Scrutineer · By framework
HIPAA risk assessment software and risk analysis tool
Your last security risk analysis covered the EHR. It did not cover the imaging archive, the shared mailbox the front desk uses for referrals, or the eleven vendors holding ePHI on your behalf. That gap is the finding in almost every enforcement action OCR has announced under its Risk Analysis Initiative.
Scrutineer inventories where ePHI actually lives, runs the analysis against all of it, and keeps the remediation trail that shows each risk was managed, not just listed.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with HIPAA risk assessment
The Security Rule does not say annual, and the calendar you are working to came from a payment program
Look up the obligation itself and the frequency is not there. 45 CFR 164.308(a)(1)(ii)(A) reads, in full: "Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate." That specification is Required, not Addressable, so there is no reasonable-and-appropriate escape hatch on it. What it does not contain is a number, a month, or the word annual. The annual habit comes from somewhere else entirely: the CMS Medicare Promoting Interoperability and MIPS Security Risk Analysis measure, which asks eligible clinicians and hospitals to conduct or review a security risk analysis of certified EHR technology at least once each calendar year, in the calendar year in which the EHR reporting period falls, and to attest that they did. That is an attestation measure attached to a payment program, scoped to certified EHR technology. It is a good habit and it is not the Security Rule. The practical consequence matters, because organizations that treat the calendar as the obligation end up with a compliant-looking annual document that covers one system, while the specification they are actually judged against asks about all ePHI they hold. OCR findings almost never turn on the date. They turn on scope and accuracy.
The rule the market is selling against is not the rule being enforced
On January 6, 2025, HHS published a Notice of Proposed Rulemaking titled "HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information," Federal Register document 2024-30983, RIN 0945-AA22, running 125 Federal Register pages. It proposed removing the Addressable and Required distinction so that nearly everything becomes required, and adding explicit duties: a technology asset inventory and network map, multi-factor authentication, encryption of ePHI at rest and in transit, annual audits of Security Rule compliance, and vulnerability scanning and penetration testing on a defined cadence. The comment period closed March 7, 2025. It has not been finalized. Reporting on the 2026 Unified Agenda places RIN 0945-AA22 on the Long-Term Actions list with July 2027 given as the anticipated timeframe for final action, which in practice signals that HHS does not expect to issue a final rule within the next twelve months, and any compliance date would then sit well beyond that. OCR received close to 5,000 comments on it. Two things follow. Buying a platform today because it promises readiness for a rule that does not exist yet is buying a forecast. Meanwhile the 2003 Security Rule, with its Required risk analysis specification, is the rule OCR is enforcing right now, and it is the one generating settlements.
Running the free SRA Tool is not the same as having done a risk analysis
The HHS and ONC Security Risk Assessment Tool is a genuinely useful, genuinely free desktop application aimed at small and medium practices, and its own disclaimer says plainly that "Use of this tool is neither required by nor guarantees compliance with federal, state or local laws." The reason is structural rather than a matter of quality. The tool analyzes what you tell it about. It does not discover ePHI, it does not read your vendor agreements, and it does not know about the network share the billing team set up in 2019. So an organization can complete every question honestly and still fail the specification, because the specification asks for an accurate and thorough assessment of the ePHI the entity holds, and a questionnaire scoped by the person answering it is only as complete as their memory of the environment. This is the failure pattern in the enforcement record: not that no assessment was done, but that the one on file was not enterprise-wide. OCR has been extending the same reasoning into the next specification along, 164.308(a)(1)(ii)(B) risk management, which is also Required and asks you to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. A register of risks with nothing recorded against them satisfies neither.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Builds the ePHI inventory first, so the analysis is scoped to where the data actually is rather than to the systems someone remembered
- Covers the whole estate in one assessment: EHR, imaging, email, backups, endpoints, cloud infrastructure and the vendors holding ePHI for you
- Carries the administrative, physical and technical safeguards of 45 CFR 164.308, 164.310 and 164.312 as controls you evidence, not prose you write
- Separates Required from Addressable and records the documented rationale where you implement an equivalent measure instead
- Tracks remediation against each identified risk with an owner and a date, which is the 164.308(a)(1)(ii)(B) risk management half most assessments skip
- Keeps every business associate in the same register, with the BAA, the assurances collected and the date each was last reviewed
- Reuses one control set across HIPAA, SOC 2, ISO 27001 and PCI, so a hospital or a health tech vendor stops running four parallel evidence hunts
- Produces a dated, versioned assessment you can hand to OCR, a health system customer, or your cyber insurer without rebuilding it from scratch
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
ePHI location reference
Where ePHI actually lives, and whether your risk analysis reached it
Every published guide to HIPAA risk analysis runs on the nine elements of the assessment method. That is not where assessments fail. They fail on scope, because the analysis was built around the systems someone could name in a meeting. So this table runs on location: who owns it internally, whether it typically makes it into the assessment at all, what OCR asks to see, and the specific reason each one gets missed.
| Where ePHI lives | Who owns it internally | Does it make the risk analysis | What OCR asks to see | Why it gets missed |
|---|---|---|---|---|
| EHR or practice management system | Clinical IT or the EHR vendor | Almost always. This is the system people mean when they say they did the SRA | Access controls, audit log review, user provisioning and termination records | It does not. This is the one location that is reliably covered |
| Backups, snapshots and disaster recovery copies | Infrastructure or a managed service provider | Frequently missing. Backups are treated as an IT function, not an ePHI location | Encryption state, retention, restore testing, and who can access the backup console | The data is a copy, so nobody files it under ePHI, and ransomware cases turn on exactly this |
| Email, shared mailboxes and secure messaging | IT, usually with no clinical owner at all | Rarely, beyond a line saying email is encrypted | Encryption in transit, retention, mailbox delegation, and what happens to referral attachments | Referral and prior authorization traffic accumulates ePHI in a mailbox nobody considers a repository |
| Imaging, PACS and diagnostic modalities | Radiology, often with vendor-managed appliances | Sometimes named, seldom assessed, because the vendor manages the appliance | Network segmentation, authentication on the modality, and vendor remote access controls | Vendor-managed means someone else patches it, which gets read as someone else owns the risk |
| Connected medical devices and infusion pumps | Biomedical engineering, a separate department from IT | Almost never. Biomed inventories and IT inventories are different spreadsheets | A device inventory, supported software versions, and compensating controls where patching is impossible | Two departments each assume the other counted them, and neither list feeds the risk analysis |
| Employee endpoints, mobile devices and home offices | IT, with real gaps for contractors and locums | Partially, usually as a policy statement rather than an assessed control | Encryption enforcement, MDM enrollment coverage, and remote wipe evidence | Policy is confused with control. A written mobile policy is not evidence that devices are encrypted |
| ePHI held by business associates and their subcontractors | Nobody, in most organizations | Least covered location by a wide margin, and typically the largest population of records | A current BA inventory, executed BAAs, and the assurances you collected and reviewed | You do not hold it, so it does not feel like yours. The Security Rule disagrees, and the biggest reported breaches keep landing here |
The last row is the one that decides outcomes. ePHI held by business associates and their subcontractors is simultaneously the largest population of records most organizations are accountable for and the location least likely to appear in their risk analysis, because it does not feel like theirs to assess. The Security Rule names the business associate in the same sentence as the covered entity, and the breach reports keep arriving from that tier.
Good questions
Questions about HIPAA risk assessment
Keep reading
Guides that go deeper on HIPAA risk analysis
Best HIPAA risk assessment software
The five kinds of tool sold for this, what each produces, and which one fits a practice versus a health system.
Read the guideHIPAA compliance checklist
The administrative, physical and technical safeguards in order, with what counts as evidence for each.
Read the guideHow to conduct a cybersecurity risk assessment
The general method behind the HIPAA-specific one: scoping, threat identification, rating and treatment.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification