Therapy HIPAA Hub

Free HIPAA Security Risk Assessment Checklist for Therapists

A 43-point checklist covering all four safeguard categories OCR auditors review. Print it, work through it, and document each item completed. This is the same framework federal auditors use during a HIPAA Security Rule investigation.

Written & fact-checked by the Therapy HIPAA Hub editorial team — see our editorial standards.

Updated May 2026 · Aligned with 2024 HIPAA amendments · Last OCR guidance incorporated

12

Administrative Safeguards

7

Physical Safeguards

12

Technical Safeguards

12

Policies & Documentation

Before you begin

The HIPAA Security Rule requires you to formally document your SRA — going through this checklist alone is not sufficient. You must write down your findings, your risk level for each item, and your plan to address gaps. Keep this documentation for at least 6 years.

Administrative Safeguards

12 items

Assign a HIPAA Security Officer (even if it is you)

Required for all covered entities regardless of size

Complete and document a Security Risk Analysis (SRA) within the past 12 months

The SRA is the #1 item OCR auditors check first

Develop a written Risk Management Plan based on SRA findings

Document how you are addressing each risk identified

Implement a Sanction Policy for workforce members who violate HIPAA

Required even for solo practices — you are the workforce

Establish Information Access Management procedures

Define who can access what PHI and under what circumstances

Conduct annual HIPAA training and document it

Keep records with date, attendee names, and topics covered

Implement a Security Incident Procedures policy

How will you respond if a breach or suspected breach occurs?

Create a Contingency Plan (backup and disaster recovery)

What happens if your EHR is down or data is lost?

Review and update all Business Associate Agreements (BAAs)

BAA required with EHR, email service, telehealth platform, billing service

Evaluate contractors and vendors for HIPAA compliance annually

Ask for their HIPAA attestation or SOC 2 report

Document workforce clearance procedures

Who gets access to PHI? Background checks if applicable?

Establish a termination policy for access revocation

Immediately revoke EHR and email access when staff leave

Unlock the Full 43-Item Checklist

Enter your email to see every item — and we'll send you a copy plus the 3 mistakes that trigger the biggest OCR fines.

No spam. One-time 3-email series. Unsubscribe anytime.

☀️ Summer 2026 Offer

Trusted by 225,000+ Therapists

50% Off Your First 4 Months of SimplePractice

SimplePractice is the #1 HIPAA-compliant practice management platform for therapists. Includes a signed BAA, encrypted messaging, telehealth, and full insurance billing.

✓ 7-day free trial✓ 50% off first 4 months✓ Free credentialing available (up to 2 payers)✓ BAA included
Claim 50% Off SimplePractice →

Limited-time summer offer · No credit card required for trial

Need HIPAA-compliant email only? See Hushmail for Healthcare →

FAQ — HIPAA Security Risk Assessment

How often do I need to complete a HIPAA Security Risk Assessment?

Officially, the HIPAA Security Rule requires an SRA whenever there are significant changes to your environment — new technology, new staff, new location, or new business processes. In practice, OCR expects annual SRAs for small practices. Completing and documenting one per year is the safest approach.

Do I need to hire a consultant to do my SRA?

No. OCR's Security Risk Assessment Tool (available free at healthit.gov) is designed for small practices including solo therapists. You can complete it yourself. What matters is that you document your findings and your risk remediation plan — not who performs the assessment.

What happens if I am audited and cannot produce SRA documentation?

Failure to conduct and document an SRA is one of the most commonly cited HIPAA violations. OCR has assessed fines of $10,000 to $100,000+ specifically for missing SRA documentation. Having a completed, dated SRA on file is your primary defense in an audit.

My EHR vendor says they are HIPAA compliant — does that mean I am covered?

No. Your EHR vendor's compliance covers their systems, not your practice's processes. You are still responsible for your own administrative safeguards, workforce training, physical safeguards, and policies. The vendor's BAA covers their obligations — your SRA covers yours.

7-day free trial · 50% off 4 months