HIPAA BinderGet my forms

45 CFR § 164.308

Administrative safeguards

The Security Rule section that requires a risk analysis, and the most-cited deficiency in OCR enforcement.

Read the full official text on eCFR

Researched and written by Larry Osakwe · Last verified August 4, 2026

Checked against 45 CFR 164.308 via eCFR. Not a lawyer, not a certified compliance professional, and not affiliated with HHS.

How we research thisReport an error

What 164.308 actually says

164.308 is the administrative half of the Security Rule. It requires a security management process, and the first implementation specification under it is the risk analysis, which is marked Required rather than Addressable. There is no version of compliance that omits it.

The wording matters. The rule asks for an assessment that is accurate and thorough, covering all electronic PHI you hold. Not a questionnaire about your EHR: every system that touches ePHI, including email, backups, imaging and devices.

The paragraphs above are our plain-English reading. The blocks below are quoted verbatim from the regulation.

The text that matters

Risk analysis, Required
Risk analysis (Required). Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate.
Assigned security responsibility
Standard: Assigned security responsibility. Identify the security official who is responsible for the development and implementation of the policies and procedures required by this subpart for the covered entity or business associate.
Information system activity review
Information system activity review (Required). Implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports.

Quoted from 45 CFR § 164.308. US federal regulations are not subject to copyright. Retrieved from eCFR and last checked August 4, 2026.

What this section means you must hold

The regulation states obligations. This is the paperwork those obligations translate into, which is the part the regulation itself leaves you to work out.

The obligationWhat you produce for it
Conduct and document a risk analysis across every system holding ePHIA written Security Risk Analysis, dated, with the systems listed
Name a security official in writingA Security Official designation. In a solo practice this is you, and it still has to be written down.
Train the workforce and sanction violationsWritten policies, a training log with names and dates, a sanctions policy

Where practices get 164.308 wrong

Believing the EHR vendor did it. Your vendor can assess its own platform; it cannot assess your laptop, your email, your backup drive or your front desk. The second mistake is treating the risk analysis as one-time. It is the document OCR asks for first, and a five-year-old copy that predates your current systems answers the wrong question.

Other sections people look up

Educational summaries of federal regulations, not legal advice and not a determination about any specific practice. Where our reading and the regulation differ, the regulation controls; the eCFR link above is authoritative.

Get every document, done for you

Preview the binder free. Your binder is built to order and delivered within 30 days, with a full refund anytime before then.

See the binder and pricing