Free HIPAA risk assessment tools compared
Free HIPAA risk assessment options: what the U.S. Department of Health and Human Services (HHS) Security Risk Assessment Tool does, what state and vendor templates offer, and how each measures against the Office for Civil Rights (OCR) risk analysis requirement.
By CoreFolio
8-minute read
A free HIPAA risk assessment tool is any no-cost resource that helps an organization work through the risk analysis the HIPAA Security Rule requires. The main one is the Security Risk Assessment (SRA) Tool published by the U.S. Department of Health and Human Services (HHS). Beyond it, some state agencies publish templates or hold workshops, and many private vendors offer free template downloads.
A tool, though, is only a means. The HIPAA Security Rule requires a risk analysis at 45 CFR § 164.308(a)(1)(ii)(A), and the Office for Civil Rights (OCR) — the HHS office that enforces HIPAA — judges the finished analysis, not the software that produced it.1 This article describes each free option accurately, and sets out the standard OCR applies so a reader can measure any tool — free or paid — against it. For the step-by-step process, see how to do a HIPAA risk analysis.
What HIPAA requires of a risk analysis
The Security Rule requires a covered entity or business associate to "[c]onduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information" (ePHI) it holds.1 In 2010, OCR published Guidance on Risk Analysis Requirements under the HIPAA Security Rule.2 It describes nine elements an analysis must address:
- Scope of the analysis — all ePHI the organization creates, receives, maintains, or transmits, in any electronic medium.
- Data collection — identifying and documenting where that ePHI is stored, received, maintained, or transmitted.
- Identify and document potential threats and vulnerabilities.
- Assess current security measures — what is in place and whether it is configured and used properly.
- Determine the likelihood of threat occurrence.
- Determine the potential impact of threat occurrence.
- Determine the level of risk — for each threat-and-vulnerability combination, typically as a function of likelihood and impact.
- Finalize documentation — the Rule requires the analysis to be documented but prescribes no specific format (45 CFR § 164.316(b)(1)).
- Periodic review and updates — the analysis is ongoing, not a one-time event (45 CFR §§ 164.306(e), 164.316(b)(2)(iii)).
Two related points follow. The risk analysis is the input to a separate required step — risk management, at 45 CFR § 164.308(a)(1)(ii)(B), where the organization actually reduces the risks it found. And HHS "does not endorse or recommend any particular risk analysis or risk management model"; following a framework such as NIST SP 800-30 (from the National Institute of Standards and Technology) does not by itself prove compliance.2 Any tool is useful to the extent the completed, documented work covers the elements above.
The HHS Security Risk Assessment (SRA) Tool
The SRA Tool was developed by the Office of the National Coordinator for Health Information Technology (ONC), in collaboration with OCR, and is a free download from healthit.gov. Its stated audience is small and medium-sized providers; HHS notes it may not be appropriate for larger organizations.3
Two formats. The SRA Tool comes as an interactive Windows desktop application (installable on 64-bit Windows 7, 8, 10, or 11) and as an Excel Workbook containing the same questions, references, and risk-scoring system. The Workbook runs in Microsoft Excel or any program that reads .xlsx files — including on a Mac — and replaces the tool's legacy paper version. Neither format runs on a phone.3
Where the data lives. All entries are stored in an encrypted file on the user's own machine; HHS does not collect, view, store, or transmit anything entered into the tool. The Windows application supports multiple user accounts on that machine, but it does not sync across devices or to the cloud.3
What it does not do. HHS states plainly that use of the tool is "neither required by nor guarantees compliance with" federal, state, or local laws, and that the NIST standards it references are informational, not compliance requirements.3 The tool records the safeguards a practice reports and scores the risks it enters, but the accuracy of the result depends on the accuracy and completeness of those inputs — it does not inspect a network. It inventories vendors and business associates but does not draft business associate agreement (BAA) language or decide which relationships legally require one. It does not write policies or produce a remediation plan, and its content reflects the Security Rule in force today, not the changes proposed in the 2025 Security Rule Notice of Proposed Rulemaking (NPRM) (90 Fed. Reg. 898) — such as mandatory multi-factor authentication (MFA) and broader encryption — which is a proposal, not final law.4
State agency and extension-service resources
Some state health departments, Medicaid agencies, and university cooperative extension services publish HIPAA resources. These vary widely.
- Templates. Some states offer Word or Excel documents for recording a risk analysis. Others offer only general guidance.
- State-law context. State resources may address requirements that overlay HIPAA — for example, breach-notification timelines or medical-privacy statutes specific to that state.
- Workshops. Some agencies run in-person or virtual training.
Quality is inconsistent, and materials can go out of date. Many state templates are checklists rather than a structured analysis following a framework such as NIST SP 800-30, and they may reflect a specific program (such as Medicaid) rather than a complete Security Rule risk analysis. In California, for instance, the Center for Data Insights and Innovation (CDII, formerly the Office of Health Information Integrity, or CalOHII) and the Department of Public Health publish compliance and policy resources that emphasize California-specific laws such as the Confidentiality of Medical Information Act (CMIA) and the California Consumer Privacy Act (CCPA); those resources are not a substitute for a full HIPAA risk analysis.5
Vendor-provided free templates
Many HIPAA software vendors, electronic health record (EHR) vendors, and IT consultants offer free "HIPAA risk assessment templates," commonly as lead generation for paid products or services.
- Format. Usually a Word or Excel document with bracketed placeholders.
- Depth. The content is generic by design; the template shows what to record but not how to assess likelihood, impact, or risk level.
- Currency and quality. These documents vary in quality and are updated at the vendor's discretion.
A generic template filled in without careful, practice-specific analysis produces generic documentation. OCR has repeatedly identified risk analyses that are incomplete or not tailored to the organization as a source of enforcement findings.6
What every free tool leaves to the user
Free tools differ, but they share the same boundaries — boundaries that also apply, in large part, to paid self-assessment software:
- Input accuracy. A self-assessment reflects what the user enters. No questionnaire — free or paid — can identify a system, vendor, or gap the user does not report.
- Methodology judgment. A tool can structure the likelihood, impact, and risk-level steps, but the reasoning and the supporting rationale are the organization's to supply and document (elements 5–7 above).
- Risk management. Identifying a risk is not the same as reducing it. Remediation is the separate step required by 45 CFR § 164.308(a)(1)(ii)(B).
- Keeping current. The Security Rule treats risk analysis as ongoing. A saved report is a snapshot; periodic review and update remain the user's responsibility.
Choosing and using a free tool
Free tools have clear, legitimate uses:
- Learning. Working through the questions is a low-cost way to understand what the Security Rule covers.
- Preparation. Inventorying systems and vendors first can save time and cost before engaging a consultant.
- A budget-constrained starting point. A completed free-tool analysis is more than none, provided the organization understands the output is a starting point.
- Annual structuring. For a simple environment with in-house compliance knowledge, a free tool can organize a periodic review.
Whichever tool is used, the deliverable is measured the same way: does the documented analysis address the nine elements, does a risk management step follow it, and is it kept current?
The bottom line
The HHS SRA Tool, state templates, and vendor templates are legitimate, no-cost resources, and the SRA Tool in particular is maintained by HHS itself. None of them, by existing, satisfies 45 CFR § 164.308(a)(1)(ii)(A). What satisfies the requirement is an accurate, thorough, documented, and periodically updated risk analysis — followed by risk management — and that work depends on the organization's inputs and judgment, not on which tool records it. Running a free tool is a reasonable step; treating its output as a finished analysis without confirming it covers the elements above is the gap OCR examines.2
Sources
Footnotes
-
45 CFR § 164.308(a)(1)(ii)(A) (risk analysis); see also § 164.308(a)(1)(ii)(B) (risk management) and § 164.316(b) (documentation). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308 ↩ ↩2
-
HHS, Office for Civil Rights, Guidance on Risk Analysis Requirements under the HIPAA Security Rule (2010). https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html ↩ ↩2 ↩3
-
HHS, Office of the National Coordinator for Health Information Technology, Security Risk Assessment Tool (v3.6.1). https://www.healthit.gov/topic/privacy-security-and-hipaa/security-risk-assessment-tool ↩ ↩2 ↩3 ↩4
-
HHS, HIPAA Security Rule Notice of Proposed Rulemaking (90 Fed. Reg. 898, published January 6, 2025). A proposal, not final law. https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/index.html ↩
-
California Health and Human Services Agency, Center for Data Insights and Innovation (CDII), formerly the Office of Health Information Integrity (CalOHII). Compliance and policy resources for California state departments. https://www.cdii.ca.gov/compliance-and-policy/ ↩
-
HHS, Office for Civil Rights, Resolution Agreements and Civil Money Penalties. https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/index.html ↩