HHS Issues Free Data Security Assessment Tool
9/25/2025
Recently
the U.S. Department of Health and Human Services (HHS) Office of the
National Coordinator for Health Information Technology (ONC), in
collaboration with the HHS Office for Civil Rights (OCR), developed an
updated free downloadable Security Risk Assessment (SRA) Tool to help guide health care providers conduct a security risk assessment as required by the HIPAA Security Rule. The
target audience of this tool is medium and small providers that may
lack resources or the expertise of full-time system security officers.
The Health Insurance Portability and Accountability Act (HIPAA) Security Rule requires that covered entities and its business associates conduct a risk assessment of their health care organization. A risk assessment helps organizations ensure compliance with HIPAA’s administrative, physical, and technical safeguards.
It also helps reveal areas where an organization’s protected health
information (PHI) could be at risk. To learn more about the assessment
process and how it benefits organizations, visit the Office for Civil Rights' official guidance.
Fast Facts and links to the Free SRA Tools:
The SRA Tool is a downloadable desktop Windows-based application
that walks users through the security risk assessment process using a
simple, wizard-based approach. Users are guided through 125
multiple-choice questions about threat and vulnerability assessments and
asset and vendor management. References and additional guidance are
given along the way. Reports are available to save and print after the
assessment is completed.