HHS recently updated the HIPAA Security Risk Assessment Tool (SRA Tool) to version 3.7. The last version 3.6 was implemented one year ago in September 2025. Questions, responses, and educational materials have been updated, including an emphasis on ensuring all locations involved with Protected Health Information (PHI) are captured, including the locations of remote workers. New technologies, such as the use of AI or other productivity tools that may have access to PHI, may warrant running a fresh assessment using the new tool.
Applies to:
-
Employers with level-funded or self-funded health plans, including Health Reimbursement Arrangements (HRAs) and/or Health Flexible Spending Arrangements (FSAs)
-
Employers with a fully insured medical, dental, or vision plan providing access to PHI, such as a claims analytics data feed
-
Business Associates with access to PHI
-
Exempt: Self-funded plans which are self-administered and have fewer than 50 eligible employees, covered retirees, and COBRA qualified beneficiaries (but it is rare to not have a claims administrator assisting the employer with their plan, so this exception is rarely applicable)
Go Deeper:
Cybersecurity protections of PHI are of paramount importance, and the updated SRA tool takes into account new technologies and the rise of remote work. As a reminder, the SRA is just the start of complying with HIPAA Privacy and Security. It is intended to identify where risks to PHI can occur. From there, the employer must:
-
develop administrative, physical, and technical safeguards,
-
limit the use/disclosure of PHI to the minimum necessary,
-
protect PHI at every step (including regular threat scanning, activity monitoring, and encryption),
-
develop policies and procedures to protect PHI,
-
train employees accordingly,
-
distribute a Notice of Privacy Practices to new plan participants, and
-
develop robust breach analysis, mitigation, and reporting protocols.
Penalties for Non-Compliance:
When a potential breach of unsecured PHI occurs, the federal government may conduct an investigation. When it finds an SRA was not conducted or was not updated when the employer’s plan or operating environment significantly changed, the employer can be subject to fines and penalties. A violation can also trigger litigation risk. In the first half of 2026, two employers experiencing a ransomware attack that led to a breach of unsecured PHI had to pay settlements of $245,000 and $450,000 along with agreeing to a multi-year corrective action plan allowing the federal government to regularly review their operations.
Practical Impact to Employers:
Last year, the SRA Tool was improved to allow for individual marking of each section independently of others to better track the last date and person to review each provision. With the expansion of remote work and new technology, particularly AI tools, employers will want to keep their SRA current and utilize the latest version.
COMMENTS