Free HIPAA Security Risk Assessment Checklist for Therapists
A 43-point checklist covering all four safeguard categories OCR auditors review. Print it, work through it, and document each item completed. This is the same framework federal auditors use during a HIPAA Security Rule investigation.
Written & fact-checked by the Therapy HIPAA Hub editorial team — see our editorial standards.
Updated May 2026 · Aligned with 2024 HIPAA amendments · Last OCR guidance incorporated
12
Administrative Safeguards
7
Physical Safeguards
12
Technical Safeguards
12
Policies & Documentation
Before you begin
The HIPAA Security Rule requires you to formally document your SRA — going through this checklist alone is not sufficient. You must write down your findings, your risk level for each item, and your plan to address gaps. Keep this documentation for at least 6 years.
Administrative Safeguards
12 itemsAssign a HIPAA Security Officer (even if it is you)
Required for all covered entities regardless of size
Complete and document a Security Risk Analysis (SRA) within the past 12 months
The SRA is the #1 item OCR auditors check first
Develop a written Risk Management Plan based on SRA findings
Document how you are addressing each risk identified
Implement a Sanction Policy for workforce members who violate HIPAA
Required even for solo practices — you are the workforce
Establish Information Access Management procedures
Define who can access what PHI and under what circumstances
Conduct annual HIPAA training and document it
Keep records with date, attendee names, and topics covered
Implement a Security Incident Procedures policy
How will you respond if a breach or suspected breach occurs?
Create a Contingency Plan (backup and disaster recovery)
What happens if your EHR is down or data is lost?
Review and update all Business Associate Agreements (BAAs)
BAA required with EHR, email service, telehealth platform, billing service
Evaluate contractors and vendors for HIPAA compliance annually
Ask for their HIPAA attestation or SOC 2 report
Document workforce clearance procedures
Who gets access to PHI? Background checks if applicable?
Establish a termination policy for access revocation
Immediately revoke EHR and email access when staff leave
Unlock the Full 43-Item Checklist
Enter your email to see every item — and we'll send you a copy plus the 3 mistakes that trigger the biggest OCR fines.
No spam. One-time 3-email series. Unsubscribe anytime.
Trusted by 225,000+ Therapists
50% Off Your First 4 Months of SimplePractice
SimplePractice is the #1 HIPAA-compliant practice management platform for therapists. Includes a signed BAA, encrypted messaging, telehealth, and full insurance billing.
Limited-time summer offer · No credit card required for trial
Need HIPAA-compliant email only? See Hushmail for Healthcare →
FAQ — HIPAA Security Risk Assessment
How often do I need to complete a HIPAA Security Risk Assessment?
Officially, the HIPAA Security Rule requires an SRA whenever there are significant changes to your environment — new technology, new staff, new location, or new business processes. In practice, OCR expects annual SRAs for small practices. Completing and documenting one per year is the safest approach.
Do I need to hire a consultant to do my SRA?
No. OCR's Security Risk Assessment Tool (available free at healthit.gov) is designed for small practices including solo therapists. You can complete it yourself. What matters is that you document your findings and your risk remediation plan — not who performs the assessment.
What happens if I am audited and cannot produce SRA documentation?
Failure to conduct and document an SRA is one of the most commonly cited HIPAA violations. OCR has assessed fines of $10,000 to $100,000+ specifically for missing SRA documentation. Having a completed, dated SRA on file is your primary defense in an audit.
My EHR vendor says they are HIPAA compliant — does that mean I am covered?
No. Your EHR vendor's compliance covers their systems, not your practice's processes. You are still responsible for your own administrative safeguards, workforce training, physical safeguards, and policies. The vendor's BAA covers their obligations — your SRA covers yours.