HIPAA Security Risk Analysis: Complete Guide for Dental Practices (2026)
The HIPAA Security Risk Analysis (SRA) is the single most important compliance document your dental practice can have — and the one most likely to be missing when OCR comes knocking. It's the first document requested in 100% of OCR investigations, and its absence is treated as evidence of willful neglect. The 2026 HIPAA Security Rule Final Rule added significant new requirements to what a compliant SRA must include. If your SRA was completed before 2024, it needs to be updated.
100%
Of OCR investigations request the SRA first
$4,816
Minimum fine for a missing or inadequate SRA
Annual
Minimum SRA review frequency required
2026 Update: New in 2026: The HIPAA Security Rule Final Rule requires SRAs to explicitly document MFA deployment status, encryption coverage across all ePHI systems, annual penetration testing results, biannual vulnerability scan results, and a complete network asset inventory. SRAs completed before 2024 that don't address these areas are non-compliant.
ADA Official Partner — Recommended for Dental Practice in your area
Get Your Practice 100% HIPAA Compliant in 2026
Compliancy Group is the only HIPAA solution officially endorsed by the American Dental Association. Their Compliance Coach walks your practice through every requirement — and their Seal of Compliance proves you're audit-ready.
Get ADA-Recommended HIPAA Compliance →No credit card required to start your audit
What Is a HIPAA Security Risk Analysis?
A Security Risk Analysis (SRA) is a formal assessment required under 45 CFR § 164.308(a)(1)(ii)(A) of the HIPAA Security Rule. It identifies potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic Protected Health Information (ePHI) in your practice.
The SRA is not a checklist you can fill out in an afternoon. It's a documented process that must assess every system, device, and process in your practice that creates, receives, maintains, or transmits ePHI.
Unlike some HIPAA requirements that allow for flexibility in implementation, the SRA is mandatory — there is no exception, no alternative, and no workaround. Practices that claim they're 'too small' to need one are wrong. OCR has fined solo practitioners for missing SRAs.
What Your SRA Must Cover in 2026
The 2026 Security Rule Final Rule significantly expanded what a compliant SRA must document. Your SRA must now include:
- Scope definition: Every system, application, device, and physical location where ePHI exists or flows — including cloud systems, mobile devices, and any system accessed remotely.
- Threat identification: All realistic threats to ePHI confidentiality, integrity, and availability — including ransomware, phishing, insider threats, and physical theft.
- Vulnerability assessment: Current weaknesses in your technical, physical, and administrative controls that could allow a threat to succeed.
- Current control analysis: What safeguards you currently have in place and how effective they are against identified threats.
- Likelihood and impact ratings: A documented assessment of how likely each threat/vulnerability combination is and what the impact would be if it occurred.
- Risk level determination: An overall risk rating for each identified risk — typically High, Medium, or Low.
- MFA status (new 2026): Explicit documentation of which systems have MFA enabled and which do not, with a remediation timeline for any gaps.
- Encryption coverage (new 2026): Documentation of encryption status for all ePHI at rest and in transit across every identified system.
- Penetration testing results (new 2026): Annual penetration testing results must be incorporated into the SRA, with identified vulnerabilities and remediation status.
- Vulnerability scan results (new 2026): Biannual vulnerability scan results with remediation tracking.
- Network asset inventory (new 2026): A complete inventory of all devices that connect to your network or access ePHI — workstations, tablets, printers, X-ray machines with network connections, etc.
Who Can Complete Your SRA?
HHS provides a free SRA Tool available at hhs.gov. Small, simple practices with limited technology can use this tool and complete a basic SRA independently. However, the tool does not cover the 2026 additions (penetration testing, vulnerability scans, network asset inventory) and requires significant technical knowledge to complete accurately.
For practices with 5+ employees, any cloud-based systems, remote access capabilities, or multiple locations, OCR recommends using a qualified compliance vendor. The 2026 rule changes make it increasingly difficult for non-technical practice owners to complete a compliant SRA without expert assistance.
Important distinction: completing an SRA is not the same as remediating the risks it identifies. An SRA tells you what's wrong. A compliance program tells you how to fix it.
The Difference Between an SRA and a Risk Management Plan
These two documents are often confused, but they serve different purposes and are both required.
The SRA identifies and prioritizes risks. The Risk Management Plan (required under 45 CFR § 164.308(a)(1)(ii)(B)) documents how you will address those risks — what steps you'll take, who's responsible, and by when.
Having an SRA without a Risk Management Plan is like getting a home inspection that identifies structural issues and then ignoring the report. OCR expects to see both documents — and evidence that you're actually following the Risk Management Plan.
How Often Does Your SRA Need to Be Updated?
The HIPAA Security Rule requires practices to 'periodically' conduct the SRA. OCR interprets 'periodically' as at minimum annually. But certain events trigger an immediate SRA update regardless of when you last did one:
- Adding a new practice management software or switching EHR systems
- Implementing a new patient portal or communication platform
- Adding remote work capabilities or a new office location
- A security incident or breach (even a minor one)
- Significant staff changes, especially in the IT or billing functions
- Adding new medical equipment that connects to your network (digital X-rays, CBCT, intraoral cameras with cloud storage)
- Switching IT or managed services providers
What an OCR Auditor Looks for in Your SRA
Based on published OCR audit findings and settlement documents, here's what auditors specifically evaluate:
- Completeness: Does the SRA cover all locations, systems, and ePHI flows? Partial SRAs are treated as inadequate.
- Currency: When was the SRA completed? Is it updated for current systems and the 2026 rule changes?
- Documentation quality: Is the risk analysis process documented clearly enough to demonstrate it was actually performed? Vague, template-only responses are red flags.
- Risk Management Plan: Is there a corresponding plan that shows identified risks are being addressed?
- Evidence of implementation: Are the security controls described in the SRA actually in place? Auditors cross-reference SRA claims against technical reality.
ADA Official Partner — Recommended for Dental Practice in your area
Get Your Practice 100% HIPAA Compliant in 2026
Compliancy Group is the only HIPAA solution officially endorsed by the American Dental Association. Their Compliance Coach walks your practice through every requirement — and their Seal of Compliance proves you're audit-ready.
Get ADA-Recommended HIPAA Compliance →No credit card required to start your audit
Frequently Asked Questions
How is the SRA different from the SRA Checklist on this site?
The checklist on this site is a quick reference tool to assess whether you have the foundational safeguards in place. A full Security Risk Analysis is a formal, documented process that goes much deeper — it identifies specific threats, assesses their likelihood and impact, and produces a written risk register and management plan. Think of the checklist as a readiness scan; the SRA is the full compliance document.
How much does a HIPAA Security Risk Analysis cost?
DIY using HHS's free SRA Tool: $0 plus significant staff time (typically 20–40 hours for a small practice). Independent HIPAA consultants: $1,500–$5,000 for a one-time SRA. Managed compliance platforms (like Compliancy Group): $3,000–$7,200 annually, which includes the SRA plus ongoing compliance management, training, and documentation. Annual penetration testing (now required) adds $3,000–$8,000 separately if not included in a platform.
Can I use HHS's free SRA Tool for the 2026 requirements?
The HHS SRA Tool covers the core HIPAA Security Rule requirements but has not been updated to include the 2026 Final Rule additions (penetration testing documentation, vulnerability scan results, network asset inventory, explicit MFA and encryption documentation). If you use the HHS tool, you'll need to supplement it with separate documentation of these new requirements.
What happens if OCR finds my SRA is outdated?
An outdated SRA (one that doesn't reflect current systems or the 2026 requirements) is treated similarly to a missing SRA. OCR may classify it as Tier 3 (Willful Neglect, corrected) — which carries fines of $10,000–$50,000 per violation. 'Per violation' in this context often means per patient whose data was at risk during the period the SRA was inadequate.
Do I need to share my SRA with patients or post it publicly?
No. The SRA is an internal compliance document. You are not required to share it with patients or post it publicly. However, you must be able to produce it on demand to OCR auditors or investigators. It should be stored securely and included in your compliance documentation system.
Not Sure Where Your Practice Stands?
Take the free 5-question HIPAA Risk Assessment — get your estimated fine exposure in under 2 minutes.
Take the Free Risk Calculator →Get a Compliant 2026 SRA Without Doing It Yourself
Compliancy Group guides dental practices through a complete, documented SRA that covers all 2026 requirements — including penetration testing coordination, asset inventory, and the Risk Management Plan.
Start My 2026 SRA →ADA's official HIPAA compliance partner
Related Guides
Revenue Protection
The Hidden Cost of Dental Billing Errors in 2026
Cost Analysis
Staffing Shortage vs. Medical VAs: A Financial Comparison for Dental Practices in 2026
OCR Audit #1 Finding
Business Associate Agreements: The #1 HIPAA Violation in Dental Practices
Partner Review
Compliancy Group Review: Is It Worth It for Dental Practices in 2026?