Skip to content
compliancebase

HIPAA risk analysis

An accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.

In practice

Maintain an ePHI inventory, document likelihood and impact, assign remediation owners, and update after material change.

Common confusion

A generic penetration test is an input, not a complete HIPAA risk analysis.

Related controls

Framework versions referenced in this page:

Last verified: August 2026 · Primary sources linked above