Risk & Audits

9 Questions to Ask a HIPAA Risk Analysis Vendor Before You Sign

The single most useful question to ask a HIPAA risk analysis vendor is not about price. It is: "which parts of this do you do, and which parts do you assume we do?" The HIPAA Security Rule requires an assessment of risks to all electronic protected health information (ePHI) an organization holds — across administrative, physical, and technical safeguards, at every location where that data lives. Software can cover a great deal of that. It cannot walk your building. So the question that decides whether you end up with a complete analysis is not what the engagement costs; it is where the scope stops and who picks up the remainder. Below are nine questions that surface that boundary before you sign rather than after an incident.

The nine questions

#AskWhat it tests
1Does the scope cover administrative, physical, and technical safeguards?164.308 / 164.310 / 164.312
2Who performs the nontechnical evaluation?164.308(a)(8)
3How do you assess facility access, workstations, and media disposal?164.310
4How many locations are in scope, and how is site two priced?Scope of the analysis
5Does scope include ePHI held by our vendors?164.308(b), external sources of ePHI
6Who do we call in month seven?164.308(a)(2), 164.306(e)
7Risk analysis or gap assessment?164.308(a)(1)(ii)(A)
8Do we get a risk management plan?164.308(a)(1)(ii)(B)
9What documentation do we retain?164.316

1. Does the scope cover all three safeguard categories?

The Security Rule is organized into three sets of standards: administrative safeguards (45 CFR 164.308), physical safeguards (164.310), and technical safeguards (164.312). All three are mandatory standards. The risk analysis requirement sits inside the administrative set, at 164.308(a)(1)(ii)(A), and it is labeled Required — it asks for "an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by" the organization.

Note what that sentence does not say. It does not say "held on your servers." It does not say "in your software." It says held by the organization. If a vendor's scope of work maps only to 164.312, ask them directly where 164.310 is being covered and by whom.

2. Who performs the nontechnical evaluation?

This is the question most likely to produce a long pause, and it is worth asking early.

The rule uses the word itself. 45 CFR 164.308(a)(8) — the Evaluation standard — requires a covered entity or business associate to "perform a periodic technical and nontechnical evaluation" establishing the extent to which its security policies and procedures meet the requirements of the subpart. Not "technical evaluation." Technical and nontechnical.

A nontechnical evaluation is a review of policies, procedures, workforce practice, physical arrangement, and the way people actually behave in the building. A scanner does not produce one. A questionnaire can capture it only to the extent that whoever fills in the questionnaire has actually gone and looked. Ask who is doing the looking. There are only three legitimate answers: the vendor does it, your staff does it, or nobody does it. The third answer is common and it is the one you want to discover before an auditor discovers it.

3. How do you assess the physical safeguards at 164.310?

Get specific here, because 164.310 is specific. The standards and implementation specifications include:

  • Facility access controls (164.310(a)(1)) — policies and procedures to limit physical access to electronic information systems "and the facility or facilities in which they are housed," while ensuring authorized access is allowed.
  • Access control and validation procedures (164.310(a)(2)(iii), addressable) — controlling and validating a person's access to facilities based on role or function, including visitor control.
  • Facility security plan (164.310(a)(2)(ii), addressable) — safeguarding the facility and the equipment in it from unauthorized physical access, tampering, and theft.
  • Maintenance records (164.310(a)(2)(iv), addressable) — documenting repairs and modifications to physical components related to security, and the rule gives its own examples: "hardware, walls, doors, and locks."
  • Workstation use (164.310(b)) — policies specifying the proper functions, the manner of performance, and "the physical attributes of the surroundings" of a workstation that can access ePHI.
  • Workstation security (164.310(c)) — physical safeguards for all workstations that access ePHI, to restrict access to authorized users.
  • Device and media controls (164.310(d)) — governing receipt and removal of hardware and media into and out of a facility and movement within it. Disposal and media re-use are both labeled Required, not addressable.

Read that list against a remote questionnaire and the mismatch becomes obvious. "The physical attributes of the surroundings" of a workstation is a statement about a room. Walls, doors, and locks are named in the regulation by those words. A vendor may have an excellent method for covering this remotely — photographs, floor plans, a structured interview with someone who walks the site. That is a fine answer. "We don't cover that" is also an answer, and you need to hear it out loud.

4. How many locations does this cover, and how do you scope site two through twelve?

If you operate more than one building, this question decides your engagement, and it is the one most often left vague in a proposal.

HHS guidance on the risk analysis requirement is unusually direct about scope. It states that the scope "includes the potential risks and vulnerabilities to the confidentiality, availability and integrity of all e-PHI that an organization creates, receives, maintains, or transmits," and that "electronic media includes a single workstation as well as complex networks connected between multiple locations." It closes the point: an organization's risk analysis "should take into account all of its e-PHI, regardless of the particular electronic medium in which it is created, received, maintained or transmitted or the source or location of its e-PHI."

So the regulatory position is settled: every location holding ePHI is in scope. The open question is purely commercial — does the vendor cover your locations under one engagement, price each site separately, or hand the additional sites to a consulting statement of work at a rate not yet quoted? All three are legitimate business models. Only one of them is what you assumed you were buying. Ask for the number in writing, for the site count you actually have.

5. Does the scope include ePHI held by our vendors?

HHS's own sample questions for a risk analysis include: "What are the external sources of e-PHI? For example, do vendors or consultants create, receive, maintain or transmit e-PHI?" Your billing company, your answering service, your cloud EHR, and your document shredding vendor may all hold ePHI you are responsible for analyzing risk against. Separately, 164.308(b) requires satisfactory assurances, documented through a written contract, before a business associate handles ePHI on your behalf.

Ask whether business associate inventory and review is in scope, adjacent to scope, or an add-on. This is a frequent and expensive surprise.

6. Who do we call in month seven?

Two provisions make this a compliance question rather than a customer-service preference.

First, 164.308(a)(2) — the Assigned security responsibility standard — requires you to identify the security official responsible for developing and implementing the policies and procedures the subpart requires. That is a named human being with an ongoing job, not a software license.

Second, risk analysis is not an annual event that concludes. HHS states the process "should be ongoing," and 164.306(e) requires security measures to be reviewed and modified as needed to continue providing reasonable and appropriate protection. HHS lists the triggers explicitly: a security incident, a change in ownership, turnover in key staff or management, or planned new technology. Those things do not schedule themselves for the week your assessment renews.

So ask what happens in month seven when you replace your practice management system, or when a regulator calls. The honest answers vary — included, retainer, hourly, not offered — and any of them can suit you. Not knowing is what does not suit you.

7. Is the deliverable a risk analysis or a gap assessment?

These are different documents and the words are used loosely in sales conversations.

A gap assessment walks the text of the rule and reports what you do not have. Useful, cheap to produce, easy to automate.

A risk analysis is defined by its elements. HHS's guidance names them: determine the scope, collect data on where ePHI lives, identify and document threats and vulnerabilities, assess current security measures, determine the likelihood of threat occurrence, determine the potential impact, determine the level of risk, document, and review periodically. Threat, likelihood, and impact are the load-bearing parts. A document that lists missing controls but never estimates likelihood or impact has skipped the analysis and delivered the checklist.

Ask to see a redacted sample. The presence or absence of a likelihood-and-impact determination answers the question in about fifteen seconds.

8. Does it produce a risk management plan?

Risk analysis and risk management are two separate Required implementation specifications sitting next to each other. 164.308(a)(1)(ii)(A) is the analysis. 164.308(a)(1)(ii)(B) — Risk management — requires you to "implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level."

A vendor can deliver a flawless analysis and leave you holding the entire remediation. That may be exactly the deal you want. But an analysis that identifies twenty risks and stops is one half of a two-part obligation, and the second half has your name on it either way. Ask which half you are buying.

9. What documentation do we keep, and does it meet 164.316?

The documentation is the part an auditor sees. 164.316(b)(1) requires Security Rule documentation to be maintained in writing, and 164.316(b)(2)(i) requires retention for six years from the later of the date of creation or the date it was last in effect. The rule does not prescribe a format.

Two practical questions follow. Do you receive the underlying analysis, or a summary report? And if you leave the vendor, does the documentation leave with you, or does it live inside a platform you no longer have a login for? Six years is longer than most vendor relationships.

The question underneath all nine

Every question above is a version of the same one: where does this vendor's scope end, and have you noticed?

It is worth saying plainly that there is no single right answer to the delivery model. HHS and ONC publish a free Security Risk Assessment Tool built for small and medium-sized practices, and for a great many organizations a self-service tool run by capable staff produces a complete, defensible analysis. A single-site practice where the office manager can walk the whole building in ninety seconds has a genuinely different problem than a group with eleven clinics, three storage rooms, and a server closet behind a door that has been propped open since 2019.

What does not vary is the scope the rule requires. The Security Rule is deliberately scalable — 164.306(b) tells you to weigh your size, complexity, and capabilities, your technical infrastructure, the cost of measures, and the probability and criticality of potential risks. Cost is on that list. It is one of four items on that list, and it is not the first one.

The failure mode worth guarding against is not buying the cheap option or the expensive one. It is buying an assessment whose scope is narrower than your obligation and not finding out until someone else is reading it.

Common questions

Does a HIPAA risk analysis have to cover physical security, or just software?

It has to cover both. The Security Rule sets standards in three categories: administrative safeguards (45 CFR 164.308), physical safeguards (164.310), and technical safeguards (164.312). The risk analysis at 164.308(a)(1)(ii)(A) is an assessment of risks to all ePHI the organization holds, and 164.308(a)(8) separately requires a periodic technical and nontechnical evaluation. An assessment that only looks at software and network configuration has not covered the physical safeguards standard at 164.310, which includes facility access controls, workstation security, and device and media disposal.

Does one risk analysis cover all of an organization's locations?

The risk analysis must account for all ePHI the organization creates, receives, maintains, or transmits, regardless of its location. HHS guidance states that electronic media includes a single workstation as well as complex networks connected between multiple locations, and that the analysis should take into account all ePHI regardless of the source or location of that ePHI. Whether a vendor delivers that in one engagement or twelve is a commercial question, not a regulatory one. The regulatory requirement is that no location holding ePHI is left out of scope.

What is the difference between a risk analysis and a gap assessment?

A gap assessment compares your controls against the text of the rule and produces a list of things you do not have. A risk analysis, as defined at 45 CFR 164.308(a)(1)(ii)(A), is an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. HHS guidance describes the required elements: scope, data collection, identifying threats and vulnerabilities, assessing current security measures, determining likelihood and impact, and determining the level of risk. A checklist with no threat, likelihood, or impact analysis is a useful document, but it is not the risk analysis the rule requires.

Is a self-service risk analysis tool sufficient for HIPAA compliance?

It depends entirely on who performs the parts the software cannot perform. HHS and ONC publish a free Security Risk Assessment Tool aimed at small and medium-sized practices, and self-service tools are a legitimate way to run the process. What no tool can do on its own is walk the building, look at where the workstations face, or check whether the records room is locked. If your own staff does that work and documents it, a self-service tool can produce a complete analysis. If nobody does it, the scope has a hole in it regardless of what the software cost.