The U.S. Department of Health and Human Services has released version 3.7 of its Security Risk Assessment Tool to help small and medium-sized HIPAA-regulated entities conduct and document risk analyses involving electronic protected health information (ePHI).
September 2026 Release
The updated Security Risk Assessment Tool, version 3.7, was released in September 2026. The tool is intended for SMEs and guides users undergo the risk analysis process, including the identification of risks and vulnerabilities affecting electronic protected health information.
The tool supports compliance with the risk analysis implementation specification of the Security Management Process standard of the HIPAA Security Rule.
The Department of Health and Human Services Office of the National Coordinator for Health Information Technology developed the tool in collaboration with the Office for Civil Rights (OCR). In March 2014, the downloadable tool was first issued to help small and medium-sized HIPAA-covered entities satisfy the HIPAA Security Rule risk analysis requirement.
The tool guides regulated entities through conducting and documenting risk analyses. The process addresses potential weaknesses and gaps in security policies, as well as risks and vulnerabilities involving electronic protected health information.
Changes in Version 3.7
The September 2026 release adds content changes to questions, responses, and educational material. The update adds technologies used by covered entities and includes a new assessment-scope questionnaire addressing locations that create, receive, maintain, or transger ePHI.
The updated tool also adds questions concerning remote access and telework. Its asset inventory has been modernized to include technologies used by practices today. There was an update to the system-activity logging question to show the range of systems used by covered entities.
Version 3.7 includes changes in the software libraries and bug fixes. Changes were also made to the application and Excel workbook in response to feedback.
Risk Analysis and Risk Management Compliance
The OCR continues to identify deficiencies involving risk analysis among HIPAA-regulated entities. Identified problems include risk analyses that have not been completed, analyses that are incomplete or inaccurate, and inadequate documentation of risk analysis processes and procedures.
The OCR launched a risk analysis enforcement initiative in 2024. The initiative was established to encourage and improve compliance with the risk analysis requirement. The source states that 14 financial penalties have been imposed under the initiative. The initiative has been expanded to include risk management. Under this enforcement approach, regulated entities are expected to provide proof of a proper and complete risk analysis and prove that identified risks have been addressed through a HIPAA-compliant risk management procedure.
Risk analysis is described as the first step in the risk management process. Identified risks and vulnerabilities must then be managed and reduced to a low and acceptable level. The planned update to the HIPAA Security Rule has a July 2027 proposed release date and would increase risk analysis requirements further.
The cybersecurity performance goals issued by the OCR in January 2024 do not, by themselves, satisfy the risk management requirements of the HIPAA Security Rule. The risk management standard requires measures addressing risks and vulnerabilities identified through the risk analysis.
