HHS OCR and ASTP Announce New Version Release of Security Risk Assessment Tool
Time 2 Minute Read

On November 1, 2024, the U.S. Department of Health and Human Services’ (“HHS”) Office for Civil Rights (“OCR”) and the Assistant Secretary for Technology Policy (“ASTP”) announced the release of a new version of the Security Risk Assessment (“SRA”) Tool. HHS developed the SRA Tool as a resource to assist small and medium-sized healthcare providers in complying with their obligations under the Health Insurance Portability and Accountability Act (“HIPAA”) Security Rule.

The SRA Tool is an interactive Microsoft Windows desktop application that HHS makes freely available for download on its website. It is intended to help healthcare organizations identify and assess potential risks and vulnerabilities to electronic protected health information on their systems and provide them with cybersecurity resources and best practices. HHS also released an updated SRA Tool User Guide. HHS notes that the SRA Tool is not designed with large healthcare providers in mind, and as such, may not be appropriate for those organizations.

Key updates to the SRA Tool include:

  • new and enhanced guidance and instructions;
  • updated references to the NIST Cybersecurity Framework (“CSF”) 2.0 (replacing NIST CSF 1.1);
  • references to the Healthcare and Public Health Cybersecurity Performance Goal;
  • new content on mitigating organizational threats and vulnerabilities; and
  • new content on cybersecurity supply chain risks.

As HHS continues to prioritize cybersecurity enforcement, the SRA Tool and User Guide provide useful insight into how HHS views the HIPAA risk analysis requirement, which is foundational to Security Rule compliance.

You May Also Be Interested In

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Time 2 Minute Read

On February 19, 2026, the U.S. Department of Health and Human Services’ Office for Civil Rights announced a $103,000 settlement with Top of the World Ranch Treatment Center, an Illinois substance use disorder treatment provider, to resolve alleged noncompliance with the HIPAA Security Rule’s risk analysis requirement.

Time 2 Minute Read

The New York Office of the Attorney General recently reached a $500,000 settlement with a New York orthopedics practice for allegedly failing to protect patient and employee information in light of a 2023 data breach.

Time 2 Minute Read

The Consumer and Governmental Affairs Bureau (“CBG”) has extended, to January 31, 2027, the effective date of the Federal Communications Commission’s (“FCC”) Telephone Consumer Protection Act (“TCPA”) “global revocation” rule.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page