Most healthcare practices use these two terms interchangeably. That's a problem — because to OCR, only one of them satisfies a legal requirement. Mixing them up in your documentation is one of the fastest ways to fail an investigation you could have easily passed.
The one that's required by law
The HIPAA Security Risk Analysis (SRA) is a specific, documented activity required under 45 CFR §164.308(a)(1)(ii)(A). It's not a checkbox, not a vendor questionnaire, and not a conversation. It's a formal process that must:
- Identify the scope of all electronic Protected Health Information (ePHI) you create, receive, maintain, or transmit
- Identify reasonably anticipated threats to that ePHI
- Identify vulnerabilities in your current systems and processes
- Assess the likelihood and potential impact of each identified threat
- Document all findings and assign risk levels
- Feed directly into a written Risk Management Plan
Without this document in your file — current, signed, and specific to your environment — you are technically non-compliant regardless of how good your security actually is.
What most practices have instead
A risk assessment is an informal, broader review of your security posture. It might identify weak passwords, missing updates, or unencrypted laptops. Useful. But it is not a substitute for the SRA in an OCR audit.
Many IT vendors offer a "risk assessment" as part of their managed services. Some compliance consultants use the terms interchangeably to avoid scope conversations. The distinction matters when OCR comes asking.
| Factor | Security Risk Analysis (SRA) | General Risk Assessment |
|---|---|---|
| Required by HIPAA? | Yes — 45 CFR §164.308(a)(1) | No explicit requirement |
| Scope | All ePHI across all systems, locations, devices | Varies — often limited to IT infrastructure |
| Output | Formal written report with risk ratings and management plan | Often a findings list or recommendations doc |
| OCR Audit Value | Directly satisfies the requirement | Does not satisfy the requirement alone |
| Frequency | At least annually or after significant changes | No formal requirement |
What OCR actually looks for
OCR's Phase 2 audit protocol specifically requests the SRA document as a primary exhibit. Investigators look for:
- Date of the analysis and who conducted it
- Whether the scope covers all ePHI — not just what's on the server
- Documented threat and vulnerability identification
- Risk ratings (likelihood × impact) for each finding
- A corresponding Risk Management Plan that addresses identified risks
- Evidence the plan was implemented, not just written
The SRA is the single most cited deficiency in OCR investigations. Not because practices ignore security — but because they do the work informally and never document it properly.
The CLARITY Assessment offered by CLAS by Fred is a gap analysis and policy package — it identifies where you stand and delivers foundational documentation. It is not a formal HIPAA Security Risk Analysis under 45 CFR §164.308. The SRA is a separate engagement starting at $4,500. Ask about the difference before your next audit.
When you need to do one
You need a new or updated SRA whenever:
- You've never done one — start now
- Your last one is more than 12 months old
- You've changed EHR systems, added telehealth, or moved offices
- You've added staff who access ePHI
- You've experienced a breach or security incident
- You're onboarding new AI tools that touch patient data
AI tools in particular are creating a new wave of SRA gaps. If your practice uses any AI-assisted documentation, scheduling, billing, or clinical decision support — and that tool touches ePHI — it must be in scope for your SRA.
The bottom line
A risk assessment helps you run a safer practice. A Security Risk Analysis keeps you legally defensible. You need both — but they are not the same document, and one cannot substitute for the other in an OCR investigation.
If you're unsure which one you have, or whether what you have would hold up to scrutiny, that's a conversation worth having before an auditor initiates it for you.