A HIPAA security risk assessment is one of the most important steps a medical or dental practice can take to identify vulnerabilities, protect electronic protected health information (ePHI), and strengthen its cybersecurity posture. More importantly, risk analysis isn’t simply an IT best practice. The HIPAA Security Rule requires regulated entities to conduct an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
Today, healthcare organizations depend on electronic health records, practice-management systems, Microsoft 365, digital imaging, cloud applications, workstations, servers, mobile devices, and connected technologies. As a result, sensitive information can exist across a much larger technology environment than many organizations realize.
Furthermore, cybersecurity threats continue to evolve. Phishing, ransomware, compromised credentials, outdated software, improperly configured cloud services, and unsecured remote access can expose healthcare organizations to significant risk.
Therefore, an effective HIPAA security risk assessment should go beyond checking boxes on a compliance form. Instead, it should help an organization understand where its ePHI exists, identify potential threats and vulnerabilities, evaluate existing safeguards, prioritize risks, and develop a practical plan for improvement.
In this guide, we’ll explain what a HIPAA security risk assessment involves, which technology organizations should evaluate, common risks facing medical and dental practices, and how organizations throughout Washington DC, Maryland, and Virginia can strengthen their security posture.
What Is a HIPAA Security Risk Assessment?
A HIPAA security risk assessment is a structured evaluation of potential risks and vulnerabilities affecting ePHI within an organization.
The HIPAA Security Rule establishes administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of ePHI. Accordingly, risk analysis provides an important foundation for determining which security measures may be reasonable and appropriate for an organization’s environment.
A comprehensive assessment should help answer questions such as:
- Where does our organization create, receive, maintain, or transmit ePHI?
- Which systems and devices can access that information?
- What threats could affect those systems?
- Which vulnerabilities currently exist?
- What security safeguards have we already implemented?
- How likely is a particular threat to occur?
- What would the potential impact be?
- Which risks require remediation?
- How should we prioritize those risks?
Ultimately, the goal isn’t simply to produce a report. Instead, organizations should understand their risks and use that information to make informed security decisions.
HIPAA Risk Analysis vs. Risk Management
Although the terms are closely related, risk analysis and risk management aren’t exactly the same.
First, risk analysis identifies and evaluates potential risks and vulnerabilities affecting ePHI. Then, risk management uses those findings to determine how the organization should address identified risks.
For example, an assessment might discover that employees can access Microsoft 365 using only a password.
In that situation, the risk analysis identifies compromised credentials as a potential threat and evaluates the likelihood and potential impact.
Afterward, the risk-management process may lead the organization to implement multi-factor authentication, strengthen account controls, review administrative privileges, or improve security monitoring.
Therefore, identifying a vulnerability is only the beginning. Organizations also need a practical process for prioritizing and addressing the risks they discover.
Why HIPAA Security Risk Assessments Matter
Healthcare organizations maintain sensitive information while simultaneously depending on technology for daily operations.
Because of this dependence, cybersecurity problems can quickly become operational problems. For example, a compromised account could expose sensitive information, while ransomware could prevent employees from accessing critical systems. Likewise, an outdated server may introduce vulnerabilities, and a failed backup can make recovery significantly more difficult.
As a result, a HIPAA security risk assessment can uncover weaknesses before they contribute to a larger incident.
Risk analysis also influences decisions throughout an organization’s security program. Consequently, medical and dental practices should view risk analysis as both a compliance responsibility and a practical cybersecurity tool.
What Should a HIPAA Security Risk Assessment Cover?
A HIPAA security risk assessment should examine much more than a server or electronic health record system.
In practice, ePHI may exist across workstations, cloud platforms, email, backups, mobile devices, and third-party applications. Therefore, the assessment should evaluate the broader environment in which patient information exists and moves.
Servers and Workstations
First, organizations should evaluate servers and employee workstations for issues such as:
- Supported operating systems
- Security updates
- Endpoint protection
- Encryption
- User permissions
- Administrative privileges
- Password policies
- Screen-lock configurations
- Software vulnerabilities
In addition, the assessment should identify aging hardware so the practice can plan replacements before unsupported technology creates unnecessary risk.
Ultimately, proactive lifecycle planning can reduce security exposure while lowering the likelihood of unexpected equipment failures.
EHR, EMR and Practice-Management Systems
Medical and dental organizations often rely heavily on EHR, EMR, and practice-management platforms.
Therefore, an assessment should consider:
- User access
- Account permissions
- Authentication
- Vendor access
- Remote connectivity
- Backup protection
- Audit capabilities
- Integration with other systems
The objective isn’t necessarily to audit the application itself. Instead, the organization should evaluate the technology environment and access controls surrounding sensitive information.
Microsoft 365 and Email
Email accounts remain attractive targets because compromised credentials may provide access to communications, files, contacts, and other resources.
For this reason, organizations should review areas such as:
- Multi-factor authentication
- Administrative accounts
- User permissions
- Email security
- Account activity
- External sharing
- Microsoft Defender
- Conditional Access where appropriate
- OneDrive and SharePoint configurations
Moreover, practices should maintain clear account-management procedures for employees who join the organization, change roles, or leave.
For example, administrators should promptly adjust or remove access when an employee no longer needs specific systems or information. As a result, organizations can reduce unnecessary access and strengthen accountability.
Network and Firewall Security HelpDesk DMV
Your network connects many of the systems your organization relies on. Therefore, network security should form an important part of the assessment.
Areas to review may include:
- Firewall configuration
- Network segmentation
- Wireless security
- Guest Wi-Fi
- Remote access
- VPN configurations
- DNS security
- Network equipment
- Firmware
- Internet-facing services
In addition, organizations should understand which systems are exposed to the internet and who can access them remotely.
For example, guest Wi-Fi should remain appropriately separated from internal systems containing sensitive information. Likewise, practices should review firewall rules and remote-access configurations as their technology environment changes.
Backup and Disaster Recovery
Having backups is important. However, a successful backup notification alone doesn’t prove that an organization can recover from a serious incident.
A risk assessment should examine:
- What data the organization backs up
- Backup frequency
- Retention
- Encryption
- Off-site protection
- Access to backup systems
- Backup monitoring
- Recovery procedures
- Restoration testing
Most importantly, organizations need to know whether they can actually restore critical information after an incident.
For this reason, practices should periodically test recovery procedures rather than relying solely on successful backup notifications. Furthermore, restricting access to backup systems can help reduce the risk that an attacker compromises both production data and recovery copies.
Remote Access
Remote access provides flexibility for employees and vendors. However, weak remote-access controls can also create significant security risk.
Therefore, organizations should identify every method used to connect remotely, including:
- VPNs
- Remote support applications
- Vendor connections
- Remote desktop services
- Administrative tools
In addition, practices should use strong authentication, restrict access to authorized users, and remove remote access when users no longer require it.
Cloud Applications
Healthcare organizations increasingly use cloud platforms for scheduling, communications, file sharing, billing, patient engagement, and other operations.
As a result, a risk assessment shouldn’t stop at equipment physically located inside the office.
Because cloud services operate outside the physical office, practices must include relevant services in the overall risk analysis. For example, organizations should review user permissions, authentication controls, external sharing, account lifecycle procedures, and the types of information stored within each service.
Additionally, they should evaluate vendor relationships and applicable agreements when those services handle ePHI.
Mobile Devices
Smartphones, tablets, and laptops may provide access to email, cloud applications, patient information, or internal resources.
Similarly, these devices can create additional pathways to sensitive information.
Organizations should evaluate:
- Device encryption
- Screen locks
- Remote management
- Lost-device procedures
- Application access
- Multi-factor authentication
- Remote-wipe capabilities
Consequently, appropriate security controls can reduce the potential impact if an employee loses a device or someone steals it.
Medical and Dental Technology
Healthcare environments may also contain specialized technology that traditional business assessments overlook.
For dental practices, this may include:
- Digital X-ray systems
- Imaging servers
- Intraoral cameras
- CBCT systems
- Operatory workstations
- Practice-management platforms
Likewise, medical practices may rely on EHR systems, telehealth platforms, diagnostic technology, patient portals, and connected medical devices.
Therefore, a healthcare security assessment should consider both traditional IT infrastructure and specialized clinical technology.
Common HIPAA Security Risks in Medical and Dental Practices
Although every environment is different, certain technology risks frequently deserve additional attention.
Missing Multi-Factor Authentication
A stolen password can give an attacker access to a user’s account. However, multi-factor authentication adds another barrier by requiring additional verification.
For this reason, organizations should prioritize MFA for email, Microsoft 365, remote access, administrative accounts, and other systems that provide access to sensitive information.
Shared User Accounts
Shared accounts make it difficult to determine which individual performed a particular action. Additionally, multiple employees may continue using the same password even after someone leaves the organization.
Instead, practices should provide individual user accounts and assign access according to job responsibilities.
As a result, administrators gain better accountability and can manage access more effectively.
Excessive Administrative Access
Employees don’t need administrator privileges simply because those permissions make certain tasks more convenient.
Instead, organizations should grant users only the level of access required for their responsibilities. Consequently, limiting administrative privileges can reduce the potential damage caused by malware or a compromised account.
Unsupported or Unpatched Systems
Outdated software may contain vulnerabilities that attackers can exploit.
In fact, HHS specifically addressed unpatched software in its January 2026 cybersecurity guidance.
Therefore, organizations should incorporate patch management and technology lifecycle planning into their broader security strategy.
Additionally, practices should identify unsupported operating systems and applications before they create unnecessary exposure.
Weak Backup Protection
Backups should never become an afterthought.
For example, ransomware may significantly reduce recovery options if an attacker can reach both production data and backup copies.
Therefore, organizations should evaluate backup architecture, permissions, monitoring, recovery testing, and access controls.
Ultimately, the question isn’t simply whether backups exist—it’s whether the organization can depend on them during a real emergency.
Inadequate Employee Offboarding
Former employees should lose access to organizational systems promptly.
Therefore, practices need a consistent process for disabling access to:
- Microsoft 365
- EHR or EMR systems
- VPNs
- Cloud applications
- Remote-access tools
- Other business systems
Likewise, administrators should review permissions when an employee changes roles. By doing so, organizations can prevent outdated access rights from accumulating over time.
Unsecured Remote Access
Remote access solutions that lack strong authentication or appropriate configuration can increase risk.
For this reason, organizations should identify every method employees, administrators, and vendors use to access systems remotely.
Furthermore, practices should restrict remote access to authorized users and review permissions regularly.
Limited Security Monitoring
No organization can prevent every cyberattack. Therefore, practices also need ways to detect suspicious activity when preventive controls fail.
For example, Endpoint Detection and Response, security logging, email protection, and other monitoring technologies can provide visibility into potential threats.
As a result, administrators may identify suspicious behavior sooner and respond before an incident becomes more serious.
How a HIPAA Security Risk Assessment Works
Although the exact process varies by organization, most HIPAA security risk assessments follow a structured series of steps.
First, the organization identifies where ePHI exists. Next, it evaluates threats, vulnerabilities, and current safeguards. After that, the organization prioritizes and documents risks so it can plan appropriate corrective actions.
Step 1: Identify Where ePHI Exists
To begin, identify where your organization creates, receives, maintains, or transmits ePHI.
Potential locations include:
- Servers
- Workstations
- EHR/EMR systems
- Dental practice-management systems
- Imaging systems
- Microsoft 365
- Cloud applications
- Backups
- Laptops
- Mobile devices
- Third-party systems
Step 2: Identify Potential Threats and Vulnerabilities
Next, identify threats and vulnerabilities that could affect the confidentiality, integrity, or availability of ePHI.
Examples include:
- Cyberattacks
- Ransomware
- Phishing
- Hardware failure
- Software vulnerabilities
- Human error
- Unauthorized access
- Lost or stolen devices
- Natural disasters
- Improper configurations
At this point, the organization should document relevant threats and vulnerabilities rather than relying on assumptions about what could go wrong.
Step 3: Review Existing Security Controls
Afterward, review the safeguards currently protecting your environment.
These might include:
- MFA
- Encryption
- Firewalls
- Endpoint protection
- Backups
- Access controls
- Security policies
- Monitoring
- Employee training
Step 4: Evaluate Likelihood and Impact
At this stage, evaluate both the likelihood of each threat and its potential impact.
Not every vulnerability creates the same level of risk. For example, a weakness affecting a critical system containing significant amounts of ePHI may deserve greater priority than a lower-impact issue.
Therefore, organizations should consider both probability and potential consequences when assigning risk levels.
Step 5: Prioritize Identified Risks
Once you understand the risks, prioritize them according to severity and urgency.
For example, critical vulnerabilities may require immediate remediation. In contrast, lower-risk improvements may become part of a longer-term technology roadmap.
As a result, the organization can focus resources on the issues that present the greatest potential impact.
Step 6: Document the Assessment
Then, document the findings, assigned risk levels, and planned corrective actions.
Accordingly, documentation should provide a useful record of identified risks and support the organization’s subsequent risk-management decisions.
Step 7: Develop a Risk-Management Plan
Finally, turn those findings into a practical risk-management and remediation plan.
Potential improvements may include:
- Enabling MFA
- Replacing unsupported computers
- Updating firewall configurations
- Improving backups
- Removing unnecessary permissions
- Implementing encryption
- Strengthening email security
- Improving monitoring
- Updating policies
- Training employees
Ultimately, the assessment should lead to measurable improvements rather than becoming a document that gets filed away and forgotten.
How Often Should You Conduct a HIPAA Security Risk Assessment?
This question deserves careful attention because organizations sometimes encounter misleading claims about a mandatory annual assessment.
The current HIPAA Security Rule doesn’t establish one universal risk-analysis frequency for every covered entity.
Instead, HHS describes risk analysis as an ongoing process and explains that the appropriate frequency varies depending on an organization’s circumstances.
Therefore, practices should revisit their risk analysis when meaningful changes occur.
For example, organizations may need to reassess risk after:
- Installing a new server
- Migrating to Microsoft 365
- Changing EHR/EMR systems
- Changing dental practice-management systems
- Opening another location
- Introducing new cloud applications
- Implementing remote work
- Experiencing a security incident
- Changing backup architecture
- Adding significant new technology
Additionally, organizations should review risks periodically because technology, personnel, threats, and business operations change over time.
HIPAA Security Risk Assessments for Dental Practices
Dental practices deserve specific attention because their technology environments can be surprisingly complex.
A single practice may operate practice-management software, imaging servers, digital X-ray equipment, CBCT systems, dozens of workstations, Microsoft 365, cloud applications, VoIP, and local network infrastructure.
Furthermore, imaging systems can accumulate significant amounts of patient data over many years.
A dental security assessment should therefore consider:
- Practice-management systems
- Imaging systems and servers
- Operatory workstations
- Front-office computers
- Microsoft 365
- Network security
- Wi-Fi
- Remote vendor access
- Backup and recovery
- User permissions
- Aging technology
Ultimately, dental cybersecurity requires an understanding of both conventional IT infrastructure and the specialized technologies supporting clinical workflows.
HIPAA Security Risk Assessments for Medical Practices
Medical practices face many of the same cybersecurity concerns. However, their environments may also include EHR systems, telehealth platforms, diagnostic equipment, patient portals, electronic prescribing, cloud platforms, and numerous third-party vendors.
Consequently, medical practices should evaluate both their core infrastructure and the pathways through which employees and vendors access sensitive information.
A healthcare IT risk assessment may examine:
- EHR/EMR access
- Microsoft 365
- Endpoint security
- Servers
- Networks
- Telehealth
- Remote access
- Backups
- Cloud services
- User permissions
- Vendor access
- Business continuity
Furthermore, organizations should consider how these systems interact rather than evaluating every technology in isolation.
HIPAA Compliance and Cybersecurity Are Not the Same Thing
HIPAA compliance and cybersecurity overlap significantly. However, the two concepts aren’t interchangeable.
For example, an organization may deploy strong cybersecurity tools yet still lack adequate policies, documentation, access-management procedures, or risk analysis.
Conversely, completing a compliance checklist doesn’t automatically protect an organization against modern cyber threats.
Therefore, healthcare organizations should integrate compliance and cybersecurity rather than treating them as separate initiatives.
Furthermore, organizations can use broader cybersecurity frameworks from NIST and CISA to strengthen their overall risk-management programs.
A Practical HIPAA Security Risk Assessment Checklist
Use this checklist as a starting point. However, don’t treat it as a substitute for a comprehensive assessment of your actual environment.
Systems and Data
- Have we identified where ePHI exists?
- Do we maintain an inventory of important technology?
- Do we understand how ePHI moves between systems?
User Access
- Does each employee have an individual account?
- Do permissions match job responsibilities?
- Do administrators promptly disable former employee accounts?
- Have we restricted administrator privileges appropriately?
Authentication
- Have we enabled MFA where appropriate?
- Do we maintain appropriate password controls?
- Have we secured remote-access accounts?
Workstations and Servers
- Do our devices run supported operating systems?
- Do we install security updates consistently?
- Have we deployed endpoint security?
- Do we appropriately protect sensitive information?
Microsoft 365 and Email
- Have we enabled MFA?
- Do we protect administrative accounts?
- Have we configured appropriate email security?
- Do we review sharing permissions?
Network Security
- Do we maintain the firewall?
- Have we secured Wi-Fi appropriately?
- Do we separate guest access where appropriate?
- Do we understand our internet-facing services?
Backup and Recovery
- Do we back up critical data?
- Do we monitor backup jobs?
- Have we appropriately protected backup copies?
- Have we tested restorations?
- Do we maintain a recovery plan?
Security Monitoring
- Can we detect suspicious endpoint activity?
- Do we review important security alerts?
- Do we have visibility into potential email threats?
Documentation and Risk Management
- Have we documented the risk analysis?
- Have we prioritized identified risks?
- Do we maintain a remediation plan?
- Do we track security improvements?
Most importantly, organizations should treat this checklist as the beginning of a conversation about risk—not proof that they have achieved HIPAA compliance.
Why Choose GuardIT for an IT & Security Assessment?
A useful IT and security assessment should produce more than a list of technical problems.
Instead, it should help leadership understand which technology risks matter most, what they should address first, and how improvements fit into the organization’s broader IT strategy.
For more than 20 years, GuardIT has helped businesses manage and protect their technology environments. Today, we provide healthcare and dental IT services throughout Washington DC, Maryland, and Northern Virginia with a proactive, cybersecurity-first approach.
Our services include:
- IT and security assessments
- Managed IT services
- 24/7 monitoring
- Unlimited remote and on-site support
- Cybersecurity
- Microsoft 365 management
- Endpoint security
- Network and firewall management
- Backup and disaster recovery
- Technology lifecycle planning
- Cloud services
- Strategic IT consulting
- HIPAA-focused technology guidance
Furthermore, we look beyond individual computers. Servers, endpoints, Microsoft 365, networks, backups, remote access, cloud platforms, and aging technology all contribute to an organization’s overall technology risk.
As a result, practices can gain a clearer picture of their IT environment and develop a practical roadmap for addressing weaknesses.
Frequently Asked Questions About HIPAA Security Risk Assessments
Is a HIPAA security risk assessment required?
Yes, for regulated entities subject to the HIPAA Security Rule’s risk-analysis requirement. The rule requires an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
How often is a HIPAA risk assessment required?
The current Security Rule doesn’t establish one universal frequency. Instead, HHS describes risk analysis as an ongoing process and explains that frequency varies depending on an organization’s circumstances.
Is a vulnerability scan the same as a HIPAA security risk assessment?
No. Although vulnerability scanning can provide useful technical information, a comprehensive risk analysis considers the organization’s ePHI, threats, vulnerabilities, existing safeguards, likelihood, potential impact, and overall environment.
Does completing a HIPAA checklist count as a risk assessment?
Not necessarily. While a checklist can help organize the process, simply checking boxes may not provide an accurate and thorough assessment of the organization’s actual risks and vulnerabilities.
Should dental practices conduct HIPAA risk assessments?
Dental practices that qualify as HIPAA-regulated entities must comply with applicable HIPAA Security Rule requirements. Therefore, their risk analysis should account for relevant specialized technologies such as practice-management systems, imaging platforms, operatories, networks, backups, and cloud services.
Does a HIPAA risk assessment include Microsoft 365?
When an organization uses Microsoft 365 to create, receive, maintain, transmit, or provide access to ePHI, it should consider the relevant Microsoft 365 environment within the scope of its risk analysis.
What happens after the assessment?
The findings should feed into the organization’s risk-management process. Therefore, organizations typically prioritize remediation, assign responsibilities, document corrective actions, and track progress.
Build a Stronger, More Secure Healthcare Practice
A HIPAA security risk assessment should provide more than evidence of a compliance exercise.
Instead, it should help medical and dental organizations understand their technology, identify vulnerabilities, prioritize improvements, and make informed security decisions.
As cyber threats continue to evolve, organizations need greater visibility into where sensitive information resides and how effectively they protect it. Furthermore, ongoing risk analysis can uncover vulnerabilities created by new technology, staffing changes, cloud adoption, and evolving threats.
Ultimately, proactive risk management can help protect patient information, strengthen business continuity, reduce cybersecurity exposure, and create a more resilient technology environment.
For healthcare and dental practices throughout Washington DC, Maryland, and Virginia, GuardIT combines proactive IT management, cybersecurity, backup and disaster recovery, Microsoft 365 expertise, and strategic technology planning to help organizations strengthen their IT environments.
Schedule Your IT & Security Assessment
Do you know where the biggest technology and cybersecurity risks exist within your practice?
GuardIT helps medical and dental practices throughout Washington DC, Maryland, and Virginia evaluate their IT environments and identify opportunities to improve security, reliability, and resilience.
During an assessment, we can help evaluate areas such as:
- Servers and workstations
- Microsoft 365
- Network security
- Firewalls
- User access
- Multi-factor authentication
- Endpoint security
- Backup and disaster recovery
- Remote access
- Aging technology
- Security monitoring
Ultimately, identifying technology risks before they become serious problems can help your organization make better security and IT decisions.
Contact GuardIT today to schedule an IT and security assessment and take the next step toward a more secure, reliable, and resilient technology environment.
Additional HIPAA & Cybersecurity Resources
For additional guidance on HIPAA security, risk analysis, and cybersecurity best practices, explore these authoritative resources:
U.S. Department of Health & Human Services — HIPAA Risk Analysis Guidance
Current HHS guidance on conducting risk analysis under the HIPAA Security Rule.
HHS HIPAA Risk Analysis Guidance
U.S. Department of Health & Human Services — HIPAA Security Rule
Official information regarding HIPAA Security Rule requirements and safeguards.
HHS HIPAA Security Rule
NIST SP 800-66 Revision 2
NIST guidance designed to help regulated organizations understand and implement HIPAA Security Rule cybersecurity safeguards.
NIST SP 800-66 Revision 2
CISA — Cross-Sector Cybersecurity Performance Goals
High-impact cybersecurity practices designed to help organizations prioritize cybersecurity improvements.
CISA Cybersecurity Performance Goals