Every covered entity that touches electronic protected health information has to run a HIPAA security risk assessment — there is no opt-out. The question most Arizona practices actually struggle with isn't whether to do one, it's how: work through the free government tool in-house, or bring in a vendor who does this for a living. The right answer depends less on budget than most practices assume, and getting it wrong shows up at the worst possible time — during an OCR investigation, not during a routine compliance check.
What the HIPAA Security Rule actually requires
The obligation traces to 45 CFR 164.308(a)(1), the Security Rule's security management process standard. Buried inside it is a required implementation specification, 45 CFR 164.308(a)(1)(ii)(A): an "accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability" of the ePHI a practice creates, receives, maintains, or transmits. That means identifying every place ePHI lives, evaluating whether existing safeguards actually work, estimating the likelihood and impact of a breach, and documenting all of it with a remediation plan attached. It is not a one-time exercise — systems change, staff turn over, and new vendors get added, so the assessment has to be revisited as the practice's technology footprint changes.
This is also the single most commonly cited deficiency when the HHS Office for Civil Rights investigates a breach. A practice that never ran a risk analysis, or ran one years ago and never updated it, starts every OCR conversation from a losing position — regardless of how good its actual security controls turned out to be.
What the free HHS SRA Tool covers
The Security Risk Assessment (SRA) Tool is a free downloadable application developed jointly by the Office of the National Coordinator for Health Information Technology and the HHS Office for Civil Rights, built specifically for small and mid-sized practices that don't have an in-house compliance department. It walks a user through a wizard-style questionnaire covering administrative, physical, and technical safeguards, prompts for a threat and vulnerability inventory, touches on vendor and asset management, and generates a scored report with a remediation-tracking feature so a practice can log how it responded to each identified gap.
For a solo or small-group practice with a straightforward technology stack, that is a legitimate, credible starting point — and it costs nothing but staff time. The government's own documentation is explicit, however, that completing the tool "is neither required by nor guarantees compliance with federal, state or local laws." It is a structured self-assessment, not a certification.
Where the self-assessment runs out of road
The SRA Tool assumes the person filling it out can accurately identify every system, device, application, and vendor relationship that touches ePHI, and can honestly judge how well existing controls are working. That is a reasonable ask for a practice with one EHR and a handful of workstations. It becomes a much harder ask once a practice is running remote patient monitoring devices, a patient portal, cloud-based billing, and two or three outside vendors with their own access to the record system — which describes a large share of modern outpatient practices.
A few gaps show up consistently when practices rely on the tool alone:
- No technical testing. The tool is a questionnaire; it does not run vulnerability scans or penetration tests against the practice's actual network.
- Self-assessed objectivity. Internal staff answering questions about their own systems tend to underreport gaps they don't know exist — not out of dishonesty, but because you can't flag a vulnerability you haven't learned about yet.
- Asset inventory completeness. Shadow IT — a scheduling app a front-desk employee signed up for, a personal device syncing patient photos — routinely gets missed by an in-house pass.
- Currency of the threat model. The tool is updated periodically, but a practice-specific vendor engagement can react to a newly disclosed vulnerability or a fresh phishing pattern in real time.
- Audit-ready documentation. A remediation report generated once and filed away reads very differently to an OCR investigator than a maintained risk register with dated, specific corrective actions.
The practical decision framework
Practice size and technical complexity should drive the choice more than sticker price. A single-provider practice with one EHR, no remote monitoring, and no significant third-party integrations can reasonably start with the SRA Tool, take the results seriously, and revisit it annually. A multi-provider group, anyone using remote patient monitoring or connected devices, or any practice that has already added several outside vendors to its ePHI workflow is better served pairing the free tool — useful as a first pass and an internal-awareness exercise — with a qualified third-party risk assessment that can verify the technical environment rather than just describe it.
The two approaches aren't mutually exclusive. Many practices run the SRA Tool internally first to build the baseline inventory, then bring in a vendor to validate the findings, run the technical testing the tool can't do, and produce documentation built to withstand scrutiny. That sequencing tends to be more efficient — and often cheaper — than either extreme on its own.
Finding the right fit
What makes this decision harder in practice is that "hire a vendor" covers an enormous range of actual services, from a one-time assessment to an ongoing managed security relationship, and pricing and scope vary widely by practice size and complexity. A practice evaluating vendors should ask exactly what the engagement includes — technical scanning, policy review, staff training, ongoing monitoring — rather than assuming all "HIPAA risk assessment" offerings are equivalent.
The bottom line: the free HHS SRA Tool is a legitimate and useful starting point for every practice, but it was designed as a floor, not a ceiling. Whether a practice needs to build on that floor with a qualified vendor comes down to how much ePHI moves through how many systems — and how confident the practice is that its own staff can spot what a self-assessment might miss.