Skip to main content
CoreFolioHIPAA
Tools

The U.S. Department of Health and Human Services (HHS) Security Risk Assessment Tool: what it does well and where it falls short

A review of the free HHS Security Risk Assessment Tool: what it does well for a first HIPAA risk analysis, where it falls short, and whether it is defensible.

By CoreFolio

5-minute read

The U.S. Department of Health and Human Services (HHS) Security Risk Assessment (SRA) Tool is free, it comes from the government, and the Office for Civil Rights (OCR) helped build it and points to it as a starting point. For small practices doing a HIPAA risk analysis for the first time, it is usually the first thing they find.

The tool has real strengths and real limitations. Understanding both will help you decide whether it is right for your practice.

What the SRA Tool is

The HHS SRA Tool was developed by the Office of the National Coordinator for Health Information Technology (ONC) in collaboration with the HHS Office for Civil Rights (OCR). It is available for free download at healthit.gov, and HHS maintains and periodically updates it.

The application walks you through a structured set of questions based on the Security Rule requirements across administrative, physical, and technical safeguards. It serves questions using branching logic — your answers determine which follow-up questions you see — and each question includes a reference panel and education panel. At the end, it generates a report you can save or print, and all your answers stay stored locally on your own computer.

The genuine strengths

It is free and official. For a practice with no compliance budget, the SRA Tool is a legitimate starting point. It covers the major Security Rule requirements in a structured format. A practice that works through it thoughtfully is doing better than one that skips the risk analysis entirely.

It provides structure. The tool organizes the Security Rule into manageable sections, assigns questions to each section, and tracks your progress. That structure is valuable for someone approaching HIPAA compliance for the first time.

It produces a report. The output document, while basic, captures your answers in a format you can file. It is date-stamped and shows your responses. That is something.

OCR recognizes it. In its guidance on risk analysis, HHS explicitly points to the SRA Tool as one approach. Using it is not going to raise a flag with investigators the way using a completely informal process might.

It links questions to the rule. Each question carries a reference panel that ties it to the relevant HIPAA Security Rule citation and to National Institute of Standards and Technology (NIST) guidance such as SP 800-66 and SP 800-53, so you can see why a question is being asked and what the underlying rule requires.

The real limitations

No mobile or web version. The interactive SRA Tool is a Windows desktop application. Mac and Linux users are not shut out: HHS publishes an Excel Workbook version that carries the same questions and references and opens in Microsoft Excel — including on a Mac — or any program that reads .xlsx files, though some features and formatting work only in Excel. It calculates risk with built-in formulas rather than the guided wizard. Neither version runs on a phone. For non-Windows practices the practical trade-off is losing the wizard experience, not being unable to use the tool.

Not updated for the proposed Security Rule update. The Notice of Proposed Rulemaking (NPRM) published in January 2025 proposes significant changes — mandatory MFA, mandatory encryption, annual risk analysis, technology asset inventory requirements. As of this writing, the SRA Tool does not reflect these proposed changes. You can use the tool for the existing 2013 rule, but it will not help you assess your readiness for what is coming.

Proprietary data format (desktop app). In the Windows application your answers live inside a local database file. If you need to share your risk analysis with an auditor, an attorney, or a business partner, you export a PDF, but the underlying data is not easily portable, and if you lose the application you start from scratch. (The Excel Workbook, being a spreadsheet, is more portable — but it is a different file, not the same saved assessment.)

No remediation guidance. After you complete the assessment, the tool shows you which questions you answered in ways that indicate a gap. But it does not tell you what to do about it. The risk management plan — required separately under 45 CFR § 164.308(a)(1)(ii)(B) — is entirely up to you.

How OCR investigators actually respond to SRA Tool output

The SRA Tool output is not a safe harbor. Completing it does not by itself satisfy the risk-analysis requirement, and OCR continues to cite practices for risk-analysis failures — including practices that had run some form of assessment. When a tool-based analysis still falls short, the issue is usually one of three things:

  • The risk analysis was outdated (the tool was run once and not updated annually)
  • The scope was incomplete (the tool was completed for the electronic health record (EHR) but not for email, remote access, or vendor relationships)
  • The risk management plan did not follow (the tool was completed but nothing was done about the gaps it identified)

The tool is a legitimate starting point. It is not an end point.

Who should use the SRA Tool

Use the SRA Tool if:

  • You have no compliance budget and need to start somewhere
  • Your practice runs on Windows, or you are comfortable using the Excel Workbook on a Mac
  • You need a first-time baseline more than you need ongoing tracking
  • You are comfortable building your own risk management plan separately

Consider alternatives if you want the guided wizard but work primarily on Mac or mobile, you want your practice's facts — systems, vendors, devices, officers — saved as reusable records you maintain in one place and use across your other HIPAA documentation rather than only inside a single assessment file, the static PDF export does not fit how you file or share documentation, or you need an assessment that also covers your readiness against the proposed Security Rule update — not only the current rule the SRA Tool reflects.

The bottom line

The SRA Tool does what it says. It is free, it covers the major Security Rule requirements, and it produces a report you can file. For a practice that has done no risk analysis at all, using the SRA Tool is a meaningful improvement.

Its limitations \u2014 no mobile or web version, no coverage of the proposed Security Rule update, no remediation guidance beyond flagging gaps, and a desktop-app data file that is not easily portable \u2014 are real, and they are worth understanding before you commit to it as your long-term approach.