Every covered entity that touches electronic protected health information (ePHI) — which is to say, nearly every medical practice in Arizona — is required to conduct a HIPAA security risk assessment. It is not a suggestion buried in best-practice guidance; it is a required implementation specification under 45 CFR § 164.308(a)(1)(ii)(A) of the Security Rule, and it is not a one-time exercise. Practices are expected to revisit it periodically, and especially after any significant change to systems, staffing, or vendors. For a solo practitioner or a small group, the honest question is not whether the assessment is required, but whether it can realistically be done in-house or whether it is time to bring in a healthcare-focused managed IT provider (MSP) to do it properly.
What the HIPAA Security Rule Actually Requires
The Security Rule’s risk assessment requirement is deliberately broad: it calls for an enterprise-wide analysis of the risks and vulnerabilities to all ePHI an organization creates, receives, maintains, or transmits — on every form of electronic media, from an aging desktop in a back office to a cloud-hosted EHR to a staff member’s phone. The purpose is not paperwork for its own sake. It is meant to help a practice identify where it is actually exposed and then implement security measures that are reasonable and appropriate for the threats it faces. A five-provider clinic and a 40-bed hospital face different threats, so the Rule does not prescribe one checklist — it prescribes a process of ongoing identification and mitigation.
The Free HHS Tool — and Where It Stops Being Enough
The HHS Office for Civil Rights (OCR), jointly with the Office of the National Coordinator for Health Information Technology (ONC), publishes a free Security Risk Assessment (SRA) Tool specifically for small and medium-sized practices. It is a genuinely useful starting point: a wizard-based desktop application that walks a practice through multiple-choice questions on threats, vulnerabilities, and vendor management, all mapped back to the Security Rule’s actual requirements, and it generates a report a practice can keep on file along with a remediation log.
What the tool does not do is guarantee compliance. HHS is explicit on this point — completing the questionnaire is an aid to meeting the periodic assessment requirement, not proof that a practice’s systems are actually secure. It is also, by HHS’s own framing, built for smaller organizations; practices with more complex environments — multiple locations, a mix of legacy and cloud systems, third-party billing integrations — tend to outgrow it and move toward enterprise governance, risk, and compliance (GRC) approaches instead. The gap between "filled out the questionnaire" and "actually assessed our real technical environment" is exactly where many small practices get into trouble.
Signs a Practice Has Outgrown the DIY Assessment
A self-administered SRA tends to stop being sufficient once a few things are true at once:
- ePHI now lives in more than one system. Between an EHR, a patient portal, a billing clearinghouse, and remote-monitoring devices, nobody on staff can confidently list every place patient data actually sits.
- Nobody owns IT full time. The assessment gets assigned to whichever staff member is least busy that quarter, rather than someone who understands network configuration, access controls, or encryption.
- The practice has added remote work, telehealth, or connected devices without a parallel review of how those endpoints are secured.
- A prior assessment surfaced findings that were never remediated — the report exists in a drawer, but the vulnerabilities it identified are still open.
- The practice has never actually been through an OCR audit or a breach investigation and has no real sense of how its documentation would hold up under one.
None of these individually means a practice is out of compliance. Together, they usually mean the checklist-driven, self-administered version of the SRA has reached its limit.
What a Healthcare-Focused MSP Adds
A generalist IT vendor can patch servers and manage a firewall. A managed IT provider that specializes in healthcare brings something narrower and more useful: familiarity with how ePHI actually moves through a clinical workflow, and the ability to translate a risk finding into a fix that does not break how the front desk or the billing team works day to day.
| Task | Self-administered SRA | Healthcare-focused MSP |
|---|---|---|
| Inventory of where ePHI lives | Relies on staff memory and manual review | Technical discovery across network, cloud, and devices |
| Vendor and business-associate review | Often skipped or incomplete | Ongoing tracking as part of standard service |
| Remediation of findings | Logged, frequently not actioned | Scheduled and implemented as managed work |
| Audit-readiness documentation | A saved PDF report | Maintained, updated risk register |
The value is less about the assessment as an event and more about the assessment as an input into ongoing, managed remediation — the part most small practices never get to on their own.
Finding the Right Fit, Not Just Any MSP
Arizona has no shortage of general managed-service providers, but not every one of them has worked inside a clinical environment or understands the practical difference between a generic IT risk and a HIPAA-relevant one. The role of a neutral, statewide health-IT resource is to help a practice match with a vendor that has actually done this work in healthcare settings before — rather than a practice discovering the gap the hard way, mid-audit. Whether a given practice needs a full-scope managed IT relationship or simply a one-time, properly documented risk assessment to close a specific gap, the right first step is understanding which category of vendor actually fits the practice’s size and complexity, not defaulting to whichever provider answers the phone first.
The HIPAA security risk assessment requirement is not going away, and the free federal tool is a legitimate place to start. But for practices where ePHI now touches more systems, more vendors, and more devices than one questionnaire can meaningfully capture, matching with a managed IT partner who already understands healthcare workflows is usually the difference between a report that sits in a drawer and a security posture that actually holds up.