Category: HIPAA Risk Analysis

  • OCR and ONC Just Updated the Free SRA Tool; Here’s Why That Doesn’t Solve Your Risk Analysis Problem

    OCR and ONC Just Updated the Free SRA Tool; Here’s Why That Doesn’t Solve Your Risk Analysis Problem

    Quick answer: On September 10, 2026, OCR and ONC released version 3.7 of the Security Risk Assessment (SRA) Tool, adding new content on remote access, telework, and system activity logging, as well as expanded asset examples and revised reports. The update is genuinely useful, but it doesn’t change what makes the SRA Tool a weak standalone fit for many organizations: it doesn’t stop you from leaving sections incomplete; OCR itself has never confirmed the tool meets its own โ€œaccurate and thoroughโ€ risk analysis standard; OCR has described the tool as built for smaller organizations without ever defining what that means; and a broad, general questionnaire can’t fully account for how ePHI actually moves through your specific organization. For most practices, the SRA Tool is a reasonable starting point, not a finish line.

    OCR and ONC Just Released SRA Tool Version 3.7

    On September 10, 2026, HHS’s Office for Civil Rights and the Office of the National Coordinator for Health IT announced version 3.7 of the free SRA Tool. According to the release, the update includes:

    • Revised assessment coverage and scope questions and education
    • New remote access and telework questions and education
    • Updated system activity logging language and education
    • Expanded asset examples to reflect newer technology
    • Updated software libraries for bug and vulnerability fixes
    • Report revisions to capture additional details and comments

    OCR and ONC also scheduled webinars on September 15 and 16, 2026, to walk organizations through the new features. All of this is a real improvement over the prior version; it’s also not, on its own, the same as a compliant HIPAA risk analysis, and that gap is where many organizations run into trouble.

    The Tool Lets You Stop Before You’re Finished

    During the September 2026 OCR/NIST โ€œSafeguarding Health Informationโ€ conference, Nick Heesters, Senior Advisor for Cybersecurity in OCR’s Health Information Privacy, Data, and Cybersecurity Division, described a pattern OCR has seen play out in real investigations: organizations that used the SRA Tool but left portions of it incomplete. The software doesn’t require every section to be finished before a user can close it out or generate a report; it simply picks back up wherever the user left off, whenever that happens to be.

    That flexibility is convenient for whoever is filling it out. It’s a liability for the organization relying on it, since an incomplete assessment isn’t a defense in an investigation; it’s a finding. If your risk analysis has gaps because the tool allowed those gaps to sit unresolved, OCR treats that the same way it treats any other incomplete risk analysis.

    OCR Has Never Said the SRA Tool Meets Its Own Standard

    Here’s the detail worth sitting with. At past OCR/NIST conferences, Heesters has been asked directly whether OCR considers output from the SRA Tool to be an โ€œaccurate and thoroughโ€ risk analysis, which is OCR’s own standard under the Security Rule’s Security Management Process provision. He hasn’t given a direct yes or no. His answer has consistently been that the SRA Tool is one of the tools an organization can use as part of a broader risk analysis process, not a guarantee of adequacy on its own.

    The agency that enforces this standard has had multiple chances to say that its own free tool satisfies it, but hasn’t. That’s not a condemnation of the tool; it’s a statement about its limits, and it should shape how much weight any organization places on a completed SRA Tool questionnaire on its own.

    OCR Built This Tool With Smaller Organizations in Mind, and Never Said What โ€œSmallerโ€ Means

    OCR and ONC have described the SRA Tool as designed for small and medium-sized health care providers. Neither agency has defined where that scope actually ends. No stated employee count, revenue threshold, patient volume, or system complexity marks the line between an organization the tool was built for and one that has outgrown it.

    That ambiguity matters because many organizations using the tool don’t actually know which side of that undefined line they’re on. A practice with ten providers and a single EHR is a very different compliance environment than a forty-provider, multi-specialty group running telehealth, a patient portal, and three billing vendors; yet nothing in OCR’s own materials tells either one whether the tool was designed with them in mind. Absent a definition, organizations tend to assume the tool fits them because it’s free and easy to access, not because OCR ever confirmed that it does.

    A Broad Checklist Wasn’t Built Around Your Environment

    OCR’s own guidance, reinforced at the same 2026 conference, describes a risk analysis as an assessment of risk to ePHI at three distinct stages: where it’s created or enters the organization, where it flows internally between systems and departments, and where it leaves the organization entirely. A compliant risk analysis must trace all three stages for your specific systems, your specific vendors, and your specific workforce, not a generalized questionnaire built to apply to every covered entity at once.

    The SRA Tool asks the same structured questions of a practice with five providers, a hospital system, and a school district billing Medicaid. When your organization’s actual ePHI flow doesn’t map cleanly to the tool’s built-in categories, gaps appear, and the tool has no way to flag a misapplied category or a missed system entirely.

    What This Costs Small and Midsize Practices in Practice

    None of this means the SRA Tool has no value; it’s free, and it gives an organization a starting structure. But the real cost shows up when practice staff, who aren’t compliance professionals and aren’t expected to be, spend hours interpreting technical questions about encryption, access controls, and system logging, only to close out a tool that was never confirmed to fit their size or environment in the first place. That’s hours spent and a false sense of security produced, at the same time.

    Frequently Asked Questions

    Does using the free HHS SRA Tool satisfy HIPAA’s risk analysis requirement?

    Not necessarily. OCR has repeatedly declined to confirm that output from the SRA Tool meets its own โ€œaccurate and thoroughโ€ risk analysis standard, describing it instead as one tool that can support a broader risk analysis process.

    Does OCR require organizations to use the SRA Tool?

    No. OCR and ONC offer the SRA Tool as a free resource to help organizations conduct a risk analysis; it isn’t a mandated format, and using it doesn’t by itself guarantee compliance with the Security Rule’s risk analysis requirement.

    Is the SRA Tool meant for organizations of any size?

    OCR and ONC have described the tool as designed for small and medium-sized health care providers, but neither agency has defined what counts as small or medium. Organizations of any size can use it, but there’s no official guidance on where it stops being an appropriate fit.

    Can I leave sections of the SRA Tool incomplete and finish later?

    Yes, and that’s part of the concern. The software allows users to save an incomplete assessment and resume it later, which means an organization may end up relying on a risk analysis that was never completed.

    What did OCR update in SRA Tool version 3.7?

    Version 3.7, released September 10, 2026, added revised assessment coverage and scope questions, new remote access and telework content, updated system activity logging language, expanded asset examples, updated software libraries, and revised reporting.

    What should a practice do instead of relying only on the SRA Tool?

    Use it as a starting point if you choose to, but pair it with, or replace it with, a risk analysis conducted by someone who can map ePHI creation, flow, and exit points specific to your organization, and who can speak to whether the result would hold up under OCR’s own standard.

    Why Spend Hours on a Tool OCR Won’t Vouch For?

    A free tool that OCR itself won’t confirm meets its own standard, that was built with an undefined idea of โ€œsmallerโ€ in mind, that lets you walk away with unfinished sections, and that treats a five-provider practice the same as a five-hundred-provider health system isn’t a shortcut. It’s a slower path to the same uncertainty you started with.

    Colington Consulting’s lead consultants have personally conducted more than 1,000 HIPAA risk assessments; we work directly with your systems, your vendors, and your staff, and build a documented, defensible risk analysis mapped to how ePHI actually moves through your organization, not a generic questionnaire built to apply to everyone at once.

    Get a free HIPAA Risk Review. We’ll show you where a generic tool would leave gaps and what a thorough, defensible risk analysis looks like for your organization.

    Schedule Your Free HIPAA Risk Review โ†’

    Sources

    U.S. Department of Health and Human Services, Office for Civil Rights, and Office of the National Coordinator for Health IT, โ€œHHS Releases Updated Security Risk Assessment Tool,โ€ September 10, 2026.

    U.S. Department of Health and Human Services, Office for Civil Rights, and National Institute of Standards and Technology, โ€œSafeguarding Health Information: Building Assurance Through HIPAA Securityโ€ Conference, September 2 to 3, 2026, NIST Gaithersburg Campus, Gaithersburg, MD.

    U.S. Department of Health and Human Services, Office for Civil Rights, and Office of the National Coordinator for Health IT, Security Risk Assessment (SRA) Tool product documentation and user guide.

    45 C.F.R. ยง 164.308(a)(1), Security Management Process (Risk Analysis and Risk Management).