HIPAA BinderGet my forms

Your Security Risk Analysis, documented from your answers

The risk analysis is the document OCR asks for first, and the one most practices cannot produce. Map where patient information lives, answer the safeguard questionnaire (never anything about patients), and rate your own findings; your inventory and gap count fill in on the right as you go, free to read. $49 unlocks the full workbook: every answer documented with its 45 CFR citation, your rated risk register, and the remediation plan, instantly, and it counts toward the Complete Binder.

Need the Notice of Privacy Practices or a BAA instead? Generate your NPP or generate your BAA.

Exactly as registered; the workbook documents this entity’s analysis.

Your workbook, filling in livePreview

Security Risk Analysis Workbook45 CFR 164.308(a)(1)(ii)(A)

Security Risk Analysis Workbook

[Your practice legal name] [Practice street address]

Prepared from answers provided by [Your practice legal name] on July 29, 2026. Security Officer: [Security Officer name] · Date of analysis: July 29, 2026 · Next review due: July 29, 2027 (one year after the date of analysis)

This workbook documents this practice's own security risk analysis: the practice inventoried its systems, answered every safeguard question, and rated each finding's likelihood and impact itself. Written to satisfy the risk analysis requirement of 45 CFR 164.308(a)(1)(ii)(A), within the Security Management Process standard (164.308(a)(1)); organized to 45 CFR 164.308, 164.310, and 164.312.

Scope and method45 CFR 164.308(a)(1)(ii)(A)

Unlocks with download

ePHI asset and system inventory

Every system and device that creates, receives, maintains, or transmits electronic PHI, as identified by the practice. The safeguard questions and findings below apply to these systems.

[Check off where patient information lives in your practice and your inventory will appear here, each system with what it holds and what to confirm.]

Common threats to keep in mind while answering: phishing and credential theft, ransomware, a lost or stolen laptop or phone, wrong-patient fax or email, snooping by workforce, improper disposal, vendor breach, fire or flood or power loss, and a departed employee with live access. (Guidance note, not part of the document.)

Questionnaire summary

[Answer the 42 safeguard questions and your gap count will appear here: what is in place, what is partial, and what enters your risk register.]

Administrative safeguards45 CFR 164.308

Unlocks with download

Physical safeguards45 CFR 164.310

Unlocks with download

Technical safeguards45 CFR 164.312

Unlocks with download

Risk registerFindings rated by the practice

Unlocks with download

Remediation plan45 CFR 164.308(a)(1)(ii)(B)

Unlocks with download

Review and sign-off

Unlocks with download
Self-help compliance document, not legal adviceLive preview

Common questions

HIPAA Binder provides self-help compliance documents and educational information, not legal advice. The workbook documents your practice’s own self-assessment. We never ask for or store any patient information.