See what our clients say about working with Bonami Software across 200+ projects for 18+ industries. EXPLORE NOW!
We don't just build software. We deliver results. EXPLORE NOW!
See why businesses choose Bonami Software for reliable, scalable solutions. EXPLORE NOW!
We turn ideas into scalable products with proven delivery across 18+ industries. EXPLORE NOW!
See what our clients say about working with Bonami Software across 200+ projects for 18+ industries. EXPLORE NOW!
We don't just build software. We deliver results. EXPLORE NOW!
See why businesses choose Bonami Software for reliable, scalable solutions. EXPLORE NOW!
We turn ideas into scalable products with proven delivery across 18+ industries. EXPLORE NOW!

HIPAA Risk Analysis Is What OCR Checks First.

We run the ePHI inventory, threat, and gap analysis the Security Rule requires — documentation that satisfies regulators and drives remediation.

BrowserStack
Persistent
Yatra
Kellton
Jade Global
Optum
PokerBaazi
Walmart
Turing
BrowserStack
Persistent
Yatra
Kellton
Jade Global
Optum
PokerBaazi
Walmart
Turing

Book Your Free Demo

See it working on your own workflows. We reply within 24 hours.

  • Your idea is 100% protected by our NDA
BrowserStack
Persistent
Yatra
Kellton
Jade Global
Optum
PokerBaazi
Walmart
Turing
BrowserStack
Persistent
Yatra
Kellton
Jade Global
Optum
PokerBaazi
Walmart
Turing

Trusted by startups and global leaders

BrowserStack
Persistent
Yatra
Kellton
Jade Global
Optum
PokerBaazi
Walmart
Turing
BrowserStack
Persistent
Yatra
Kellton
Jade Global
Optum
PokerBaazi
Walmart
Turing

What a HIPAA Risk Assessment Covers

The Security Rule requires a thorough assessment of every risk to ePHI — where it lives, what threatens it, and what controls close the gaps.

ePHI Inventory & Data Flow Mapping

Every location where ePHI is created, stored, or transmitted — databases, backups, email, mobile devices, third-party apps, and integrations.

Threat & Vulnerability Identification

External attackers, insider threats, system failures, and disasters — each evaluated against the weaknesses they could exploit, from unpatched software to weak authentication.

Likelihood & Impact Analysis

Each threat-vulnerability pair is scored by probability and impact — penalties, patient harm, reputational damage — so risk scores drive prioritization, not guesswork.

Control Evaluation & Gap Analysis

Current controls are tested against each risk, and gaps are mapped to HIPAA Security Rule specifications — required and addressable — so remediation targets the right controls.

Remediation Planning

A prioritized, owner-assigned remediation plan with timelines — your roadmap from current risk posture to defensible compliance, updated as gaps close.

OCR-Ready Documentation

A written report retained six years — the document OCR auditors request first — covering scope, findings, risk scores, controls, gaps, and remediation.

HIPAA Risk Analysis Is Foundational — Not Optional

Hover to see why risk analysis is the foundation of HIPAA compliance.

How We Conduct a HIPAA Risk Assessment

A five-step path from scope to OCR-ready documentation and a prioritized remediation roadmap.

Why a Current Risk Assessment Is a Compliance Necessity

A missing or stale risk analysis puts you on the defensive.

Book a Free Consultation
OCR First
OCR audits examine whether a risk analysis exists, is thorough, and is current — without one, you are on the defensive.
Pass Reviews
Enterprise health systems request the risk assessment before signing — a documented risk analysis is a prerequisite for selling to healthcare.
Prioritized
Risk scoring produces a prioritized remediation roadmap — highest-impact risks first. Without it, security spending is guesswork.
Always Live
A one-time assessment fails HIPAA's ongoing requirement — every new system, vendor, or PHI change restarts the clock.
6 Years
HIPAA requires retaining risk analysis documentation for six years — detailed enough for a regulator to reconstruct it later.
PHIPA Too
Canadian digital health companies face parallel obligations under PHIPA, HIA, and equivalent provincial legislation.

The Five Components HIPAA Requires Your Risk Analysis to Cover

OCR evaluates risk assessments against each component — any gap becomes an audit finding.

ePHI Inventory

Where ePHI Lives

Every location where ePHI exists across the organization's environment.

  • Databases and data warehouses
  • Backup and archive media
  • Email and messaging systems
  • Mobile devices and laptops
  • Third-party applications and APIs
Threats

Threat Identification

Threat actors and events that could compromise ePHI integrity.

  • External attackers and ransomware
  • Phishing and social engineering
  • Malicious or negligent insiders
  • System and hardware failures
  • Natural and environmental events
Vulnerabilities

Vulnerability Assessment

Technical and operational weaknesses threats could exploit.

  • Unpatched software and dependencies
  • Weak or shared authentication
  • Inadequate access controls
  • Misconfigured cloud services
  • Undocumented data flows
Risk Scoring

Likelihood & Impact

Threat-vulnerability pairs scored by likelihood and impact.

  • Likelihood rating per threat
  • Impact on ePHI confidentiality
  • Impact on ePHI integrity
  • Impact on ePHI availability
  • Combined risk level and priority
Controls

Current Controls & Gaps

Existing controls evaluated per risk, gaps mapped to Security Rule.

  • Required specification compliance
  • Addressable specification review
  • Control effectiveness evaluation
  • Gap identification and documentation
  • Remediation priority assignment
Documentation

OCR-Ready Report

Six-year retained documentation detailed enough for OCR scrutiny.

  • Assessment methodology and scope
  • Full findings and risk scores
  • Current controls documented
  • Gaps mapped to Security Rule
  • Prioritized remediation roadmap

The Risk Assessment Framework We Work From

Standards-based tooling and guidance to produce a risk analysis that satisfies OCR, enterprise healthcare customers, and provincial regulators.

HIPAA Security Rule H HIPAA Security Rule
45 CFR 164.308(a)(1) 4 45 CFR 164.308(a)(1)
HHS SRA Tool H HHS SRA Tool
PHIPA (Ontario) P PHIPA (Ontario)
HIA (Alberta) H HIA (Alberta)
Your Risk Assessment Is the Document OCR Asks For First.

A documented HIPAA risk analysis is the foundation of defensible compliance — and the first thing OCR requests. We conduct it and deliver a prioritized remediation roadmap your team can act on.

Book a Risk Assessment
AI Readiness

Award-Winning AI Development & Consulting

2025

100 Fastest Growth Companies

2025

Global Spring Winner

2025

Top App Development Company

2024

AWS Partner Network

2024

Google Cloud Partner

2025

Highly Rated on Trustpilot

2024

Verified Agency

2024

Top App Development Company

2024

ASSOCHAM Member

Frequently Asked Questions

[ 1 ]

How often should a HIPAA risk assessment be updated?

HIPAA sets no fixed interval, but you must reassess whenever significant changes occur — a new system, business associate, security incident, or change in how ePHI is processed. Most professionals recommend a full reassessment at least annually, treating it as a living document.

[ 2 ]

What is the HHS Security Risk Assessment Tool?

HHS OCR and ONC jointly developed the free Security Risk Assessment (SRA) Tool to help smaller healthcare organizations conduct HIPAA risk assessments. It offers a structured questionnaire, threat and vulnerability guidance, and reporting — a useful starting point for less complex environments.

[ 3 ]

What is the difference between a HIPAA risk assessment and a security audit?

A HIPAA risk assessment is an internal exercise evaluating your own risks, vulnerabilities, and controls against Security Rule requirements. A security audit is an external review — by a third party, an enterprise customer, or OCR — and a current risk assessment makes it go smoothly.

[ 4 ]

Does the HIPAA risk analysis requirement apply to Canadian companies?

HIPAA's risk analysis requirement applies to any covered entity or business associate handling ePHI of U.S. patients, wherever located. A Canadian digital health company serving U.S. healthcare is a Business Associate and must comply; PHIPA and provincial laws impose comparable obligations.

Global presence

Three offices. One team.

Hi, I'm ARIA. Ask me anything about Bonami's AI agents.