HIPAA Security Risk Assessment: What Every Arizona Medical Practice Needs to Know

Your practice manager just asked if you’ve done a risk assessment this year. You’re not sure what that means or where to start. You’re not alone. Most small practices are in the same spot.

Let’s Start With What You’re Already Living

There’s the check-in computer at the front desk. Four different people use it throughout the day. Does it lock when someone walks away? There’s the server in the back closet. It’s been humming along since 2019. Nobody’s really sure what’s on it anymore. The closet doesn’t lock. There’s the fax machine in the hallway where patients walk past. And that old laptop the office manager uses for billing that goes home sometimes. It’s not encrypted.

None of this makes you a bad practice. It makes you a normal one. But each of these is exactly what a security risk assessment is designed to catch.

So What Is a Risk Assessment, Exactly?

A security risk assessment (SRA) is a structured look at how your practice creates, stores, sends, and protects electronic protected health information (ePHI). Where does patient data live? Who can get to it? What could go wrong? What are you doing about each risk?

Good vs. Bad: How to Tell the Difference

Practice A downloaded a free checklist. Someone checked “yes” on everything during a slow lunch break. It doesn’t mention their EHR by name, doesn’t list their actual devices. That’s not a risk assessment. That’s a liability.

Practice B sat down with their IT provider for half a day. They walked through every room, every system. The assessment names their actual EHR, lists their devices, identifies specific risks, and includes a plan with target dates. That’s what counts.

Why This Matters

A security risk assessment is required under the HIPAA Security Rule for every covered entity, every year. Risk analysis failures are the single most cited issue in OCR enforcement actions. OCR continues to ramp up enforcement. In 2025, they recovered over $19 million in penalties across 21 enforcement actions. In April 2026 alone, OCR settled $1.16 million across four entities, every one cited for failing to conduct a proper risk analysis.

Getting Started

Pick a partner who knows healthcare IT. Block time for it. Be honest about gaps. Don’t chase perfection.

At Asteroid IT, we walk small practices through this process without the jargon or the panic. Call us at 480-937-7021 or reach out through our website.

Scroll to Top