OCR Releases HIPAA Security Assessment Tool
Time 2 Minute Read
Categories: Health Privacy

On March 28, 2014, the Department of Health and Human Services’ (“HHS’”) Office for Civil Rights (“OCR”) released a tool to assist covered entities in complying with the HIPAA Security Rule requirement to conduct a risk assessment. The HIPAA Security Rule obligates covered entities to accurately and thoroughly assess “the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information” (“PHI”) they maintain. The tool, which is aimed at small to medium health care providers, was developed jointly by OCR and the HHS Office of the National Coordinator for Health Information Technology (“ONC”), and follows the National Institute of Standards and Technology’s development of a similar toolkit.

The tool contains 156 questions and resources that are designed to help health care providers:

  • Understand the context of each question;
  • Consider the potential impacts to PHI if certain HIPAA Security Rule requirements are not met; and
  • View the actual text of the HIPAA Security Rule.

HHS also developed a user guide and instructional videos to supplement the tool. Health care providers can store their answers and comments in the tool and view their current results at any time.

Upon its release, Susan McAndrew, Deputy Director of OCR’s Division of Health Information Privacy, noted that the tool “will greatly assist providers in performing a risk assessment to meet their obligations under the HIPAA Security Rule” while Karen DeSalvo, National Coordinator for Health Information Technology, commented that “[p]rotecting patients’ protected health information is important to all health care providers and the new tool we are releasing today will help them assess the security of their organizations.”

You May Also Be Interested In

Time 2 Minute Read

The U.S. Department of Health and Human Services’ Office for Civil Rights recently announced a settlement with health care software company MMG Fusion to resolve the company’s alleged noncompliance with the HIPAA Privacy, Security and Breach Notification Rules.

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Time 2 Minute Read

On February 19, 2026, the U.S. Department of Health and Human Services’ Office for Civil Rights announced a $103,000 settlement with Top of the World Ranch Treatment Center, an Illinois substance use disorder treatment provider, to resolve alleged noncompliance with the HIPAA Security Rule’s risk analysis requirement.

Time 2 Minute Read

The New York Office of the Attorney General recently reached a $500,000 settlement with a New York orthopedics practice for allegedly failing to protect patient and employee information in light of a 2023 data breach.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page