Accurate and thorough assessment
The SRA must identify all ePHI created, received, maintained, or transmitted by the entity, and assess risks to its confidentiality, integrity, and availability — no gaps, no assumptions.
The HIPAA Security Risk Analysis Engine assembles a documentation-complete Security Risk Analysis and Risk Management Plan — every required element, every asset inventory, every threat and vulnerability, mapped to the HIPAA Security Rule and NIST SP 800-66/800-30, checked against the letter of 45 CFR §164.308 before a credentialed assessor releases it.
Every HIPAA covered entity and business associate is legally required to conduct an 'accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability' of electronic protected health information — a Security Risk Analysis (SRA) — under 45 CFR § 164.308(a)(1)(ii)(A). It is not optional, it is not one-time, and it is the single most-frequently-cited deficiency in OCR investigations.
In late 2024 OCR launched a dedicated Risk Analysis Initiative — a targeted enforcement campaign against entities that failed to perform an adequate SRA. By early 2026 it had produced 11 enforcement actions, including PIH Health ($600,000), Northeast Radiology ($350,000), Health Fitness Corporation ($227,816), and a $90,000 settlement over a ransomware attack affecting ~14,000 patients — all citing the same root failure.
Most organizations run this by hand, from memory, once a year. The regulation has not been read end-to-end since the last time it mattered. That is exactly where completeness gaps hide.
The HIPAA Security Risk Analysis Engine exists to close that gap with a single, exhaustive standard applied identically to every file.
We do not summarize the law and hope. Every SRA is scored against a versioned rule pack tied to the exact text of 45 CFR §164.308(a)(1)(ii)(A) and supporting NIST guidance. These are the provisions each SRA is held to.
The SRA must identify all ePHI created, received, maintained, or transmitted by the entity, and assess risks to its confidentiality, integrity, and availability — no gaps, no assumptions.
A plan to reduce risks and vulnerabilities to a reasonable and appropriate level, with implementation schedule and assigned responsibility.
Policies and procedures for sanctioning workforce members who fail to comply with security policies.
Procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking.
Threat and vulnerability identification, likelihood and impact determination, risk level assignment, and control mapping per NIST guidance.
The SRA must be conducted at least once every 12 months, as reinforced by OCR's December 2024 NPRM. Our engine tracks the cadence and triggers renewal automatically.
AI extracts and drafts. Deterministic rules — running as code, outside the model — decide what is complete. A credentialed security assessor signs every release. That order is never reversed.
Upload your current SRA (if any) and entity details. We return a free completeness read: which statutory elements and control mappings you already have, and which are missing.
As your authorized clerical agent, we inventory all systems, devices, and data flows that create, receive, maintain, or transmit ePHI, corroborated across interviews and evidence.
We enumerate threats and vulnerabilities from the HIPAA Security Rule, NIST SP 800-30, and industry sources, mapped to your environment.
Asset inventory is reconciled to evidence; threat/vulnerability list is checked against the control library; risk levels are computed deterministically; any failure blocks release.
A credentialed security assessor reviews the risk determinations, signs the attestation, and certifies the SRA as OCR-defensible. High-risk or complex entities route to senior assessor review.
You receive the SRA report, risk register, risk management plan, evidence log, and attestation — ready for OCR audit, MIPS attestation, or payer security questionnaires.
The deliverable is completeness itself — every statutory element and control mapping accounted for or explicitly exception-coded. Nothing is left implicit.
The gates that decide completeness are code, not a model's opinion. A drafting error cannot slip past a regulatory requirement.
We prepare documentation and run assessments as your clerical agent. We never provide legal advice, make policy decisions, or act as your security officer.
Simple, predictable, and aligned with a documentation standard — not a cut of any recovery.
Start with a free Gap Scan. Send your current SRA (if any) and entity details and we'll return a completeness read against every subsection of 45 CFR §164.308.
Documentation-completeness service · not legal advice · your organization retains all responsibility for security decisions.