Security Risk Assessment Tool

The Health Insurance Portability and Accountability Act (HIPAA) Security Rule requires that covered entities and its business associates conduct a risk assessment of their healthcare organization. A risk assessment helps your organization ensure it is compliant with HIPAA’s administrative, physical, and technical safeguards.

A risk assessment also helps reveal areas where your organization’s protected health information (PHI) could be at risk. To learn more about the assessment process and how it benefits your organization, visit the Office for Civil Rights’ official guidance.

Learn About HIPAA Security Rule

On this page

What is the Security Risk Assessment Tool?

The Office of the National Coordinator for Health IT (ONC), in collaboration with the HHS Office for Civil Rights (OCR), developed a downloadable Security Risk Assessment (SRA) Tool to help guide you through the process. The tool is designed to help healthcare providers conduct a security risk assessment as required by the HIPAA Security Rule. The target audience of this tool is medium and small providers; thus, use of this tool may not be appropriate for larger organizations.

SRA Tool for Windows

The SRA Tool is a desktop application that walks users through the security risk assessment process using a simple, wizard-based approach. Users are guided through multiple-choice questions, threat and vulnerability assessments, and asset and vendor management. References and additional guidance are given along the way. Reports are available to save and print after the assessment is completed.

This application can be installed on computers running 64-bit versions of Microsoft Windows 7/8/10/11. All information entered into the tool is stored locally on the user’s computer. HHS does not collect, view, store, or transmit any information entered into the SRA Tool.

Download SRA Tool v3.7 [MSI – 72.5 MB]

What’s New in Version 3.7?

  • Content improvements in questions, responses, and education. These changes are meant to make the application and workbook versions more relevant in the evolving cybersecurity environment as well as easier to use. Areas of emphasis include:
    • Tool scope transparency reminding users that the SRA Tool survey alone may not identify all risks present in an organization.
    • New assessment-scope question to ensure SRAs account for every location that creates, receives, maintains, or transmits ePHI.
    • New remote access & telework question to highlight and provide education on this persistent risk area.
    • Modernized asset inventory to cover the technology that practices use.
    • Modernized system-activity logging question for the varied systems that organizations use.
    • Potential review triggers for when to update security assessments.
  • Minor updates to reports and references. Reports were updated to ensure that all comments, details, and review data were included.
  • Updated software libraries. Application uses updated libraries that include bug fixes and potential vulnerability mitigation.

SRA Tool Excel Workbook

This version of the SRA Tool takes the same content from the Windows desktop application and presents it in a familiar spreadsheet format. The Excel Workbook contains conditional formatting and formulas to calculate and help identify risk in a similar fashion to the SRA Tool application. This version of the SRA Tool is intended to replace the legacy “Paper Version” and may be a good option for users who do not have access to Microsoft Windows or otherwise need more flexibility than is provided by the SRA Tool for Windows.

This workbook can be used on any computer using Microsoft Excel or another program capable of handling .xlsx files. Some features and formatting may only work in Excel.

Download Workbook v3.7 [XLSX – 218 KB]

SRA Tool User Guide

Download the SRA Tool v3.7 User Guide for FAQs and details on how to install and use the SRA Tool application and SRA Tool Excel Workbook.

Download User Guide [PDF – 2.7 MB]

SRA Webinars

ONC will hold two webinars that will serve as a training session and overview of the Security Risk Assessment (SRA) Tool 3.7. During this webinar, attendees will receive an introduction to security risk assessment, instructions on how to download, install, and use the SRA Tool, an overview of changes included in the new SRA Tool 3.7 release, and an opportunity to participate in a Q&A session.

To accommodate the busy schedules of small and medium practices, there are two opportunities to attend this webinar live. 

Tuesday, September 15, 12:00-1:00 p.m. ET Register for this session.
Wednesday, September 16, 3:00–4:00 p.m. ET Register for this session.

Need Help?

Please leave any questions, comments, or feedback about the SRA Tool using our Health IT Feedback Form. This includes any trouble in using the tool or problems/bugs with the application itself. Also, please feel free to leave any suggestions on how we could improve the tool in the future.

You may also leave a message with our Help Desk by contacting 734-302-4717 or sending email to SRAHelpDesk@Altarum.org.

Submit Questions or Feedback

Disclaimer

The Security Risk Assessment Tool at HealthIT.gov is provided for informational purposes only. Use of this tool is neither required by nor guarantees compliance with federal, state or local laws. Please note that the information presented may not be applicable or appropriate for all health care providers and organizations. The Security Risk Assessment Tool is not intended to be an exhaustive or definitive source on safeguarding health information from privacy and security risks. For more information about the HIPAA Privacy and Security Rules, please visit the HHS Office for Civil Rights Health Information Privacy website.

NOTE: The NIST Standards provided in this tool are for informational purposes only as they may reflect current best practices in information technology and are not required for compliance with the HIPAA Security Rule’s requirements for risk assessment and risk management. This tool is not intended to serve as legal advice or as recommendations based on a provider or professional’s specific circumstances. We encourage providers, and professionals to seek expert advice when evaluating the use of this tool.