← Back to Services

HIPAA Risk Assessment

Comprehensive Security Risk Analysis for healthcare practices, dental offices, and medical clinics. Full compliance assessment covering all administrative, physical, and technical safeguards. Required by law. Your primary defense against OCR audits and breach liability.

What Is a HIPAA Risk Assessment?

The HIPAA Security Rule requires every covered entity and business associate to conduct a documented Security Risk Analysis. Not every practice does it. Those that don't face OCR fines and breach liability.

CLAS by Fred performs a comprehensive Security Risk Analysis that covers:

  • Administrative Safeguards: Security management, workforce security, information access management, security awareness and training, security incident procedures.
  • Physical Safeguards: Facility access controls, workstation security, workstation use policies, device and media controls.
  • Technical Safeguards: Access controls, audit controls, integrity controls, transmission security, encryption standards.
  • Environmental Factors: Business continuity, disaster recovery, third-party risk, vendor management and BAAs.

The Deliverable

You receive a comprehensive written Risk Assessment report (15–25 pages) that includes:

  • Executive summary of findings and risk level
  • Detailed findings by domain (admin, physical, technical)
  • Risk scores and prioritization matrix
  • Remediation roadmap with timeline and effort estimates
  • Regulatory citations and gap explanations
  • Recommendations for compliance frameworks

Why You Need This (Beyond Compliance)

The OCR (Office for Civil Rights) averages $1.5M per healthcare breach. Most breaches are preventable. A documented Security Risk Assessment proves to regulators that you identified and addressed risk intentionally — the legal standard for "reasonable safeguards."

Your liability insurance may also require it. Always check your coverage.

What's Included in the Assessment

Onsite Interviews
Meet with key staff (clinical, IT, admin) to understand workflows, decision-making, and current controls.
Systems & Infrastructure Review
Document hardware, software, network architecture, backups, encryption, and access controls.
Policy Audit
Review existing security policies against HIPAA requirements. Identify gaps and overlaps.
Vendor & BAA Assessment
Evaluate third-party risk (EHR, billing, cloud storage, etc.). Confirm BAAs are in place and current.
Workforce Security Review
Check access controls, offboarding procedures, and role-based permissions.
Incident Response Readiness
Evaluate breach detection, notification, and recovery procedures.

Typical Timeline

Engagement: 2–3 weeks from kickoff to delivery.

Onsite time: 8–12 hours (scheduled across 2–3 visits).

Report prep: 3–5 days after final onsite visit.

How to Prepare

  • Gather existing security policies, IT documentation, and vendor lists.
  • Confirm IT contact(s) and facility manager availability for interviews.
  • Document any recent security incidents or concerns.
  • Provide access to EHR, network infrastructure, and device inventory.

Next Steps After the Assessment

Once you have the Risk Assessment report, you'll know exactly what to fix. CLAS by Fred can help you:

  • Develop missing policies (Security, Incident Response, Access Control, etc.)
  • Create staff training programs tailored to your findings.
  • Implement technical controls via an MSP partner (we'll recommend one).
  • Track remediation progress with a Compliance Tracker and regular check-ins.
  • Retain ongoing vCISO support to stay audit-ready and monitor regulatory changes.

Frequently Asked Questions

Do I have to fix everything immediately?
No. The assessment identifies risks and prioritizes them. We create a roadmap with realistic timelines. You can tackle high-risk items first and spread medium/low-risk work over months. That's what a Compliance Tracker does.
Will this assessment replace my IT support?
No. HIPAA Risk Assessment is advisory — it identifies what needs to be fixed. Technical implementation (patching, encryption, backups, endpoint security) is handled by your MSP. We'll help you brief them on findings and track their work.
What if my practice is already compliant?
Great news — and unlikely. Even practices with mature IT teams find gaps. The assessment confirms compliance, identifies low-hanging fruit, and gives you a documented baseline for audits. It's also useful for insurance, board minutes, and investor confidence.
How much does this cost?
HIPAA Risk Assessment starts at $4,500 for small practices (1–15 employees, single location). Larger or multi-location practices may cost more. Contact us for a custom quote.
Can I keep the assessment confidential from the OCR?
Yes. Risk assessments prepared for legal advice are typically privileged. Discuss privilege protection with your attorney if you're concerned about OCR requests.