Compliance & HIPAA Staffing

How Often Must a Small Practice Do a HIPAA Risk Analysis?

A HIPAA security risk assessment for a small practice is not annual by law but by reality. Here's the real frequency, what OCR expects, and how to shrink the scope.

The CallSphere Health Team July 14, 2026 9 min read
HIPAA riskCallSphere AIAudit-readyCOMPLIANCE & HIPAA STAFFING

If you run the front office at a six-doctor primary care group, the question lands on your desk in one of two ugly ways. Either your malpractice carrier's cyber addendum asks for the date of your last risk analysis, or a patient complaint has already reached the Office for Civil Rights and an investigator wants the document by Friday. Both times you are looking for a HIPAA security risk assessment your small practice may not have refreshed since the EHR went live. The good news is that the frequency question has a clear, defensible answer. The better news is that you can shrink how much the assessment has to cover before you ever run it again.

Let me give you the direct answer first, then the reasoning OCR actually applies, because the gap between what the regulation literally says and what enforcement expects is exactly where practices your size get caught.

The Frequency Answer Nobody Writes Down in the Rule

Read the HIPAA Security Rule cover to cover and you will not find the word "annual." The requirement at 45 CFR 164.308(a)(1)(ii)(A) says a covered entity must "conduct an accurate and thorough assessment of the potential risks and vulnerabilities" to electronic protected health information. The companion requirement to review and modify security measures says to do so "as needed" to maintain reasonable protection. No calendar date. No fixed interval.

That vagueness is a trap, not a loophole. OCR's own guidance describes risk analysis as an ongoing process, and every piece of enforcement guidance it has published treats a stale analysis as no analysis at all. So the working answer for a 6-provider practice is this: run a full, organization-wide risk analysis at least once every twelve months, and re-run the affected scope whenever something material changes. "Material change" is not a mystery either. It means you switched EHR or practice management platforms, you added a new vendor that creates or touches ePHI, you opened a second location, you rolled out a patient portal or texting tool, or you had a security incident of any size.

Think of it as a standing annual review with event-driven triggers layered on top. The annual pass proves you are maintaining the program. The triggers prove you are not letting a six-month-old change sit unassessed until the next cycle.

flowchart TD
    A[Last full risk analysis complete] --> B{12 months elapsed}
    B -->|Yes| C[Run full organization-wide analysis]
    B -->|No| D{Material change occurred}
    D -->|New EHR or vendor or location| C
    D -->|Security incident| C
    D -->|No change| E[Continue monitoring]
    C --> F[Document findings and remediation]
    F --> A
    E --> B

The practices that get this wrong almost always do one of two things. They confuse a one-time analysis done at go-live with an ongoing program, or they treat a vendor's security questionnaire as their risk analysis. Neither survives contact with an auditor.

Why 76% of OCR Penalties Trace Back to This One Document

Here is the number that should reshape how you prioritize compliance spending: a large majority of OCR resolution agreements, on the order of 76%, cite the failure to conduct an accurate, thorough, and organization-wide risk analysis. Not the breach. Not the ransomware. The missing or inadequate risk analysis.

That pattern is not a coincidence, and understanding why it happens tells you exactly where your exposure sits. When OCR opens an investigation, whether from a breach report or a patient complaint, the very first document request is almost always your most recent risk analysis. The investigator does not need to reconstruct how a laptop got stolen or how a phishing email worked. They ask for the analysis, and one of three things happens. It does not exist. It exists but is years old. Or it exists and is current but scoped to only part of the practice, so it never covered the system that failed.

Any of those three establishes the violation from paperwork alone. It is the cleanest finding in all of HIPAA enforcement, which is precisely why it appears in three out of four settlements. A breach might be defensible if you can show reasonable safeguards; a missing risk analysis proves you did not know what your safeguards should have been.

For a small practice this is actually reassuring, because it means the highest-leverage compliance work is also the most concrete. You are not trying to guarantee no incident ever happens. You are trying to make sure that when an investigator asks for the foundational document, you hand over something current, thorough, and organization-wide.

What a Defensible Analysis Actually Contains

The free HHS Security Risk Assessment Tool is genuinely useful, and I would not talk anyone out of using it. But running the tool and saving the PDF is not the same as conducting a risk analysis, and OCR has said as much. The tool produces a structured questionnaire; the analysis is the reasoning you document around it.

A defensible risk analysis for a 6-provider office has six documented parts:

  • A data inventory of every place ePHI is created, received, maintained, or transmitted. This is the piece practices consistently under-scope. It includes the EHR and the practice management system, but also the workstations, the backup drive, the fax line, the texting tool, the patient portal, the third-party billing service, the appointment reminder system, and yes, the voicemail box and the sticky-note message pad at the front desk.
  • The threats and vulnerabilities reasonably anticipated against each asset. Theft, ransomware, misdirected fax, an employee accessing records they should not, a vendor breach upstream.
  • The security measures already in place. Encryption, access controls, audit logging, BAAs, training.
  • The likelihood and impact of each threat exploiting each vulnerability. This is your risk rating, high, medium, or low, and it is where judgment gets documented.
  • Your risk determination and the remediation plan. What you decided to fix, in what order, by when, and who owns it.
  • Evidence of follow-through. OCR looks for the loop closing, not just the gap being named.

Notice how much of that inventory is front-desk surface area. The phone system, the voicemail, the message pad, the reminder texts, the after-hours answering arrangement. In most primary care offices the single most touched, least documented ePHI channel is the telephone, and it is the part of the inventory that changes most often as staff turn over.

The Attack Surface You Can Delete Before You Assess It

Here is the lever most compliance consultants skip, because they audit what exists rather than helping you reduce it. Every asset in that inventory is something the risk analysis has to cover, something a threat can target, and something a departing employee can mishandle. The cheapest risk to manage is the one you eliminate from scope entirely.

Consider how patient information actually moves through a busy front desk. A patient calls, the coordinator is with someone at the window, so the call goes to voicemail. The voicemail contains a name, a callback number, and often a symptom or medication question, which is ePHI sitting in a box that may have no access log and no retention control. Someone jots the callback on a paper pad. That pad is ePHI on a desk. After hours, calls route to a personal cell or a legacy answering service that may not have a signed BAA. Each of those is a line item your risk analysis must inventory, rate, and defend, and each is a place a breach can start.

Now consolidate all of it. When an AI front desk answers 100% of calls, books directly into the schedule, and logs every interaction in one BAA-backed system with real audit trails, several of those inventory line items collapse into a single, well-documented channel. The voicemail box with no logging goes away because calls are answered live. The paper message pad goes away because messages are captured and routed digitally. The after-hours gray area with an un-BAA'd answering service goes away because the same compliant system covers nights and weekends. You have not just added coverage; you have removed assets from the surface your annual analysis has to account for. CallSphere is built so that phone-based ePHI lives in one auditable place with a signed BAA behind it, which is exactly the kind of narrowed, documented scope an OCR investigator wants to see. You can see how the call-handling piece fits together on the /features page.

flowchart LR
    A[Voicemail with no log] --> D[Scattered ePHI surface]
    B[Paper message pad] --> D
    C[After-hours answering service] --> D
    D --> E[Large audit scope and risk]
    F[Single BAA-backed call system] --> G[One logged ePHI channel]
    G --> H[Narrow audit scope and risk]

The compliance point is subtle but real: reducing scope is a security control in its own right. Fewer places ePHI lives means fewer threats to enumerate, fewer vulnerabilities to rate, and fewer failure points to remediate. Your risk analysis gets shorter and stronger at the same time.

Budgeting the Annual Cost Without Overpaying

The annual HIPAA risk assessment cost for a practice your size ranges widely, and the range itself tells you how confused the market is. A do-it-yourself pass with the free HHS SRA Tool costs your team's time, realistically 15 to 30 hours of an office lead's year. A guided assessment from a compliance vendor typically runs a few thousand dollars. A full third-party security risk assessment with penetration testing and a written remediation roadmap can run into five figures for a group with multiple locations.

For a 6-provider single-location primary care office, you generally do not need the five-figure engagement every year. A sound pattern is a thorough external assessment when something big changes, such as a new EHR or a new location, paired with a documented internal review using the SRA Tool in the intervening years, plus your event-driven re-runs. What you cannot do is skip it, because the cost of a missing analysis is not measured against consultant fees. It is measured against OCR penalties that start in the tens of thousands and against the cyber-insurance claim that gets denied when you cannot produce a current analysis.

The smartest money is spent narrowing scope before you assess, because every channel you consolidate lowers both the assessment effort and the ongoing risk it documents. A flat-rate front-desk system that folds phone ePHI into one logged, BAA-backed channel does double duty here: it covers calls you are currently missing and it simplifies the compliance work you are currently dreading. The /pricing page lays out the flat monthly cost, which is far easier to reconcile against a compliance budget than a variable answering-service invoice with no BAA behind it.

Where to Start This Week

If you are not sure your practice has a current, defensible risk analysis, treat that as the finding and act on it. Pull the last analysis and check the date and the scope; if it is more than a year old or does not name every system and phone channel you use today, it is stale. Build or update the ePHI inventory first, because everything else hangs off it, and pay special attention to the front-desk channels that change every time someone leaves. Then, before you commission the next full assessment, ask a simpler question: how many of these ePHI touchpoints can I consolidate or delete? A voicemail box you no longer use, an answering service without a BAA, and a paper message pad are three line items you can remove from scope entirely. The narrower the surface, the shorter the analysis, and the less there is to defend the day the investigator's document request lands.

Frequently asked questions

How often does a small medical practice have to do a HIPAA risk assessment?

The Security Rule requires that risk analysis be conducted and updated 'as needed,' with no fixed calendar date, but OCR treats a genuinely current analysis as the standard. In practice a 6-provider primary care office should complete a full organization-wide analysis once a year and re-run the relevant portion any time you change EHR, add a new vendor that touches ePHI, open a location, or suffer a security incident.

What does OCR expect documented in a HIPAA risk analysis?

OCR expects a scoped inventory of everywhere ePHI lives and moves, a list of reasonably anticipated threats and vulnerabilities against each of those assets, an assessment of the likelihood and impact of each, the security measures already in place, and your risk determination with a remediation plan and timeline. The checklist output from a tool is a starting point, not the finished analysis; the documented reasoning and the follow-through are what auditors ask for.

Why do so many HIPAA fines involve risk analysis failures?

Because the risk analysis is the foundational requirement every other safeguard depends on, and it is the easiest gap for OCR to prove from documents alone. Investigators do not have to reconstruct a breach; they simply ask for your most recent analysis, and when it is missing, years old, or scoped to only part of the practice, the violation is established on paper. That is why risk-analysis findings appear in roughly three-quarters of resolution agreements.

Stop staffing around the problem. Let AI cover it.

CallSphere Health puts an AI team inside every part of your front office — answering every call, filling the schedule, chasing claims and recalling patients — so a short-staffed practice runs like a fully-staffed one.

Keep reading