaches, simply implementing those measures does not satisfy the risk management requirements of the HIPAA Security Rule. The risk management standard requires specific risk management measures to be implemented to address the risks and vulnerabilities identified by the risk analysis.

OCR has confirmed that the risk analysis enforcement initiative has been expanded to cover risk management. In addition to requiring evidence showing that an accurate and comprehensive risk analysis has been conducted, OCR requires evidence that identified risks have been subjected to a HIPAA-compliant risk management process. OCR wants to ensure that regulated entities are acting on the results of their risk analyses and are taking appropriate actions to reduce risks and vulnerabilities to ePHI.

The post HHS Updates Security Risk Assessment Tool appeared first on The HIPAA Journal .

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content