HIPAA Risk Analysis Worksheet

A step-by-step risk analysis worksheet built on the NIST SP 800-66 Rev 2 methodology. Covers threat identification, vulnerability assessment, likelihood and impact scoring, and residual risk documentation. Required by 45 CFR §164.308(a)(1)(ii)(A).

What is inside

  • Structured threat inventory covering ePHI access points: EHR, scheduling software, email, mobile devices, and physical records
  • Likelihood × impact scoring matrix with built-in risk level categories (low / moderate / high)
  • Pre-populated with the most common threats found in OCR investigations of small practices
  • Residual risk documentation section — records what controls are in place after mitigation
  • Annotated with the specific regulatory citations so you understand what each section satisfies

We publish the same practical templates and decision tools that clinics use to structure recurring HIPAA work. No enterprise gate. No resource-library gimmicks. Just useful material exchanged for an email address.