HIPAA Security Risk Analysis for Small Clinics: A Plain-English Walkthrough

A HIPAA security risk analysis is the required review of where patient data lives, what could go wrong and what you are doing about it. If you run a small medical, dental, therapy, or specialty clinic in the Portland area, you have probably heard "HIPAA security risk analysis" from an auditor, a cyber insurance application, or an EHR vendor. It sounds like something only hospital systems do. It is not. Under HIPAA, every covered entity and business associate that handles electronic protected health information (ePHI) is expected to do one.

The good news: it does not have to be a binder nobody reads. It is simply an honest look at where your patient data lives, what could go wrong, and what you are doing about it. Here is the process in plain English.

What a HIPAA security risk analysis is (and what it is not)

The HIPAA Security Rule requires covered entities and business associates to "conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability" of the ePHI they hold. That requirement sits at 45 CFR 164.308(a)(1)(ii)(A). The next line, 164.308(a)(1)(ii)(B), requires risk management: security measures that reduce those risks to a reasonable and appropriate level.

A few things a risk analysis is not:

  • Not just a vulnerability scan. A scan is a useful input, but it will not tell you that the front desk shares one login.
  • Not a certificate. HHS does not issue a "HIPAA certified" stamp.
  • Not a one-time project. HHS guidance treats risk analysis as an ongoing process that is updated as your clinic changes.

Why it matters for Portland clinics right now

The HHS Office for Civil Rights (OCR), which enforces HIPAA, has made risk analysis a named enforcement priority through its Risk Analysis Initiative. Recent OCR settlements, including ransomware and phishing cases, repeatedly cite a failure to conduct an accurate and thorough risk analysis.

There is also a regulatory change on the horizon. In January 2025, HHS published a proposed update to the HIPAA Security Rule that would make many expectations more specific, such as a written technology asset inventory and network map. That update is proposed, not final; the current Security Rule is what applies today. Cyber insurers and health system partners also increasingly ask whether you have a current analysis.

Step-by-step HIPAA security risk analysis for clinics

Step 1: Define your scope

List every place ePHI is created, received, maintained, or transmitted: your main office, any satellite location, staff who work from home, and mobile devices. If a provider checks the patient portal from a personal phone, that phone is in scope.

Step 2: Inventory your systems and data flows

Write down where patient information lives and how it moves. For most small clinics, that includes:

  • The EHR or practice management system, and whether it is cloud-hosted or on a local server
  • The patient portal and any online scheduling or intake forms
  • Email (usually Microsoft 365 or Google Workspace), plus e-fax and secure messaging tools
  • Imaging, lab, and billing systems, and the clearinghouse you send claims through
  • Workstations, laptops, phones, scanners, and backups
  • Vendors with access, and whether each has a signed business associate agreement (BAA)

Mapping data flows is also the foundation of data loss prevention; see our data loss prevention guide for Portland businesses.

Step 3: Identify threats and vulnerabilities

For each system, ask what could realistically go wrong: phishing that captures a password, ransomware that locks the EHR, a stolen laptop, a former employee whose account is still active, or a vendor breach. Then note the weaknesses that make those events more likely, such as missing multi-factor authentication (MFA), unpatched computers, shared logins, or backups that have never been test-restored.

Step 4: Review your current safeguards

Document what you already have in place. The Security Rule groups safeguards into three families: administrative (policies, training), physical (locked closets, device disposal), and technical (MFA, encryption, audit logs). Be honest: a policy that says "we encrypt all laptops" does not help if two never were.

Step 5: Rate likelihood and impact

For each threat, estimate how likely it is and how bad it would be, using a simple high, medium, low scale. Ransomware against an EHR server with no offline backup is usually high and high. The goal is to rank risks so you fix the biggest ones first.

Step 6: Build your risk management plan

Turn the ranked list into actions with an owner and a target date. Typical early wins include turning on MFA everywhere, retiring shared accounts, encrypting every device that touches ePHI, confirming BAAs with every vendor, setting up monitored and tested backups, and running short, regular security awareness training. Adding AI tools? Fold them in too; our post on AI and HIPAA for Portland healthcare practices covers what to check.

Step 7: Document it and keep it current

HIPAA requires that Security Rule documentation be kept for six years from the date it was created or last in effect, whichever is later (45 CFR 164.316). Save the analysis, the plan, and evidence of completed work. Revisit it when you add a new EHR, office, or major vendor, or after an incident. Many practices also review it yearly.

Free tools that help

HHS offers a free Security Risk Assessment (SRA) Tool, developed by the Office of the National Coordinator for Health IT together with OCR. It is designed for small and medium-sized providers and comes as a Windows application or an Excel workbook, with your answers stored locally. It is a great structure, but HHS notes the questionnaire alone may not identify every risk, so pair it with a real look at your systems and settings.

If the worst happens: breach notification in Oregon

Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering a breach of unsecured PHI. Breaches affecting 500 or more people must also be reported to HHS within that window, and to prominent media outlets when more than 500 residents of a state or jurisdiction are affected. Smaller breaches are reported to HHS within 60 days after the end of the calendar year.

Under Oregon’s ORS 646A.604, organizations that follow HIPAA breach rules are largely covered by that compliance, but they still must send the Oregon Attorney General a copy of the notice when a breach affects more than 250 Oregonians. Confirm the details for your situation with counsel.

Common mistakes we see in small practices

  • Copying a template and changing the name. OCR looks for an analysis that reflects your actual environment.
  • Leaving out the cloud and vendors. Microsoft 365, the patient portal, hosted EHRs, and BAAs all belong in scope.
  • Skipping the follow-through. A list of risks with no plan, owners, or dates does not reduce risk.
  • Never updating it. An analysis from two office moves ago does not describe your clinic today.

When to get HIPAA IT help

Most small clinics do not have a full-time IT person, which is where a good IT Provider Portland clinics can lean on helps. With managed IT services in Portland, the inventory, patching, MFA, backups, and monitoring that feed your risk analysis are handled every day, so the evidence is already there.

At PDX Information Technology Services, HIPAA-focused IT Support Portland clinics rely on is part of our managed services, not a one-off project. We sign a BAA, run a HIPAA-oriented security risk assessment with a prioritized fix list, and then keep working that list with you month after month. On-site support from Hillsboro to Gresham to Wilsonville to Vancouver WA, including Portland, Beaverton and Clackamas, with no trip fee; remote support anywhere in the U.S. You can see what is included on our HIPAA IT services for Portland clinics page.

We also want switching to feel safe. Clients can try us for 90 days and opt out if we’re not the right fit; after that, a 12-month agreement begins. That is the kind of peace of mind we think Portland IT Support should come with.

FAQ

How often should a small clinic do a HIPAA security risk analysis?

HIPAA treats risk analysis as an ongoing process rather than setting a fixed calendar interval in the current rule. Update it when something significant changes or after an incident; many practices also review it annually.

Is the free HHS SRA Tool enough on its own?

It is a solid framework, but HHS notes the questionnaire alone may not identify every risk. Combine it with a real review of devices, accounts, cloud settings, and vendors.

Can our IT provider do the risk analysis for us?

An IT partner can do most of the heavy lifting: inventory, technical review, and the fix list. Your practice still owns the decisions, since HIPAA responsibility stays with the covered entity.

What changes if the proposed HIPAA Security Rule update becomes final?

The January 2025 update is proposed, not final, so the current rule applies today. Practices with a current, well-documented analysis will have far less catching up to do if it is finalized.

Do we have to tell the Oregon Attorney General about a breach?

Under ORS 646A.604, if a breach affects more than 250 Oregonians, you must send the Attorney General a copy of your notice, even when following HIPAA breach rules.

Related: managed cybersecurity services · IT compliance services in Portland · backup and disaster recovery · data backup and recovery · managed IT for healthcare · BAA for IT providers

Ready for a clear picture of your clinic’s risk?

If you would like a calm, plain-English look at where your patient data lives and what to fix first, we would be glad to help. Our IT Services Portland team works with small healthcare practices across the metro from our office at 4800 Meadows Road #395 in Lake Oswego.

Book a time with Steve on Calendly or call us at 971-331-4871.

Running a healthcare practice in Clark County? See our HIPAA IT services in Vancouver, WA.

Get In Touch

Share On Social Media

Other Recent Blog Articles

What a BAA Means When You Hire an IT Provider for a Medical, Dental or Therapy Office

October 3, 2026

A plain-English look at the Business Associate Agreement (BAA) for IT providers: why an IT company that touches patient data is usually a business associate, what the agreement should cover, what it does not do, and what to ask before you sign. For Portland-area medical, dental and therapy offices.

AI for Construction Companies in 2026: Jobsite Productivity Without Leaking Bids or Plans

October 1, 2026

Practical AI for construction companies in the Portland metro: where AI helps (estimating drafts, RFIs, scheduling), what never leaves the job trailer (bids, plans, owner data), and how managed IT keeps field phones from becoming shadow AI.

AI Acceptable Use Policy for Small Business: A Practical Template for 2026

September 29, 2026

A practical AI acceptable use policy for Portland metro SMBs: what to approve and ban, never-paste rules, shadow AI, human review, rollout and training, plus a one-page template your team will actually follow.