HIPAA Risk Analysis for Dental and Medical Practices: What It Is and How Often

The HIPAA requirement practices most often skip: what a risk analysis must cover, how often to review it, and why regulators ask for it first.

3 min readVault Data Servers

If your practice has ever been asked "when did you last do a risk analysis?" and the honest answer was a shrug, you're in good company. It's the HIPAA requirement practices most often skip, and the one regulators most often find missing. It's also less mysterious than it sounds.

What the rule actually requires

The HIPAA Security Rule requires every covered entity — every dental and medical practice that handles electronic patient information — to conduct "an accurate and thorough assessment of the potential risks and vulnerabilities" to that information (45 CFR §164.308(a)(1)(ii)(A)). The very next requirement is risk management: actually doing something about what the assessment finds.

Two things are worth noticing. First, it isn't optional and it doesn't scale away for small offices; a three-chair practice has the same obligation as a hospital, sized to its own systems. Second, the regulation describes an outcome, not a form. There is no official template you fill in once and file.

What a real risk analysis covers

A useful risk analysis answers four questions, in writing:

  • Where does patient information live? The practice management system, imaging, email, the scanner that saves to a shared folder, the laptop that goes home, the backup drive, the phone system that records calls.
  • What could go wrong with each? Ransomware, a stolen laptop, a former employee whose account still works, a vendor with remote access nobody remembers granting.
  • How likely is it, and how bad would it be? Not every risk deserves the same attention. A shared front-desk password matters more than a theoretical attack on the thermostat.
  • What are you doing about it? The controls already in place, the gaps, and who is fixing each gap by when.

The output is a document a reasonable outsider could read and follow: an inventory, a list of risks with ratings, and a plan. If your "risk analysis" is a checklist with every box ticked and no inventory behind it, it won't survive a serious look.

How often

The rule doesn't name a frequency. In practice the expectation is an ongoing process: review it at least once a year, and again whenever something material changes — a new practice system, a move to cloud email, a second location, a merger, or a security incident. A risk analysis dated three years ago that describes a server you no longer own is evidence of a problem, not of compliance.

Why it keeps coming up

When the Office for Civil Rights investigates a breach or complaint, the first document it typically asks for is the risk analysis. A missing or superficial one has been the single most common finding in HIPAA enforcement for years, and since late 2024 OCR has run an enforcement initiative focused specifically on risk analysis. Practices that had a breach they couldn't have prevented have still paid settlements, because they couldn't show they had ever looked.

There is also a proposed overhaul of the Security Rule, published by HHS in January 2025, that would make many safeguards explicit — multi-factor authentication, encryption, a written technology asset inventory, and restoring critical systems within a set time. As of October 2026 it is still a proposal, with the federal regulatory agenda now listing final action for 2027. Either way, the risk analysis remains the foundation: the proposal builds on it rather than replacing it.

Doing it without it taking over your month

  • Start with the inventory. Most of the value is in simply listing every system, device and vendor that touches patient data. Practices are routinely surprised by what turns up.
  • Be specific about gaps. "Improve security" is not a finding. "Two former staff accounts still active in email" is, and it can be closed today.
  • Date and keep everything. HIPAA documentation must be retained for six years. Keep each year's version rather than overwriting it — the history is what shows an ongoing process.
  • Tie it to your cyber insurance. Renewal questionnaires ask many of the same questions. One honest document answers both.

The goal isn't a binder. It's knowing where your patient data is, what could happen to it, and what you're doing about it — and being able to show that on paper when someone asks.

How we handle this

Cybersecurity at Vault Data Servers

See the service
All articles

Talk to us

Want a second opinion on your setup?

Call us directly. You'll get someone who can answer the technical question, not read it off a script.

1.480.907.0700