How to Comply with HIPAA Security Risk Analysis Requirements for MIPS Attestation

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

How to Comply with HIPAA Security Risk Analysis Requirements for MIPS Attestation

Kevin Henry

HIPAA

July 03, 2026

6 minutes read
Share this article
How to Comply with HIPAA Security Risk Analysis Requirements for MIPS Attestation

Understanding MIPS Security Risk Analysis Requirement

You must complete a HIPAA Security Risk Analysis (SRA) to attest for the MIPS Promoting Interoperability category. The HIPAA Security Rule requires an “accurate and thorough” assessment of risks and vulnerabilities to ePHI confidentiality, integrity, and availability, followed by timely remediation. For MIPS, you attest that this work has been done and that you are managing identified risks.

The SRA is not a one-time task. It is an ongoing process that evaluates how your people, technology, vendors, and facilities protect ePHI. Your attestation should reflect current conditions in your environment and a good‑faith effort to reduce risk consistent with OCR guidance.

  • Purpose: Identify where ePHI resides, how it moves, and what could compromise it.
  • Security Risk Analysis Scope: Include all systems, workflows, and third parties that create, receive, maintain, or transmit ePHI.
  • Outcome: A prioritized list of risks and a plan to mitigate them, supporting your MIPS attestation.

Conducting Comprehensive HIPAA Security Risk Analysis

Start by defining the Security Risk Analysis Scope. Map every location of ePHI, including EHR, practice management, patient portals, imaging, email, texting, telehealth, mobile devices, backups, removable media, cloud services, and business associates.

  • Inventory assets and data flows: Document systems, users, interfaces, and where ePHI enters, moves, and exits.
  • Identify threats and vulnerabilities: Consider ransomware, lost devices, misconfiguration, insider misuse, natural events, and third‑party failures.
  • Evaluate current controls: Review administrative, physical, and technical safeguards such as policies, training, facility security, access controls, MFA, encryption, audit logging, and patching.
  • Rate likelihood and impact: Use a consistent method to produce risk levels and create a risk register.
  • Validate with evidence: Capture screenshots, configuration exports, and sample audit logs to support your findings.

Close each finding with a clear remediation path, required resources, and an owner. This rigor demonstrates that your SRA is comprehensive and actionable.

Implementing Risk Management Strategies

Translate findings into a Risk Management Plan that is tracked and updated throughout the year. Focus first on high‑likelihood/high‑impact risks to ePHI confidentiality, integrity, and availability.

  • Prioritize and schedule: Set target dates and interim safeguards; document exceptions with justification and review dates.
  • Strengthen technical controls: Enforce unique IDs, MFA, role‑based access, device encryption, vulnerability remediation, endpoint protection, and secure configurations.
  • Bolster administrative safeguards: Update policies, complete role‑specific training, review access quarterly, and rehearse incident response.
  • Harden physical safeguards: Control facility access, protect server rooms, and secure media handling and disposal.
  • Assure vendor risk: Maintain business associate agreements, evaluate vendor controls, and define breach notification expectations.
  • Measure progress: Track key metrics (e.g., patch timelines, audit log reviews, account recertifications) and report to leadership.

When preparing to attest, confirm that your HIPAA SRA and remediation activities align with the MIPS Promoting Interoperability requirement. Ensure your CEHRT is in use, your policies are current, and your risk management actions are underway.

  • Confirm completion: Conduct or update your SRA for the performance period and document corrective actions in progress.
  • Assemble evidence: Keep the SRA report, risk register, remediation logs, training records, screenshots, and CEHRT details.
  • Attest accurately: Answer the security risk analysis attestation truthfully; incomplete or outdated analyses jeopardize your PI category.
  • Retain records: Preserve supporting documentation for at least six years to satisfy HIPAA documentation retention expectations.

A careful, evidence‑backed attestation reduces audit risk and supports your overall MIPS score.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Documenting Security Risk Analysis and Remediation

Strong documentation shows you performed a thorough SRA and are actively managing risk. It also proves your Security Risk Analysis Scope was complete and that decisions were informed by OCR guidance.

  • SRA report: Purpose, scope, methodology, date(s), team, asset inventory, data flow summary, and assumptions.
  • Findings and risk ratings: Threats, vulnerabilities, affected assets, likelihood/impact rationale, and residual risk.
  • Risk Management Plan: Priorities, owners, milestones, budgets, and acceptance/exception justifications.
  • Control evidence: Access reviews, audit log checks, encryption status, vulnerability scans, backup tests, and incident drills.
  • Governance records: Policy updates, security awareness training rosters, leadership approvals, and vendor due diligence.
  • Attestation packet: Copies of the attestation, screenshots, and a crosswalk tying PI requirements to your evidence.

Utilizing Security Risk Assessment Tools

A Security Risk Assessment Tool can streamline your analysis with structured questions and reports. Tools aligned with HIPAA and OCR guidance help smaller practices perform consistent evaluations and produce audit‑ready documentation.

  • Benefits: Standardized checklists, built‑in risk scoring, and automatic evidence logs.
  • Use with judgment: Tailor questions to your environment; tools support but do not replace expert analysis.
  • Augment with scans: Add vulnerability scans, EHR security reports, and configuration baselines for depth.
  • Close the loop: Export the risk register and feed it directly into your Risk Management Plan.

Maintaining Compliance Through Annual Self-Assessments

Perform an SRA at least annually and after significant changes, such as EHR upgrades, new telehealth platforms, office moves, or security incidents. Between SRAs, use focused self‑assessments to ensure controls remain effective.

  • Quarterly tasks: Review access, inspect audit logs, verify backups and restores, and test incident response steps.
  • Change management: Assess security impact before deploying new systems or workflows that touch ePHI.
  • Training and awareness: Refresh workforce training and targeted phishing defense exercises.
  • Continuous improvement: Re‑rate residual risks as fixes land and update the Risk Management Plan accordingly.

By aligning your SRA, remediation, and documentation with the HIPAA Security Rule—and accurately attesting under MIPS Promoting Interoperability—you create a defensible, repeatable compliance program that safeguards patients and sustains performance‑based reimbursement.

FAQs.

What are the HIPAA security risk analysis requirements for MIPS attestation?

You must conduct an accurate and thorough assessment of risks and vulnerabilities to ePHI, document the Security Risk Analysis Scope, implement security updates and corrections, and maintain evidence of ongoing risk management. Your MIPS attestation confirms these actions are current and active for the performance period.

How does the security risk analysis impact MIPS Promoting Interoperability scores?

The SRA is a required attestation for the Promoting Interoperability category. If you cannot attest “yes,” you generally fail the PI category, which can significantly reduce your final MIPS score and may trigger a negative payment adjustment.

What should be included in the documentation of the risk analysis?

Include scope and methodology, asset and data flow inventory, identified threats and vulnerabilities, risk ratings, the Risk Management Plan with owners and timelines, control evidence (e.g., encryption status, access reviews, audit logs), training records, vendor assessments, and your attestation packet.

How often must clinicians complete the security risk analysis for MIPS attestation?

Complete the SRA at least annually and whenever major changes could affect ePHI (for example, new systems, migrations, or incidents). Your attestation should reflect a current assessment and demonstrable progress on remediation activities for the performance year.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles