45 CFR § 164.308(a)(1)(ii)(A) Every subsection, on every pack — verified, not assumed

The most rigorous §164.308 SRA a healthcare organization can get.

The HIPAA Security Risk Analysis Engine assembles a documentation-complete Security Risk Analysis and Risk Management Plan — every required element, every asset inventory, every threat and vulnerability, mapped to the HIPAA Security Rule and NIST SP 800-66/800-30, checked against the letter of 45 CFR §164.308 before a credentialed assessor releases it.

Every subsection of 45 CFR §164.308(a)(1)(ii)(A)Asset inventory & ePHI flow mappingThreat/vulnerability enumeration & control mappingCredentialed assessor release on every SRA5-business-day SLA
Why SRAs fail

A single missing element can trigger an OCR penalty.

Every HIPAA covered entity and business associate is legally required to conduct an 'accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability' of electronic protected health information — a Security Risk Analysis (SRA) — under 45 CFR § 164.308(a)(1)(ii)(A). It is not optional, it is not one-time, and it is the single most-frequently-cited deficiency in OCR investigations.

In late 2024 OCR launched a dedicated Risk Analysis Initiative — a targeted enforcement campaign against entities that failed to perform an adequate SRA. By early 2026 it had produced 11 enforcement actions, including PIH Health ($600,000), Northeast Radiology ($350,000), Health Fitness Corporation ($227,816), and a $90,000 settlement over a ransomware attack affecting ~14,000 patients — all citing the same root failure.

Most organizations run this by hand, from memory, once a year. The regulation has not been read end-to-end since the last time it mattered. That is exactly where completeness gaps hide.

The HIPAA Security Risk Analysis Engine exists to close that gap with a single, exhaustive standard applied identically to every file.

#1
most-cited deficiency in OCR investigations
The benchmark

Measured against the letter of the regulation — subsection by subsection.

We do not summarize the law and hope. Every SRA is scored against a versioned rule pack tied to the exact text of 45 CFR §164.308(a)(1)(ii)(A) and supporting NIST guidance. These are the provisions each SRA is held to.

45 CFR §164.308(a)(1)(ii)(A)

Accurate and thorough assessment

The SRA must identify all ePHI created, received, maintained, or transmitted by the entity, and assess risks to its confidentiality, integrity, and availability — no gaps, no assumptions.

45 CFR §164.308(a)(1)(ii)(B)

Risk management plan

A plan to reduce risks and vulnerabilities to a reasonable and appropriate level, with implementation schedule and assigned responsibility.

45 CFR §164.308(a)(1)(ii)(C)

Sanction policy

Policies and procedures for sanctioning workforce members who fail to comply with security policies.

45 CFR §164.308(a)(1)(ii)(D)

Information system activity review

Procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking.

NIST SP 800-66r2 / 800-30

Risk assessment methodology

Threat and vulnerability identification, likelihood and impact determination, risk level assignment, and control mapping per NIST guidance.

45 CFR §164.308(a)(1)(ii)(A) (annual)

Annual recurrence

The SRA must be conducted at least once every 12 months, as reinforced by OCR's December 2024 NPRM. Our engine tracks the cadence and triggers renewal automatically.

How an SRA is built

Intake to assessor release, with deterministic gates the AI cannot overrule.

AI extracts and drafts. Deterministic rules — running as code, outside the model — decide what is complete. A credentialed security assessor signs every release. That order is never reversed.

01

Gap Scan

Upload your current SRA (if any) and entity details. We return a free completeness read: which statutory elements and control mappings you already have, and which are missing.

02

Asset inventory & ePHI flow mapping

As your authorized clerical agent, we inventory all systems, devices, and data flows that create, receive, maintain, or transmit ePHI, corroborated across interviews and evidence.

03

Threat & vulnerability enumeration

We enumerate threats and vulnerabilities from the HIPAA Security Rule, NIST SP 800-30, and industry sources, mapped to your environment.

04

Deterministic completeness gates

Asset inventory is reconciled to evidence; threat/vulnerability list is checked against the control library; risk levels are computed deterministically; any failure blocks release.

05

Assessor release

A credentialed security assessor reviews the risk determinations, signs the attestation, and certifies the SRA as OCR-defensible. High-risk or complex entities route to senior assessor review.

06

Delivery

You receive the SRA report, risk register, risk management plan, evidence log, and attestation — ready for OCR audit, MIPS attestation, or payer security questionnaires.

The bar we hold

Rigor you can measure.

100%
Assessor-released
No SRA ships without a credentialed assessor's signature.
5 days
Standard SLA
From complete intake to released SRA.
<1%
Critical-defect target
Tracked against a gold-standard SRA library.
3
Control frameworks mapped
HIPAA Security Rule · NIST SP 800-66 · NIST SP 800-30, every applicable control.
Why the HIPAA Security Risk Analysis Engine

Built to be the most thorough option a healthcare organization has.

Documentation-complete, by design

The deliverable is completeness itself — every statutory element and control mapping accounted for or explicitly exception-coded. Nothing is left implicit.

Deterministic, not vibes

The gates that decide completeness are code, not a model's opinion. A drafting error cannot slip past a regulatory requirement.

In its lane, on purpose

We prepare documentation and run assessments as your clerical agent. We never provide legal advice, make policy decisions, or act as your security officer.

Engagement

Flat fee, per released SRA. No hourly billing, ever.

Simple, predictable, and aligned with a documentation standard — not a cut of any recovery.

  • A free Gap Scan before you commit — see exactly what is missing.
  • One flat fee per released SRA; disclosed pass-through costs for any third-party evidence requests.
  • Optional fixed-fee senior assessor review for complex or high-risk entities.
  • Optional Annual Renewal Add-on for automatic re-assessment and updated report each year.
FAQ

Questions, answered precisely.

Is the HIPAA Security Risk Analysis Engine a law firm?
No. The HIPAA Security Risk Analysis Engine, a service of Your Deputy, Obuke LLC, provides documentation-completeness services. It is not a law firm, does not provide legal advice, and does not represent you in any legal matter. Attorney review is available and recommended for complex or high-risk matters.
Do you act as our security officer or make policy decisions?
Never. The Engine is not a security officer and does not make policy decisions. Your organization remains responsible for implementing security measures and accepting residual risk. We document and assess, not decide.
What makes an SRA 'complete'?
Completeness is defined by the regulation: an accurate and thorough assessment of risks to ePHI, a risk management plan, sanction policy, and information system activity review procedures — all mapped to the HIPAA Security Rule and NIST guidance. Deterministic gates enforce each one before release.
How fast is it?
The standard SLA is five business days from complete intake to an assessor-released SRA. The free Gap Scan is returned much sooner and tells you exactly what is still needed.
How are you priced?
A flat fee per released SRA, plus disclosed pass-through costs. No hourly billing and no percentage of any recovery or revenue.

See what's missing before OCR does.

Start with a free Gap Scan. Send your current SRA (if any) and entity details and we'll return a completeness read against every subsection of 45 CFR §164.308.

Documentation-completeness service · not legal advice · your organization retains all responsibility for security decisions.