All Resources
Healthcare· 6 min read

HIPAA Security Risk Assessment — What's Actually Required

HIPAA Security Rule requires a documented risk assessment. The ONC tool is a starting point — not the finish line.

The HIPAA Security Rule (45 CFR 164.308(a)(1)) requires every covered entity and business associate to conduct an accurate and thorough assessment of risks to ePHI. The assessment is the foundation of every other security control.

FAQ

Frequently Asked Questions

Related Services

How PF Consulting Firm can help

Ready to get started?

Talk with our team — we'll prepare every form, file with the right agency, and walk you through the process.