Understanding the HIPAA Security Risk Assessment Tool

Understanding the HIPAA Security Risk Assessment Tool

Photo Attribution: Tashatuvango/Shutterstock.com

In October of 2019, the Department of Health and Human Services Office for Civil Rights (OCR) and the Office of the National Coordinator for Health Information Technology (ONC) released version 3.1 of the Security Risk Assessment Tool (SRA).

What does it do?

This downloadable tool acts as a preliminary risk assessment guide for small to medium healthcare providers. The HIPAA Security Rule mandates that providers conduct periodic risk assessments of their assets. While using the SRA Tool does not automatically make users HIPAA compliant nor 100 percent secure, it does assist them in identifying problematic aspects in their infrastructure, protocols and processes.

The tool is an independent application that stores the data locally only. It asks the user a number of simple questions related to existing HIPAA requirements. The user's answer to each question should help them determine if they must take action on the issue in question or not. Moreover, the tool allows providers to document additional comments and measures that will be taken to address any deficiencies.

How are the questions developed?

The SRA Tool questions are gathered from a number of resources, the first and most important of which is the HIPAA Security Rule itself. Furthermore, questions are also based on a number of National Institute of Standards and Technology (NIST) publications and the Health Information Technology for Economic and Clinical Health (HITECH) Act.

Why should you use it?

The SRA Tool is a great asset to have in your toolkit. Aside from it being an affordable starting point for small and medium providers, it is a user friendly way to identify potential vulnerabilities and threats to ePHI. Results of risk assessments are color coded and easy to understand. Moreover, it allows providers to assess all software and hardware involved with sensitive health records, including vendors and business associates. The SRA Tool can be used to conduct routine checks per the provider's needs.

Useful features


The tool takes into consideration that some terms may be unclear or require further information for the user to understand. Accordingly, in the event that users are unsure of what a word means, if it is underlined and in blue, they may click on it for clarification.


The SRA Tool asks users a series of questions relating to their implementation of standards mandated by HIPAA. It divides the questions into seven sections including:

  • SRA Basics

  • Security Policies, Procedures, & Documentation

  • Security & Your Workforce

  • Security & Your Data

  • Security & Your Practice

  • Security & Your Vendors

  • Contingency Planning

After each section, the Tool prompts the user to select potential vulnerabilities and rate threats in terms of potential impact. This pool of data is then used to determine the provider or BA's risk level with regard to that specific section.

Risk Report

At the end of the risk assessment, the Tool reveals a report that highlights any risk indications. The report includes a risk breakdown in the form of a color coded pie chart, a risk assessment rating key and areas that must be reviewed.

For more information visit the Security Risk Assessment Tool web page.

Client Success

  • 50% reduction in time to deploy Giva's change, incident, problem, asset management and knowledgebase modules
  • 60% reduction in the 5 year Total Cost of Ownership (TCO)
  • Saved at least 1 FTE due to lower ongoing administration
  • Saved 1 week per month due to easy to use reports
  • Increased to 90% achievement in meeting service level agreements
  • 70% reduction in generating reports and admin; eliminated 35 hours/month
  • 50% faster to create/assign a service request
  • 60% increase in information captured during the initial phone call
  • 50% increase in the number of service requests created due to intuitive design
  • 80% increase in productivity by using Giva's dashboards and reports
  • 60% increase in meeting service level agreements
  • 45% increase in the number of the calls logged due to Giva's intuitiveness and ease of use
  • 50% increase in productivity by using Giva's integrated custom forms