ONC and HHS OCR Release Updated HIPAA Security Risk Assessment Tool
Time 1 Minute Read

On September 13, 2023, the National Coordinator for Health Information Technology (“ONC”) and the Office for Civil Rights (“OCR”) at the U.S. Department of Health and Human Services released version 3.4 of the Security Risk Assessment (“SRA”) Tool under the Health Insurance Portability and Accountability Act (“HIPAA”) Security Rule.

The HIPAA Security Rule requires HIPAA covered entities to perform a risk assessment to identify and evaluate potential risks and vulnerabilities associated with the processing of electronic protected health information. The SRA is designed to assist small- and medium-sized covered entities with conducting the risk analyses required under the HIPAA Security Rule.

The latest version of the SRA Tool introduces a number of new features, including a glossary, updated references to the latest edition of the Health Industry Cybersecurity Practices, and a remediation report for tracking and recording responses. The SRA tool is available through the ONC’s website.

You May Also Be Interested In

Time 2 Minute Read

The U.S. Department of Health and Human Services’ Office for Civil Rights recently announced a settlement with health care software company MMG Fusion to resolve the company’s alleged noncompliance with the HIPAA Privacy, Security and Breach Notification Rules.

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Time 2 Minute Read

On February 19, 2026, the U.S. Department of Health and Human Services’ Office for Civil Rights announced a $103,000 settlement with Top of the World Ranch Treatment Center, an Illinois substance use disorder treatment provider, to resolve alleged noncompliance with the HIPAA Security Rule’s risk analysis requirement.

Time 2 Minute Read

The New York Office of the Attorney General recently reached a $500,000 settlement with a New York orthopedics practice for allegedly failing to protect patient and employee information in light of a 2023 data breach.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page