How to Conduct a HIPAA Risk Analysis: A Step-by-Step Guide for Healthcare Organisations

Author: Eunoia Consulting Co. | Published: May 13, 2026

A practical, step-by-step guide to conducting a HIPAA risk analysis — the single most commonly cited deficiency in OCR enforcement actions. Covers scope, methodology, documentation, and risk management planning.

Key Takeaways

  • A HIPAA risk analysis is legally required under the Security Rule — not optional — and must be documented, comprehensive, and repeated regularly.
  • Risk analysis scope must include all systems that create, receive, maintain, or transmit ePHI — including AI tools and cloud platforms.
  • Likelihood and impact ratings must be assigned to each identified threat and vulnerability, not just catalogued.
  • AI-specific threats — model inversion, prompt injection, data poisoning — must now be included in every healthcare risk analysis.
  • OCR enforcement actions consistently cite inadequate risk analysis as the root cause of HIPAA penalties.

Why the HIPAA Risk Analysis Is the Foundation of Compliance

If there is one HIPAA requirement that healthcare organisations consistently fail to meet — and that the Office for Civil Rights (OCR) consistently cites in enforcement actions — it is the risk analysis. The HIPAA Security Rule at 45 CFR § 164.308(a)(1) requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all electronic protected health information (ePHI) they create, receive, maintain, or transmit.

This is not a one-time exercise. It is an ongoing process that must be updated whenever significant changes occur to your environment, systems, or operations — and reviewed at least annually.

The OCR's guidance makes clear that a risk analysis is the prerequisite for all other HIPAA Security Rule compliance. Without it, you cannot know what safeguards are appropriate, and you cannot demonstrate that your security programme is reasonable and appropriate for your specific environment.

What a HIPAA Risk Analysis Must Cover

The OCR's guidance on risk analysis identifies nine required elements:


A robust HIPAA risk analysis is the foundation of a compliant healthcare operation — but compliance is only one dimension of operational excellence. Eunoia Consulting Co.'s Healthcare Business Management Consulting service helps organisations build the governance, process, and management infrastructure that keeps compliance sustainable at scale. Learn more →


Once your risk analysis is complete, the next step is ensuring your AI systems meet HIPAA requirements before deployment. Read our companion guide: HIPAA AI Compliance Checklist: What Healthcare Organisations Must Do Before Deploying AI.