Most healthcare practices use these two terms interchangeably. That's a problem — because to OCR, only one of them satisfies a legal requirement. Mixing them up in your documentation is one of the fastest ways to fail an investigation you could have easily passed.

The one that's required by law

The HIPAA Security Risk Analysis (SRA) is a specific, documented activity required under 45 CFR §164.308(a)(1)(ii)(A). It's not a checkbox, not a vendor questionnaire, and not a conversation. It's a formal process that must:

Without this document in your file — current, signed, and specific to your environment — you are technically non-compliant regardless of how good your security actually is.

What most practices have instead

A risk assessment is an informal, broader review of your security posture. It might identify weak passwords, missing updates, or unencrypted laptops. Useful. But it is not a substitute for the SRA in an OCR audit.

Many IT vendors offer a "risk assessment" as part of their managed services. Some compliance consultants use the terms interchangeably to avoid scope conversations. The distinction matters when OCR comes asking.

Factor Security Risk Analysis (SRA) General Risk Assessment
Required by HIPAA? Yes — 45 CFR §164.308(a)(1) No explicit requirement
Scope All ePHI across all systems, locations, devices Varies — often limited to IT infrastructure
Output Formal written report with risk ratings and management plan Often a findings list or recommendations doc
OCR Audit Value Directly satisfies the requirement Does not satisfy the requirement alone
Frequency At least annually or after significant changes No formal requirement

What OCR actually looks for

OCR's Phase 2 audit protocol specifically requests the SRA document as a primary exhibit. Investigators look for:

The SRA is the single most cited deficiency in OCR investigations. Not because practices ignore security — but because they do the work informally and never document it properly.

Important distinction

The CLARITY Assessment offered by CLAS by Fred is a gap analysis and policy package — it identifies where you stand and delivers foundational documentation. It is not a formal HIPAA Security Risk Analysis under 45 CFR §164.308. The SRA is a separate engagement starting at $4,500. Ask about the difference before your next audit.

When you need to do one

You need a new or updated SRA whenever:

AI tools in particular are creating a new wave of SRA gaps. If your practice uses any AI-assisted documentation, scheduling, billing, or clinical decision support — and that tool touches ePHI — it must be in scope for your SRA.

The bottom line

A risk assessment helps you run a safer practice. A Security Risk Analysis keeps you legally defensible. You need both — but they are not the same document, and one cannot substitute for the other in an OCR investigation.

If you're unsure which one you have, or whether what you have would hold up to scrutiny, that's a conversation worth having before an auditor initiates it for you.