← Back to Resources

Running Your First Security Risk Assessment: A Step-by-Step Workbook

A structured, NIST 800-66-aligned process for completing your HIPAA SRA without a consulting firm — including a risk register template, evidence checklist, and the six mistakes that get organisations cited.

RISK MATRIXLOWMEDHIGHCRITLIKELIHOODIMPACT

The SRA is the foundation of every HIPAA compliance programme.

The Security Risk Analysis requirement (§164.308(a)(1)) is the single most frequently cited HIPAA violation in HHS enforcement actions. It is also the requirement that unlocks every other safeguard — because without knowing your risks, you cannot make defensible decisions about your controls.

Many organisations either skip it entirely, complete a checkbox version that would not survive scrutiny, or pay a consulting firm $20,000+ for a report that gathers dust until the next audit cycle. This workbook gives you the structure to do it properly — and continuously.

A defensible SRA in six structured stages.

01

Define Scope and Asset Inventory

Identify every system, application, device, and workforce role that creates, receives, maintains, or transmits ePHI. If you use Axxess, your EHR, a scheduling platform, and shared network drives — all of these are in scope. Missing even one asset class is the most common SRA gap OCR investigators find.

02

Identify Threats and Vulnerabilities

For each asset, enumerate realistic threats (ransomware, insider misuse, lost laptop) and map them to existing vulnerabilities (no MFA, unpatched OS, no DLP policy). Use NIST 800-66 Appendix D as your starting threat catalogue — it maps directly to HIPAA Security Rule categories.

03

Assess Current Controls

Document what controls exist today and rate their effectiveness. This is not a pass/fail audit — it is an honest inventory. A control that is partially implemented should be documented as such, not inflated. Auditors compare your risk register to your control evidence; inconsistencies are red flags.

04

Calculate Risk Likelihood and Impact

Rate each threat-vulnerability pair on a likelihood × impact scale (typically 1–5 or Low/Medium/High/Critical). Protexa's risk matrix visualises your full exposure in a heatmap, updated in real time as controls are remediated — replacing the static annual spreadsheet.

05

Build and Assign Remediation Tasks

Every identified gap becomes a tracked remediation task with an owner, priority level, and due date. Without this step, the SRA is a document, not a programme. HIPAA requires you to implement security measures sufficient to reduce risk to a reasonable and appropriate level.

06

Document, Review, and Repeat

The SRA must be reviewed and updated periodically and in response to environmental or operational changes — not just annually. New vendor relationships, system migrations, workforce changes, and incident reports are all triggers for SRA updates. Your documentation is your defence.

Six patterns that turn a compliant SRA into a citation.

  • →Treating the SRA as a one-time event rather than a continuous programme
  • →Scoping only the EHR and ignoring email, file shares, and portable devices
  • →Using a vendor's generic template without customising it to your environment
  • →Rating all risks as "Low" to avoid remediation work — auditors are trained to spot this
  • →Completing the SRA but failing to document how risks were remediated
  • →No evidence linking the SRA output to actual control implementation
Protexa SRA Workflow

Protexa's Dynamic Risk Assessment module replaces static annual spreadsheets with a live risk heatmap. Run HIPAA Risk Assessments across all control families, track assessor progress, and monitor your compliance trend over a rolling 30-day window — with every gap automatically converted into a tracked remediation task.

Your SRA.
Automated.

Run your entire Security Risk Assessment inside Protexa — with real-time risk scoring, automated evidence requests, and a ready-to-export audit pack.

Book a Walkthrough← Back to Resources