Back to Blog
Compliance

HIPAA Risk Analysis for MSPs: A Step-by-Step Guide for 2026

The HIPAA security risk analysis is now OCR's #1 enforcement target — and the 2026 Security Rule update makes it annual. This guide covers what a compliant analysis looks like, what changed, and how to package it as a recurring MSP service.

BC
Brett Coffin
Updated July 20267 min read

HIPAA Risk Analysis for MSPs: A Step-by-Step Guide for 2026

TLDR: A HIPAA security risk analysis is the foundational requirement under 45 CFR 164.308(a)(1) — and it's now OCR's number-one enforcement target. Inadequate risk analysis appeared in more HIPAA enforcement actions than any other violation in recent OCR data, and the pending 2026 HIPAA Security Rule update codifies annual analysis cycles, mandatory ePHI asset inventories, and biannual vulnerability scanning. This guide covers what a compliant risk analysis looks like, what the 2026 rule changes mean for your clients, and how to package this into a recurring MSP service.


If you manage IT for healthcare organizations, their first HIPAA audit question almost always comes down to the same document: the security risk analysis. Not the firewall configuration. Not the encryption policy. The risk analysis.

The reason is simple: a security risk analysis is what the law requires before everything else. Under 45 CFR 164.308(a)(1)(ii)(A), covered entities and business associates must conduct an "accurate and thorough assessment of the potential risks and vulnerabilities" to the confidentiality, integrity, and availability of electronic protected health information (HHS HIPAA Risk Analysis Guidance). It is the required first step — and in recent OCR enforcement data, it is also the most frequently missed one.

For MSPs managing healthcare clients, this creates both a compliance obligation and a clear service opportunity. If your clients do not have a documented, current risk analysis, they are exposed — and you are the one positioned to fix it.

Why Risk Analysis Is OCR's Primary Enforcement Focus Right Now

In October 2024, OCR launched a dedicated "Risk Analysis Initiative," signaling it would specifically focus HIPAA investigations on whether organizations had conducted adequate risk analyses. The results came quickly. Within its first several months, the initiative resulted in combined settlements of nearly $900,000 from eight healthcare organizations — for failures that often came down to missing or outdated risk analysis documentation ([Feldesman LLP, 2025](https://www.feldesman.com/ocrs-new-security-risk-analysis-initiative-results-in-seven-enforcement-actions-in-first-six-months/)).

Inadequate risk analysis was the most frequently cited violation in recent OCR enforcement data, appearing in 13 separate matters as of early 2025 ([Shook Hardy & Bacon, 2025](https://www.shb.com/intelligence/newsletters/pds/hansen-march-2025-ocr-enforcement)). And in 2026, OCR announced it is expanding the initiative to cover risk management as well — meaning regulators now expect organizations to prove not only that they identified risks, but that they acted on them with documented remediation.

The enforcement math is straightforward. Healthcare data breaches cost an average of $7.42 million per incident — the highest of any industry, a position healthcare has held for 14 consecutive years ([IBM Cost of a Data Breach Report, 2025](https://www.ibm.com/reports/data-breach)). Healthcare breaches also take an average of 279 days to detect and contain, compounding the financial exposure. A documented, current risk analysis is the first line of defense against both the breach and the regulatory fine that can follow.

What the 2026 HIPAA Security Rule Update Changes

The pending 2026 HIPAA Security Rule update — published as a proposed rule in January 2025 and moving toward finalization — significantly tightens the risk analysis requirement. For MSPs, the key changes are:

Annual risk analysis cycle. The update explicitly codifies an annual requirement. Organizations must conduct and document a fresh risk analysis at least once per year, and whenever a relevant change to systems, operations, or technology occurs.

ePHI technology asset inventory. Organizations must maintain a documented inventory of all technology assets that create, receive, maintain, or transmit ePHI. The inventory must be reviewed and updated at minimum annually. For MSPs, this maps directly to the asset visibility you already maintain for clients — it now needs to be formally documented and linked to ePHI data flows.

Biannual vulnerability scanning. The proposed rule mandates vulnerability scanning at minimum every six months on all systems that handle ePHI. Annual scans are no longer sufficient.

Annual penetration testing. Annual penetration testing of ePHI-handling systems becomes a mandatory requirement, not a best practice. For smaller healthcare clients managed by MSPs, this opens a clear and defensible service line.

For a full breakdown of what the 2026 Security Rule overhaul means across all administrative, physical, and technical safeguard categories, see our overview of the 2026 HIPAA Security Rule changes.

The Eight Elements of a Compliant HIPAA Risk Analysis

HHS guidance defines the components of an "accurate and thorough" risk analysis. A compliant analysis addresses all eight elements:

1. Define the scope. Identify every system, application, database, device, and process that creates, receives, maintains, or transmits ePHI. The 2026 update makes this a formal, documented asset inventory — no longer an informal exercise.

2. Gather data on ePHI flows. Document where ePHI lives, how it moves, and who accesses it. This includes on-premises systems, cloud applications, backup infrastructure, mobile devices, and third-party integrations (EHRs, billing platforms, telehealth tools).

3. Identify threats. What events could compromise ePHI confidentiality, integrity, or availability? Common categories include ransomware, unauthorized access, insider threats (accidental and malicious), physical theft or loss of devices, third-party vendor failures, and natural disasters. Threats should reflect the actual environment and vertical — a behavioral health clinic faces different threat scenarios than a dental group.

4. Identify vulnerabilities. Where could threats exploit weaknesses in the client's current controls? This includes technical vulnerabilities (unpatched systems, weak access controls, misconfigured cloud settings), process vulnerabilities (no workforce training, no access review cadence), and physical vulnerabilities (uncontrolled physical access to servers or workstations containing ePHI).

5. Assess current security controls. What controls are already in place, and how effective are they? Document existing safeguards — MFA, endpoint protection, encryption, backup configurations, access policies — and evaluate whether they adequately address the vulnerabilities identified in the prior step.

6. Determine likelihood. For each threat-vulnerability pair, assess the likelihood that a threat event will occur and successfully exploit the vulnerability. Use a consistent scale: high, medium, and low is sufficient. A numerical matrix is not required but aids documentation consistency across clients.

7. Determine impact. If the threat succeeds, what is the impact on ePHI confidentiality, integrity, or availability? Consider both the magnitude of potential harm to individuals and the number of records affected.

8. Determine and document risk levels. Combine likelihood and impact into a composite risk level. This produces the prioritized risk register that drives the subsequent risk management plan — the remediation roadmap that 2026 enforcement will also scrutinize. Every element must be documented in a format that can be produced on request during an OCR investigation.

Packaging HIPAA Risk Analysis as a Recurring MSP Service

The risk analysis is not a one-time project. The 2026 rule update makes it annual, and it is most valuable as a living document updated whenever the environment changes. That makes it a natural fit for recurring MSP service delivery.

A practical tiered structure:

  • **Initial HIPAA Risk Analysis** ($2,500–$5,000 project): Conduct the full eight-element analysis for a client that has never had one or has not updated it in years. Deliver a documented risk analysis report and a prioritized risk register. This is the natural follow-up deliverable after running an initial [MSP security assessment](/msp-security-assessment) for any healthcare client.
  • **Annual Risk Analysis Update** ($1,200–$2,500/year): Conduct the required annual refresh — updated asset inventory, updated threat and vulnerability assessment, validation of controls implemented since the prior analysis, and an updated risk register. This is the recurring revenue component: once a client has invested in the initial analysis, they have every reason to maintain it.
  • **Biannual Vulnerability Scanning** ($300–$800/month): Deliver the vulnerability scans now required under the proposed rule, with remediation reporting and evidence documentation formatted for compliance records.
  • **Annual Penetration Testing** ($2,000–$5,000/year): Satisfy the annual pen test requirement with scoped testing of ePHI-handling systems and a written report usable as audit evidence.

Bundled into a HIPAA Compliance Program tier, these services create a subscription offering with a hard regulatory mandate behind every renewal conversation. For a broader look at how to build productized compliance offerings, see the HIPAA compliance checklist for MSPs and how it maps to each safeguard category. And if you are also supporting clients with SOC 2 readiness, note that SOC 2 auditors review risk assessment processes as part of the CC3 criteria — the same risk analysis work you are doing for HIPAA produces directly usable evidence for SOC 2 compliance as well.

Documenting for Audits

The deliverable of a HIPAA risk analysis is not just the findings — it is the documentation. During an OCR investigation, the risk analysis is one of the first artifacts requested. The document should:

  • Be dated and attributed to a responsible party or role
  • Identify the scope, methodology, and data sources used
  • Document all eight analysis elements with supporting evidence
  • Map threat-vulnerability pairs to risk levels
  • Reference the resulting risk management plan (the remediation roadmap that tracks how identified risks are being addressed)
  • Include a version history showing when it was last updated and what triggered the update

If you are conducting risk analyses across multiple healthcare clients, consistent documentation templates are essential. They ensure quality, reduce the time required for each annual update, and produce a recognizable, professional artifact when clients need to demonstrate compliance to their own auditors, insurers, or business partners.

For a complete view of how HIPAA controls — including risk analysis — map across all eight supported frameworks in a multi-tenant dashboard, explore the HIPAA compliance for MSPs platform overview.


*Ready to run HIPAA gap assessments and track risk analysis status across your full healthcare client portfolio from a single dashboard? Start free with Nuronus — 2 clients, no credit card required.*

Ready to Add Compliance Services to Your MSP?

Free forever for 2 clients. All features included. No credit card required.

Get Started Free
BC

Brett Coffin

Founder, Nuronus

20+ years in IT infrastructure and security. Built Nuronus after watching MSPs leave compliance revenue on the table because the tooling made it impossible to deliver profitably.