How Often Should a Medical Practice Run a Security Risk Assessment?
If you're looking for a single number, here it is: run a full security risk assessment at least once a year, and again any time something meaningful changes in your practice. That's the short answer. The longer answer matters, because "at least annually" is where most practices get tripped up in an audit or, worse, after a breach.
The HIPAA Security Rule is the source of the requirement, and it's deliberately vague on timing. Under the HIPAA Security Rule, a security risk assessment isn't a one-and-done project. It is an ongoing risk analysis process. There's no fixed calendar deadline written into the regulation. That flexibility is meant to fit practices of every size, but it also means the responsibility for setting a defensible cadence falls on you.
What HIPAA actually requires
The rule uses the term "risk analysis" and requires it under 45 CFR 164.308(a)(1)(ii)(A). It never says "do this every 12 months." Instead, it expects the analysis to stay current. HIPAA requires an ongoing, current risk analysis. There is no fixed calendar frequency in the rule; you must reassess whenever your environment, systems, threats, or operations change and keep documentation up to date.
Because the requirement is risk-based rather than date-based, regulators and compliance professionals have converged on a practical standard. Because the HIPAA Security Rule is risk-based, the smart answer to "how often" is: at least annually enterprise-wide, plus event-driven reviews and continuous monitoring. Industry guidance is consistent on this point. While the federal regulation does not state a rigid calendar deadline, administrative guidelines and industry best practices dictate that a HIPAA security risk assessment must be completed at least once every 12 months (annually).
So the annual cadence isn't in the statute, but skipping it leaves you without the documentation an investigator will ask for first.
The annual baseline, plus three things that reset the clock
A yearly assessment covers your whole environment: where patient data lives, who can touch it, how it moves, and what could go wrong. Think of it as your baseline. On top of that, certain events should trigger a fresh assessment regardless of when you last did one.
The CMS security risk analysis guidance is explicit about this rhythm. Conducting a security risk analysis is required when certified EHR technology is adopted in the first reporting year. In subsequent reporting years, or when changes to the practice or electronic systems occur, a review must be conducted.
Here are the changes that should prompt an assessment before your next annual review comes due:
- New or changed technology. New or substantially changed systems (EHR modules, imaging, patient portals, telehealth). Cloud migrations. A new practice management platform or a switch to cloud-hosted records reshapes where your data sits and how it's protected.
- Operational changes. Opening a second location, merging with another practice, onboarding a large group of staff, or bringing on new vendors that handle patient data.
- Security incidents and threat shifts. A ransomware scare, a phishing incident, or a newly disclosed vulnerability affecting software you rely on. After any material event, you reassess rather than wait.
Quarterly targeted reviews for high-risk systems and recent changes. Ad hoc assessments after material events (technology changes, incidents, new vendors). Continuous monitoring of key controls to detect drift between formal assessments. For most small and mid-sized practices, a full annual assessment plus event-driven check-ins is realistic and defensible. Larger organizations layer in more frequent targeted reviews.
If you attest to MIPS, the annual requirement is firmer
Practices participating in the Merit-based Incentive Payment System (MIPS) don't get to treat the timing as optional. The security risk analysis is a required attestation objective, and it has to be completed within the performance year you're reporting on.
The attestation is part of your annual MIPS submission. This means your SRA must be finalized, documented, and available for review before you submit your MIPS data, no late completions. Note that the assessment must cover your full environment. This security risk assessment must include all devices (including medical devices), connecting interfaces. If you bill Medicare and report through MIPS, budget for the assessment as a fixed annual task, not a "when we get to it" item.
The mistake that fails audits: assessment vs. analysis
A lot of practices believe they've met the requirement because they filled out a compliance checklist. That's not the same thing, and the distinction is exactly what OCR scrutinizes.
A compliance checklist tells you whether you've implemented specific safeguards. A risk analysis tells you where your actual exposures are. If a compliance assessment asks, "How compliant are we?" then the risk analysis asks, "how secure are we?" The terms get used interchangeably in conversation, but only one satisfies the legal requirement. The HIPAA Security Rule uses "risk analysis" in 164.308(a)(1)(ii)(A) to describe the required evaluation, while "risk assessment" has become the common term in practice. For compliance purposes, both terms refer to the same fundamental requirement.
The stakes here aren't theoretical. Throughout 2018 and 2019, the OCR has identified the failure to conduct an adequate risk assessment as a key finding in nearly half of their settlements, making it the largest single source of identified HIPAA violations. More recently, OCR launched an enforcement initiative aimed squarely at this failure. "Failure to conduct a HIPAA Security Rule risk analysis leaves health" care organizations exposed, and penalties have followed.
Why the frequency question is worth taking seriously
Healthcare remains one of the most targeted sectors for cyberattacks, and the numbers behind that have grown sharply. In 2025, large healthcare data breaches were reported at an average rate of 2.1 data breaches per day. In 2024, an average of 792,226 individuals were affected by a healthcare data breach every day.
The financial exposure is significant too. Recent OCR settlements tied to risk-analysis failures illustrate the range. The monetary fines announced in conjunction with the resolution agreements ranged from as little as $25,000 at the low end to as much as $3 million for a national medical supplier that did not conduct a compliant risk analysis. A regular assessment cadence is one of the few controls that both reduces your breach risk and gives you the documentation to defend yourself if OCR comes knocking.
A practical schedule for most practices
If you want a cadence you can actually follow, this is a sensible default:
- Once a year: a complete, documented risk assessment covering every system that stores, processes, or transmits patient data. Date it, sign it, keep the prior versions.
- On every major change: a focused reassessment when you add or replace an EHR, migrate to the cloud, open a location, or change vendors.
- After any incident: a review triggered by a breach, near-miss, phishing event, or newly disclosed vulnerability.
- Between formal assessments: ongoing monitoring of your highest-risk systems so problems surface early rather than at year-end.
Document everything, including the reasoning behind decisions you make. If an investigator asks why you did or didn't act on a given risk, your notes are the record that answers for you.
Frequently asked questions
Is a HIPAA risk assessment legally required every year?
The Security Rule doesn't name a specific interval, but it requires an ongoing, current analysis. In practice, annually is the accepted standard, and it's effectively mandatory if you attest to MIPS. Waiting longer than a year is hard to defend in an audit.
What's the difference between a risk assessment and a risk analysis?
They're used interchangeably in everyday conversation and refer to the same core requirement, but OCR's language is "risk analysis." The key distinction to remember is between a risk analysis (identifying and prioritizing your actual security exposures) and a compliance checklist (confirming you've implemented specific safeguards). Only the former satisfies the rule.
Does a small practice really need to do this as often as a hospital?
The frequency baseline is the same: annually plus event-driven reviews. The scope differs. A solo practice's assessment is far simpler than a health system's, but the obligation to keep it current applies regardless of size.
What triggers an off-cycle assessment?
New or changed technology, cloud migrations, opening or merging locations, new vendors that handle patient data, and any security incident or newly disclosed vulnerability.
The bottom line
Run a full security risk assessment at least once a year, then reassess whenever your technology, operations, or threat picture changes, and keep every version documented. That cadence satisfies the HIPAA Security Rule's ongoing-analysis expectation, meets MIPS attestation needs, and gives you a defensible record if you're ever audited or breached.
Most practices don't have in-house security staff to run this well, and a checklist filled out by a busy office manager is exactly the kind of "assessment" that fails an OCR review. If you'd rather have the technical work handled properly, PolySec performs in-person HIPAA security risk assessments built around your specific practice, including on-site vulnerability and network scanning, policy and BAA review, an audit-ready findings report, and a remediation roadmap so you know what to fix and in what order.
Top comments (0)