{ "@context": "https://schema.org", "@graph": [ { "@type": "Service", "name": "HIPAA Security Risk Assessment", "serviceType": "Penetration Testing", "provider": { "@type": "Organization", "name": "Affordable Pentesting", "url": "https://affordablepentesting.com" }, "areaServed": "US", "url": "https://affordablepentesting.com/compliance/hipaa-compliance-help" }, { "@type": "BreadcrumbList", "itemListElement": [ { "@type": "ListItem", "position": 1, "name": "Home", "item": "https://affordablepentesting.com/" }, { "@type": "ListItem", "position": 2, "name": "HIPAA Security Risk Assessment", "item": "https://affordablepentesting.com/compliance/hipaa-compliance-help" } ] } ] }
Compliance Assessment

HIPAA Security Risk Assessment

Gap analysis against Trust Services Criteria before your auditor finds the gaps. Audit-ready evidence packages delivered fast, priced for real budgets.

HIPAA compliance icon
Why Us

Built for teams that need results, not retainers

OSCP, CEH & CREST Certified

Our assessors hold the certifications your auditors and assessors recognize — OSCP, CEH, and CREST. No junior analysts running checklists.

Fixed-Rate Pricing

You get a fixed price before we start. No hourly billing, no scope creep surprises, no invoice that looks nothing like the quote.

5–10 Day Turnaround

Most assessments are delivered in five to ten business days from kickoff. Built for real audit deadlines, not enterprise consulting timelines.

Auditor-Ready Deliverables

Reports are structured so your auditor, QSA, C3PAO, or certification body can evaluate evidence directly. No translation layer required.

Why a Formal HIPAA Risk Analysis is Mandatory

A HIPAA Security Rule risk analysis is a legal requirement, not a recommendation. Under 45 CFR 164.308(a)(1)(ii)(A), covered entities and business associates must conduct an accurate and thorough assessment of the risks to the confidentiality, integrity, and availability of ePHI. When an OCR investigator arrives after a breach, the risk analysis is the first document they request — and “we did not have one” is among the most commonly cited findings in OCR enforcement actions.

The Rule does not prescribe a methodology or a frequency, which is exactly what trips organizations up. You are expected to set a defensible cadence and justify it through your own risk analysis. Untested policies sitting in a binder do not demonstrate that your safeguards work. Evidence does.

Administrative, Physical, and Technical Safeguards

The Security Rule organizes requirements into three safeguard categories, and a complete risk analysis has to cover all three rather than stopping at the technical layer:

  • Administrative safeguards — risk analysis and management, workforce security, access management, security awareness training, incident procedures, contingency planning, and periodic evaluation under 164.308(a)(8)
  • Physical safeguards — facility access controls, workstation use and security, and device and media controls
  • Technical safeguards — access control, audit controls, integrity controls, person or entity authentication, and transmission security

Several of these are designated addressable rather than required. Addressable does not mean optional. It means you must implement the safeguard, or document why it is not reasonable and appropriate for your environment and implement an equivalent alternative. Treating addressable as optional without documentation is a finding waiting to happen.

Where Penetration Testing Fits Under HIPAA

The Security Rule as currently in force does not use the term “penetration testing” and does not set a testing schedule. What it does require is the risk analysis at 164.308(a)(1)(ii)(A) and periodic technical and non-technical evaluation at 164.308(a)(8). OCR guidance and industry practice treat penetration testing as the strongest practical method of satisfying that evaluation requirement, because it produces evidence that your technical safeguards actually resist attack rather than merely existing on paper.

That may change. On December 27, 2024, HHS issued a Notice of Proposed Rulemaking to modernize the Security Rule — the most significant proposed update since 2013 — which would make penetration testing at least every twelve months and vulnerability scanning at least every six months explicit requirements, alongside mandatory encryption and MFA. As of this writing the NPRM is still proposed, not final, and the current Security Rule remains in effect. The proposal contemplated a compliance window beginning after a final rule takes effect.

The practical read: do not treat proposed text as settled law, and do not wait for it either. Organizations that already run annual testing will absorb a final rule without disruption. Our guide to the proposed HIPAA Security Rule update tracks the current status and what to prepare for now.

What Our HIPAA Risk Assessment Covers

  • Documented risk analysis satisfying 164.308(a)(1)(ii)(A), structured in a format that holds up under OCR review
  • Review of all three safeguard categories, including a defensible position on every addressable implementation specification
  • Technical testing of systems that create, receive, maintain, or transmit ePHI — applications, APIs, cloud infrastructure, remote access paths, and internal segments
  • Business associate and vendor review, since covered entities and business associates are jointly responsible for ePHI
  • Gap report with prioritized remediation roadmap and an evidence inventory your compliance team can maintain
  • Signed BAA in place before any testing begins

How Often Should You Reassess?

The Security Rule sets no fixed interval, so the cadence is yours to define and defend. Most organizations land on annually, plus a reassessment after any material change to the ePHI environment — a new EHR deployment, a cloud migration, a merger, or a significant architectural change.

Documentation must be retained for six years and reviewed periodically. Our HIPAA compliance checklist covers what to keep, for how long, and in what form.

What Does a HIPAA Risk Assessment Cost?

Pricing depends almost entirely on the size of your ePHI footprint — the number of systems, whether cloud infrastructure is in scope, and how many business associate relationships need review. A small practice and a multi-site hospital system are not comparable engagements.

We scope to your actual environment and quote transparently. Our HIPAA risk assessment cost guide explains what drives pricing and how to scope realistically.

HIPAA Resources

Get HIPAA Risk Ready

A documented risk analysis, technical safeguard testing, and an evidence package built for OCR scrutiny.

  • Risk analysis satisfying 164.308(a)(1)(ii)(A), structured the way OCR expects to receive it
  • Technical testing of the systems that actually touch ePHI, not a policy review with a checklist
  • Prioritized remediation roadmap and evidence inventory your compliance team can maintain

Do not wait for a breach investigation to find out where your gaps are. Get your HIPAA Security Rule assessment quote and walk in prepared.

meet with a team member
48h
Average quote turnaround from form submission
5–10
Business days to a complete, deliverable assessment
0
Sales calls — quote first, conversation only if you want one
How It Works

From form to findings in three steps

1

Fill out the form

Tell us your framework, environment size, and audit deadline. Takes two minutes. No account required, no sales call triggered.

2

Get a scoped quote

We review your submission and send a fixed-price quote with scope, timeline, and what you’ll receive — usually within one business day.

3

Assessment delivered

Once you approve, we kick off immediately. Gap report, remediation roadmap, and evidence package delivered in 5 to 10 business days.

Get a Quote

Start Your HIPAA Security Readiness Today

Risk analysis, safeguard testing, and an OCR-ready evidence package — scoped to your environment.

  • Documented risk analysis satisfying 164.308(a)(1)(ii)(A)
  • Administrative, physical, and technical safeguards reviewed, with a defensible position on every addressable specification
  • Signed BAA in place before testing begins

No sales calls. Same-day response.

meet with a team member
Common Questions

Common HIPAA Security Rule Questions

Is a HIPAA risk assessment legally required?

Yes. The risk analysis requirement under 45 CFR 164.308(a)(1)(ii)(A) is mandatory for covered entities and business associates. A structured assessment is how you produce that risk analysis in a format that satisfies OCR expectations and holds up under investigation.

How often should a HIPAA risk assessment be performed?

The Security Rule does not specify an interval, so you set and justify your own cadence. Most organizations assess annually and reassess after any significant change to the ePHI environment — new EHR systems, cloud migrations, or mergers all warrant reassessment.

Does HIPAA require a penetration test?

Not under the Security Rule as currently in force. The Rule does not name penetration testing or set a testing schedule. It does require a risk analysis and periodic evaluation of your safeguards under 164.308(a)(8), and penetration testing is widely treated as the strongest evidence for that evaluation. HHS has proposed a Security Rule update that would make penetration testing at least every twelve months an explicit requirement, but that proposal is not final and the current Rule remains in effect.

What is the proposed 2024 HIPAA Security Rule update?

HHS issued a Notice of Proposed Rulemaking on December 27, 2024, published in the Federal Register in January 2025. It proposes removing the addressable/required distinction, mandating encryption of ePHI and multi-factor authentication, and requiring vulnerability scanning every six months and penetration testing every twelve months. It remains a proposed rule. Organizations should prepare, but should not treat the proposed text as current legal requirement until HHS publishes a final rule.

Do business associates need their own risk assessment?

Yes. Business associates are directly liable under the Security Rule and must conduct their own risk analysis. A covered entity's assessment does not cover its vendors, and a BAA does not transfer the obligation.

What is the difference between required and addressable safeguards?

Required specifications must be implemented as written. Addressable specifications must be implemented if reasonable and appropriate for your environment — and where they are not, you must document why and implement an equivalent alternative. Addressable never means optional.