Get Demo
↑

HIPAA Security Risk Analysis Template (SRA)

Template outline for §164.308(a)(1) risk analysis — assets, threats, controls, residual risk, and remediation.

Published: September 2026 Compliance · HIPAA 8–12 min read

§164.308(a)(1) requires a risk analysis as part of the Security Management Process. This page is a template outline you can copy into your GRC tool. For narrative methodology see also HIPAA risk assessment guide.

Related: HIPAA hub · Checklist · CSA.

Required vs Addressable (Security Rule) — 45 CFR 164.306(d): Required implementation specifications must be implemented. Addressable specs: implement if reasonable and appropriate; if not, document why and implement an equivalent alternative measure if reasonable and appropriate. Addressable ≠ optional.

Documentation retention — 45 CFR 164.316(b)(2): retain Security Rule documentation for 6 years from the date of creation or the date when it last was in effect, whichever is later. This covers policies, procedures, and related documentation — not a separate “6-year SIEM log retention” statute. Operational log retention is a risk-based practice supporting audit controls (164.312(b)).

Template Sections

  1. Scope: legal entity, CE/BA role, facilities, systems with ePHI
  2. Asset inventory: applications, databases, endpoints, cloud accounts, medical devices, vendors
  3. Data flows: how ePHI is created, received, maintained, transmitted
  4. Threats & vulnerabilities: ransomware, insider misuse, misconfig, lost media, vendor failure
  5. Current controls: map to Administrative, Physical, Technical safeguards; note Required vs Addressable decisions
  6. Likelihood × impact: scoring method documented
  7. Risk treatment: mitigate / accept / transfer with owners and due dates
  8. Sign-off: Security Officer / leadership approval, date, next review date

No binary Excel file is hosted here. Request a working tracker via contact.

How CyberSilo Helps

Keep the SRA Alive Between Audits

Connect risk rows to monitoring findings so remediation status stays current.

Frequently Asked Questions

Is a risk analysis Required?

Yes. Risk analysis is part of the Security Management Process under §164.308(a)(1) and is frequently cited in OCR enforcement.

How often should we update it?

When ePHI environments change materially and on a scheduled review cadence; retain documentation for 6 years under 164.316(b)(2).

Can a vendor SRA replace ours?

Vendor assessments help BA oversight but do not replace your organisation’s analysis of systems under your control.

HIPAA hub · Risk assessment guide · Policies · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!