HIPAA Security Risk Assessment Template
Three documents and three sheets that rate each system you actually hold against the threats that reach it, instead of ticking off specifications.
Free download · No account needed
Asset and Data Register
Impact is derived from the record count
Illustrative rows for a fictional practice, Wraycombe Orthopaedics. The right-hand column is computed, never picked from a dropdown.
| Asset | Records | C | I | A | Impact | In use since |
|---|---|---|---|---|---|---|
| Imaging archive | 128,400 | 5 | 4 | 4 | 5 | Mar 2014 |
| Legacy billing exports on a NAS | 63,900 | 5 | 2 | 1 | 5 | Sep 2011 |
| Electronic health record | 41,200 | 5 | 5 | 5 | 4 | Jun 2017 |
| Clearinghouse portal | 38,700 | 4 | 3 | 2 | 3 | Feb 2019 |
| Email and calendar | 9,400 | 3 | 2 | 3 | 2 | Jan 2016 |
| Ambient scribe vendor | 3,800 | 5 | 2 | 1 | 2 | Apr 2025 |
| Online intake form vendor | 2,600 | 4 | 2 | 1 | 2 | Sep 2024 |
Last analysis current as of 4 March 2024. Shaded rows came into use after it.
The record system is not the top row. An archive of old billing exports nobody has opened in years outranks it, because impact is computed from what is in the asset rather than from how important the asset feels.
Remaining columns: Category, Record Count Source, Vendor, Access Count, Authentication, Encrypted At Rest, Encrypted In Transit, Backed Up, Restore Tested, Logs Retained, Analysis Current As Of, Owner, Notes.
Every free HIPAA security risk assessment template is the same object. A questionnaire with one row per implementation specification, a yes or a no, and sometimes a risk level chosen from a dropdown. Fill it in and you have a compliance checklist. The rule asks for something else: an assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of the electronic patient data the practice holds. Held where. A questionnaire has no inventory behind it, so it cannot say, and it cannot rate what it cannot locate.
This pack is asset-first. The register comes before any rating, which is the sequence NIST SP 800-66r2 calls the preparation step and describes as what makes threats identifiable at all. Every row in the analysis is one asset crossed with one threat that actually reaches it, rated twice: once as though nothing were in place, and once against safeguards somebody actually verified. Impact is computed from the record count on the asset, not chosen, which is the move that changes the answer.
Wraycombe Orthopaedics found eleven assets holding patient data and sixty-three applicable asset-threat pairs. The single highest-scoring pair, 25 of 25, sat on a legacy imaging server. Replacing it removes 42 points of risk over 25 days. Unique credentials with multi-factor authentication touch fourteen pairs across six assets and remove 102 points over three days, which is twenty times the rate. Ranked by score, the migration goes first. Ranked by risk removed per day of effort, it goes fourth.
What's in the pack
Asset and Data Register
Every place patient data is created, received, maintained or transmitted, each with a record count and its source, so impact becomes a computed number rather than a dropdown selection. Vendor-held assets get a row here too, though the vendor and BAA management pack runs the deeper two-source discovery and BAA status check this register only summarizes.
Threat and Safeguard Analysis
One row per asset crossed with one threat that reaches it, rated inherent and residual, with a safeguard supported only by a policy sentence rated as absent.
Remediation Tracker
Ranks by risk removed per day of effort across every pair a control touches, and separately by highest single score, so the practice sees where the two disagree.
Risk Assessment Report
The ten-minute summary, including the section most reports omit: which assets the analysis does not reach and which safeguards nobody could verify.
Remediation Plan
Owners, dates and the evidence that will exist when each item is done. Accepted risks get the same written treatment as an addressable specification rather than a blank row.
Management Attestation
One signed page taking its currency date from the oldest assessed asset rather than the signature date, and refusing to attest to anything the registers do not support.
Risk Analysis Staleness Watch
A weekly read for assets adopted since the last assessment, safeguards whose verification has aged out, and remediations closed without the pairs being recalculated. It runs on the same weekly rhythm as the payer audit watch.
Seeded threat catalogue
Twelve threats a small practice actually faces, each mapped to the specifications it touches, with the applicability decision recorded either way rather than assumed. Bloodborne pathogen and hazard communication exposure sit outside this register entirely; the OSHA workplace safety pack runs those two determinations by role instead of by data asset.
How to use it
- 1
Open in River, or download it
Open the pack in River and let the agent build the asset register from your own documents, or download the blank Word and CSV files instantly and work through them yourself.
- 2
Send an eighteen-month payment export
The single highest-yield document and the one nobody offers unprompted. Money remembers the survey platform and the scribe tool that never made it onto anyone's system list.
- 3
Count the records on each asset
From a row count, a patient count or an export size, with the source recorded. This is what makes impact derivable, and it is why the ranking comes out different.
- 4
Rate, then rank twice
Every asset crossed with the threats that reach it, then remediation ordered by risk removed per day alongside the order by score. Argue with the difference.
Frequently asked questions
Is this template free?
Yes. Download the whole pack as Word documents and CSV sheets with no credit card. "Edit with AI" is a separate, optional path for practices that want the agent to build the asset register from their own documents. Other packs are in the template library.
What format are the downloaded files?
Word documents (.docx) for the report, the remediation plan and the attestation, and CSV (.csv) for the three registers, zipped into one file. They open natively in Word, Pages, Google Docs, Excel, Numbers and Sheets.
Why not use the questionnaire template I already have?
Because a yes or no against each implementation specification says whether you have a control, not what it protects or how much exposure it removes. Without an asset inventory there is nothing to rate, and the questionnaire cannot answer the question it is being used to answer.
How often does the assessment have to be repeated?
The Security Rule sets no interval. It requires evaluation in response to environmental or operational changes affecting the security of the data, so a new system or a new vendor is a trigger and an anniversary is not. Payment programmes may impose their own annual expectation separately.
Does this satisfy the Promoting Interoperability measure?
The measure requires conducting or reviewing a risk analysis under 45 CFR 164.308(a)(1), with actions occurring within the calendar year of the reporting period. This pack produces that work and the attestation behind it. Whether your submission qualifies is between you and your advisers.
Do I need a consultant to do this?
Not necessarily, and a consultant who hands back a specification questionnaire has not done this either. Where the practice runs complex infrastructure or is responding to an incident, get help. Either way the registers are what the help should be producing.
What does 'Edit with AI' actually do?
It creates a free River account, installs this exact pack as a private workspace, and opens it ready to read whatever you send. Nothing is written until you send something. The policy and evidence side of the same programme is a separate pack.
Rate the systems you hold, not the specifications you have
Download the blank pack as Word and CSV files, or open this exact pack in River and let the agent build the asset register from your own documents first.
Edit with AI