Free template

Free HIPAA Risk Assessment Template

A working risk assessment workbook: asset inventory, threat/vulnerability pairing, scoring matrix, and a risk register that populates itself.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

A working risk assessment workbook: asset inventory, threat/vulnerability pairing, scoring matrix, and a risk register that populates itself.

What is in the download

  • Format: XLSX
  • Length: 1 page(s) / file(s)
  • Includes: rule citations, fill-in guidance in the margin, and a completed example
  • Licence: free to modify and use commercially

What is in the workbook

The workbook implements §164.308(a)(1)(ii)(A) — the required, non-addressable risk analysis — as a set of linked tabs rather than a questionnaire, because the regulatory standard is an accurate and thorough assessment of risks to your ePHI, and no questionnaire score meets it. The tabs, in working order: a methodology sheet stating the approach (aligned to the NIST SP 800-30 shape most assessors expect) with written definitions for every likelihood and impact level, so two assessors converge on what a “3” means; an asset inventory for every system that creates, receives, maintains, or transmits ePHI — with columns for data types, volume, owner, vendor, and BAA status; a data-flow view capturing where ePHI moves between systems and organisations; a threat and vulnerability pairing sheet, pre-seeded with the common pairs (phishing against email, ransomware against backups, lost devices against endpoints, misconfiguration against cloud storage) and room for your own; a scoring matrix that combines likelihood and impact after credit for current controls; and the risk register that populates itself from the pairing and scoring sheets, with treatment columns — mitigate with owner and date, or accept with signatory, rationale, and review date. The completed example is a filled workbook for a fictional 25-person telehealth company, which is the fastest way to calibrate your own scoring.

How to use it

  1. Read it end to end before filling anything in.
  2. Delete every clause describing a control you do not have. An untrue policy is evidence against you.
  3. Assign an owner and a review date to each section.
  4. Publish it, collect acknowledgements against the version number, and retain both for six years.

For a workbook, step two means score current controls honestly — crediting yourself with an MFA rollout that is 60% complete produces a register that understates your real exposure and overstates your defence.

How to customise it

Budget the real time where it belongs: the asset inventory is more than half the total effort, and it is interview work, not spreadsheet work — sit with engineering and operations and ask where the data actually is, because the documented architecture always misses the exports, the test databases, and the shared drives. Adjust the level definitions to your scale (an outage that is “critical” for a clinic may be “moderate” for a pure-software business associate) before scoring anything, and then never adjust them mid-assessment. Add threat pairs the seed list cannot know — your specific vendors, your specific legacy system. And treat the register as the living end-product: the workbook is designed for annual refresh and change-triggered updates, with each year saved as a dated version, because the six-year retention of §164.316 applies to the history and the version trail is itself evidence the programme runs continuously.

Common mistakes

  • Scoping to the EHR. A register with no row for email, backups, laptops, or the analytics warehouse is instantly implausible and the most common way an otherwise decent assessment fails review.
  • Threats floating free of assets. A generic threat list unpaired with your systems is the mark of a template exercise. The pairing sheet exists precisely to prevent it.
  • The all-medium diagonal. If every risk lands medium, the scoring avoided decisions and the register produces no remediation queue. The ranking is the point.
  • Silent risk acceptance. A high risk identified in year one and never mentioned again reads as negligence; the same risk with a signed acceptance and review date reads as governance. The register’s acceptance columns are the difference.
  • No management plan. The analysis has a required sibling at §164.308(a)(1)(ii)(B) — the treatment columns with owners and dates are that plan; leaving them blank delivers half the requirement.

The inventory built here feeds nearly everything else: the policy set should answer the risks this register ranks, the encryption and access control policies implement its most common mitigations, the incident response plan handles the threats that materialise anyway, and the annual review checklist schedules the refresh. The methodology reasoning — scales, accepted risk, repeatability — is covered in depth in the risk analysis guide and the broader risk assessment guide.

The honest limitation

A template is a starting point, not a program. It cannot record who acknowledged it, prove it was followed, or update itself when your environment changes. Those three things are what the platform does, and they are the difference between having documents and having compliance.

Start where you are

Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.

Questions

Is it really free?

Yes. Email address, instant download, no call required, no watermark, no expiry.

Can we edit and rebrand it?

Yes. Free to modify and use commercially. No attribution required.

Will using this make us compliant?

No. It gives you a defensible starting document. Compliance is what happens when the document describes what you actually do and you can prove it.

What is the catch?

You are on our email list until you unsubscribe, and we will occasionally mention that we sell a platform and services. That is the entire catch.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo