River
Y CombinatorBacked by Y Combinator
FREE TEMPLATE

HIPAA Security Risk Assessment Template

Three documents and three sheets that rate each system you actually hold against the threats that reach it, instead of ticking off specifications.

Free download  ·  No account needed

Asset and Data Register

Impact is derived from the record count

Illustrative rows for a fictional practice, Wraycombe Orthopaedics. The right-hand column is computed, never picked from a dropdown.

AssetRecordsCIAImpactIn use since
Imaging archive128,4005445Mar 2014
Legacy billing exports on a NAS63,9005215Sep 2011
Electronic health record41,2005554Jun 2017
Clearinghouse portal38,7004323Feb 2019
Email and calendar9,4003232Jan 2016
Ambient scribe vendor3,8005212Apr 2025
Online intake form vendor2,6004212Sep 2024

Last analysis current as of 4 March 2024. Shaded rows came into use after it.

The record system is not the top row. An archive of old billing exports nobody has opened in years outranks it, because impact is computed from what is in the asset rather than from how important the asset feels.

Remaining columns: Category, Record Count Source, Vendor, Access Count, Authentication, Encrypted At Rest, Encrypted In Transit, Backed Up, Restore Tested, Logs Retained, Analysis Current As Of, Owner, Notes.

Every free HIPAA security risk assessment template is the same object. A questionnaire with one row per implementation specification, a yes or a no, and sometimes a risk level chosen from a dropdown. Fill it in and you have a compliance checklist. The rule asks for something else: an assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of the electronic patient data the practice holds. Held where. A questionnaire has no inventory behind it, so it cannot say, and it cannot rate what it cannot locate.

This pack is asset-first. The register comes before any rating, which is the sequence NIST SP 800-66r2 calls the preparation step and describes as what makes threats identifiable at all. Every row in the analysis is one asset crossed with one threat that actually reaches it, rated twice: once as though nothing were in place, and once against safeguards somebody actually verified. Impact is computed from the record count on the asset, not chosen, which is the move that changes the answer.

Wraycombe Orthopaedics found eleven assets holding patient data and sixty-three applicable asset-threat pairs. The single highest-scoring pair, 25 of 25, sat on a legacy imaging server. Replacing it removes 42 points of risk over 25 days. Unique credentials with multi-factor authentication touch fourteen pairs across six assets and remove 102 points over three days, which is twenty times the rate. Ranked by score, the migration goes first. Ranked by risk removed per day of effort, it goes fourth.

Every document in the pack

The Threat and Safeguard Analysis, the Remediation Tracker, and what the analysis no longer covers.

Threat and Safeguard Analysis

One row per asset crossed with one threat that actually reaches it. Sixty-three pairs across eleven assets, not a full cross product.

AssetThreatLIInherentSafeguard verifiedResidual
Legacy imaging serverRansomware5525none25
Legacy billing exportsCredential theft4520none20
Imaging archiveCredential theft4520none20
Electronic health recordCredential theft4416policy only16
Electronic health recordInsider access3412Role review, Feb8
Staff laptopsLost device326Disk encryption2

Policy only is rated as none. The record system's multi-factor row is supported by a sentence in a policy and by no setting anybody could produce, so it is rated as though the control is absent and the report says that is what was done. This single discipline is most of the difference between this analysis and the practice's own estimate of itself.

The same threat crosses six assets. Credential theft appears on the record system, both archives, the clearinghouse portal, email and the backup console. That pattern is closed by one control, and it is invisible in a register organised by specification.

Every pair records why the threat applies, or why it does not. A threat marked not applicable with no reasoning is indistinguishable from a threat nobody considered.

Remediation Tracker

Ranked twice, because the two orderings disagree and the disagreement is the output.

ControlPairsRisk removedDaysPer dayBy score
Unique IDs and multi-factor14102334.02nd
Delete billing exports past retention655227.53rd
Automatic logoff936218.06th
Replace legacy imaging server442251.71st

Why the migration is not first

It owns the single worst pair in the register, 25 of 25, and it is a real finding. It is also 25 days of work that closes four rows on one asset. Three days of access control closes fourteen rows across six assets and removes two and a half times the risk. Both rankings are in the tracker so the practice argues with the order rather than inheriting it.

The deletion row

Deleting billing exports past their retention need is the only control here that reduces impact rather than likelihood, because it reduces the record count itself. Second highest rate in the register, two days of work, and it is on almost no practice's list.

A business associate agreement appears in the plan and not in the risk reduction column. It allocates consequence rather than lowering likelihood, and mixing the two breaks the arithmetic.

Coverage

What the analysis no longer covers

Last analysis current as of4 March 2024Assets in the register11
Assets adopted after that date3Their pairs15 of 63

The ambient scribe vendor, the online intake form vendor and the patient survey platform all came into use after the analysis was written. Twenty-four per cent of the register was never assessed, and the report's cover date says nothing about it.

Why the date is per asset

A risk analysis is a statement about a set of assets, not a file with a date on it. The Security Rule makes the trigger for re-evaluation an environmental or operational change rather than an anniversary, so the register carries an assessment date on every row and the weekly sweep reads that column instead of the report.

The separate clock

A practice attesting to a payment programme has a second obligation running on its own timetable, and the two are tracked apart rather than assumed to be the same thing.

The attestation takes its currency date from the oldest assessed asset, not from the day it was signed.

What's in the pack

01

Asset and Data Register

Every place patient data is created, received, maintained or transmitted, each with a record count and its source, so impact becomes a computed number rather than a dropdown selection. Vendor-held assets get a row here too, though the vendor and BAA management pack runs the deeper two-source discovery and BAA status check this register only summarizes.

02

Threat and Safeguard Analysis

One row per asset crossed with one threat that reaches it, rated inherent and residual, with a safeguard supported only by a policy sentence rated as absent.

03

Remediation Tracker

Ranks by risk removed per day of effort across every pair a control touches, and separately by highest single score, so the practice sees where the two disagree.

04

Risk Assessment Report

The ten-minute summary, including the section most reports omit: which assets the analysis does not reach and which safeguards nobody could verify.

05

Remediation Plan

Owners, dates and the evidence that will exist when each item is done. Accepted risks get the same written treatment as an addressable specification rather than a blank row.

06

Management Attestation

One signed page taking its currency date from the oldest assessed asset rather than the signature date, and refusing to attest to anything the registers do not support.

07

Risk Analysis Staleness Watch

A weekly read for assets adopted since the last assessment, safeguards whose verification has aged out, and remediations closed without the pairs being recalculated. It runs on the same weekly rhythm as the payer audit watch.

08

Seeded threat catalogue

Twelve threats a small practice actually faces, each mapped to the specifications it touches, with the applicability decision recorded either way rather than assumed. Bloodborne pathogen and hazard communication exposure sit outside this register entirely; the OSHA workplace safety pack runs those two determinations by role instead of by data asset.

How to use it

  1. 1

    Open in River, or download it

    Open the pack in River and let the agent build the asset register from your own documents, or download the blank Word and CSV files instantly and work through them yourself.

  2. 2

    Send an eighteen-month payment export

    The single highest-yield document and the one nobody offers unprompted. Money remembers the survey platform and the scribe tool that never made it onto anyone's system list.

  3. 3

    Count the records on each asset

    From a row count, a patient count or an export size, with the source recorded. This is what makes impact derivable, and it is why the ranking comes out different.

  4. 4

    Rate, then rank twice

    Every asset crossed with the threats that reach it, then remediation ordered by risk removed per day alongside the order by score. Argue with the difference.

Frequently asked questions

Is this template free?

Yes. Download the whole pack as Word documents and CSV sheets with no credit card. "Edit with AI" is a separate, optional path for practices that want the agent to build the asset register from their own documents. Other packs are in the template library.

What format are the downloaded files?

Word documents (.docx) for the report, the remediation plan and the attestation, and CSV (.csv) for the three registers, zipped into one file. They open natively in Word, Pages, Google Docs, Excel, Numbers and Sheets.

Why not use the questionnaire template I already have?

Because a yes or no against each implementation specification says whether you have a control, not what it protects or how much exposure it removes. Without an asset inventory there is nothing to rate, and the questionnaire cannot answer the question it is being used to answer.

How often does the assessment have to be repeated?

The Security Rule sets no interval. It requires evaluation in response to environmental or operational changes affecting the security of the data, so a new system or a new vendor is a trigger and an anniversary is not. Payment programmes may impose their own annual expectation separately.

Does this satisfy the Promoting Interoperability measure?

The measure requires conducting or reviewing a risk analysis under 45 CFR 164.308(a)(1), with actions occurring within the calendar year of the reporting period. This pack produces that work and the attestation behind it. Whether your submission qualifies is between you and your advisers.

Do I need a consultant to do this?

Not necessarily, and a consultant who hands back a specification questionnaire has not done this either. Where the practice runs complex infrastructure or is responding to an incident, get help. Either way the registers are what the help should be producing.

What does 'Edit with AI' actually do?

It creates a free River account, installs this exact pack as a private workspace, and opens it ready to read whatever you send. Nothing is written until you send something. The policy and evidence side of the same programme is a separate pack.

Rate the systems you hold, not the specifications you have

Download the blank pack as Word and CSV files, or open this exact pack in River and let the agent build the asset register from your own documents first.

Edit with AI