Security Risk AnalysisSRA
A Security Risk Analysis (SRA) is HIPAA’s required, documented assessment of the risks and vulnerabilities to the electronic PHI a practice holds. Under 45 CFR 164.308(a)(1)(ii)(A) it must be an accurate and thorough assessment of potential risks to the confidentiality, integrity, and availability of ePHI. It is the single most-cited deficiency in OCR enforcement.
Last verified: July 23, 2026
What SRA means under HIPAA
The requirement is short and specific. Section 164.308(a)(1)(ii)(A) directs a covered entity or business associate to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the electronic PHI it holds. Everything else in the administrative safeguards standard, including risk management, sanctions, and information-system activity review, builds on that analysis.
In OCR enforcement, a missing or superficial risk analysis is the most common finding, because it is both foundational and easy to skip. A defensible SRA inventories every system and location that stores or transmits ePHI (EHR, imaging, billing, portals, email, laptops, backups), identifies threats and vulnerabilities to each, rates the risk, and records what you decided to do about it. It is a document you produce, not a certificate you buy.
Because your systems and threats change, the SRA is not a one-time exercise. Review it at least annually and whenever you add a vendor, a location, or a new way of handling ePHI. A risk analysis that was accurate two software migrations ago is no longer accurate and thorough.
SRA FAQ
Related terms
PHI
45 CFR § 160.103
BAA
45 CFR § 164.502(e), § 164.504(e)
Breach Notification Rule
45 CFR §§ 164.400–414
See every term in the HIPAA glossary.
Turn the vocabulary into the documents
Knowing the terms is step one. See the full document set a covered practice keeps, or generate the ones you can build yourself now.
See what goes in a HIPAA binderSource
Last verified July 23, 2026. This definition is educational self-help information, not legal advice, and it paraphrases the regulation; the controlling text is 45 CFR § 164.308(a)(1)(ii)(A), linked above. Whether HIPAA applies to your practice depends on the covered-entity test. State law may add stronger requirements.