Every practice that creates, receives, maintains, or transmits electronic protected health information (ePHI) is a HIPAA covered entity, and every covered entity owes the government the same document: a documented security risk assessment (SRA). Small and mid-size Arizona practices frequently assume this is optional, or that a one-time exercise from a few years ago still counts. Neither is true, and the gap between what the rule requires and what most practices actually have on file is one of the most consistently cited findings in HHS Office for Civil Rights (OCR) enforcement actions.
What 45 CFR 164.308 Actually Requires
The requirement is not a vague best practice — it is written into the Security Rule itself. Under 45 CFR 164.308(a)(1)(ii)(A), the "Risk analysis (Required)" implementation specification, covered entities must "conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate." This sits under the broader "Security management process" standard, which requires policies and procedures to prevent, detect, contain, and correct security violations.
Two companion provisions reinforce the point. 45 CFR 164.308(a)(8) requires a "periodic technical and non-technical evaluation" of how well existing safeguards meet the Security Rule. 45 CFR 164.316(b)(2)(iii) requires that risk-analysis documentation be reviewed and updated "as needed." Read together, these three provisions describe a standing obligation, not a project a practice completes once and files away.
How Often an SRA Actually Needs to Happen
The Security Rule does not print a fixed interval in the regulatory text, which is exactly why so many practices get the cadence wrong. OCR guidance and the language of 164.308(a)(8) treat risk analysis as an ongoing activity tied to two triggers, not a calendar alone:
- A baseline, enterprise-wide review at least annually — the accepted floor for any practice handling ePHI, regardless of size.
- An updated assessment whenever something material changes — a new EHR or practice-management system, a new billing vendor with system access, a ransomware attempt or confirmed breach, added locations, or new remote-access and telehealth workflows.
A practice that ran an SRA in 2022 and has since switched EHR vendors, added a patient portal, or brought on a new revenue-cycle vendor with system access does not have a current risk analysis, even though a document with that title exists in a drawer somewhere. OCR investigators look at whether the assessment reflects the environment as it exists today, not whether one was ever performed.
What a Complete Assessment Actually Covers
A risk analysis that would hold up under an OCR audit or a breach investigation needs to go well past a checklist. At minimum, it should document:
- Asset inventory and ePHI flow mapping — every system, device, application, and vendor that creates, stores, or transmits ePHI, and how data moves between them.
- Threat and vulnerability identification — the specific risks facing each asset, not a generic industry list.
- Evaluation of current safeguards — the administrative, physical, and technical controls already in place, with evidence they are actually functioning.
- Likelihood and impact scoring — a consistent method for ranking risks so remediation effort goes where it matters most.
- A written remediation plan — each identified high risk mapped to a specific control, an owner, and a deadline, with sign-off from practice leadership.
A spreadsheet template downloaded and filled out in an afternoon rarely satisfies this bar. OCR’s enforcement history consistently treats a thin, generic, or unsigned assessment the same as no assessment at all — failing to conduct a thorough, documented risk analysis remains one of the most commonly cited findings in both routine audits and post-breach investigations.
Where Arizona Practices Typically Fall Short
Three gaps show up repeatedly among smaller Arizona practices:
| Common gap | Why it matters under 164.308 |
|---|---|
| SRA treated as a one-time IT project | Fails the "periodic evaluation" and "as needed" update language in 164.308(a)(8) and 164.316(b)(2)(iii) |
| Vendor and business-associate systems left out of the asset inventory | ePHI flowing through a billing, RPM, or EHR-hosting vendor is still in scope for the assessment |
| No documented remediation plan tied to findings | An assessment without follow-through demonstrates the risk was identified but not addressed — a distinct finding OCR treats separately |
The vendor-inventory gap is particularly common in practices that have added a Health Information Exchange connection, a remote patient monitoring program, or an outsourced billing relationship without updating the risk analysis to reflect the new data flows those relationships create.
Finding a Qualified SRA Vendor
A security risk assessment is a specialized deliverable, and the market for firms that produce a genuinely audit-ready one is uneven — some vendors sell a templated checklist under the SRA label; others provide the asset-mapping, threat scoring, and remediation planning an OCR reviewer would expect to see. Arizona Health Interoperability Council exists as a neutral matching point for exactly this problem: practices describe their EHR setup, vendor relationships, and prior compliance history, and get routed to vetted health-IT and compliance vendors qualified to perform the assessment, rather than the first search result. That is the same convening role Arizona’s health-IT community has relied on this organization for historically — connecting practices to the right operational partner rather than selling a product or acting as a compliance authority itself. This is not legal or compliance advice; it is a path to the licensed professionals and vendors who provide it.
The Bottom Line
A HIPAA security risk assessment is not a one-time deliverable, and it is not satisfied by a downloaded template completed in isolation from the practice’s actual systems and vendors. 45 CFR 164.308(a)(1)(ii)(A) requires an accurate, thorough assessment of risk to ePHI; 164.308(a)(8) and 164.316(b)(2)(iii) require that it stay current. For an Arizona practice that has not refreshed its risk analysis since its last major system change, the fastest path to a defensible one is working with a vendor who does this as their core discipline — not adding it to an already full internal to-do list.