Quick answer

On September 10, 2026, OCR and ONC released version 3.7 of the free Security Risk Assessment Tool. It is a real improvement, and for a small practice with nothing on file it is far better than nothing. It is also a self assessment, which means it evaluates the practice you describe to it, and the government’s own page says using it neither satisfies nor guarantees compliance.

What the tool is

The Security Risk Assessment Tool is free software published jointly by the HHS Office for Civil Rights and the Office of the National Coordinator for Health Information Technology. It was built for small and medium sized providers who do not have a compliance department.

You install it, answer a long sequence of questions about your practice, and it produces a report.

That report is genuinely helpful. It walks a practice owner through categories most people would not think to consider, and it produces something written at the end. If the alternative is a practice that has never documented anything, the tool is the better outcome and I am not going to pretend otherwise.

What version 3.7 changed

The September 10 update is not cosmetic. The changes OCR and ONC describe include:

Assessment coverage and scope questions. This is the most interesting addition, and it points directly at the failure described further down this page.

Questions covering remote access and telework. Practices added remote work arrangements during and after 2020 and mostly never revisited what that meant for their data.

Revised language on system activity logging. Logging is one of those requirements that practices assume their software handles.

Expanded asset examples reflecting newer technology, updated software libraries, and revisions to the report output.

OCR ran webinars on September 15 and 16 walking through the changes.

The sentence on the government’s own page

The healthit.gov page for the tool includes a line worth reading slowly. It states that use of the tool is “neither required by nor guarantees compliance with federal, state or local laws.”

That is the publisher of the tool telling you that running it is not the same as satisfying the rule.

This is not a criticism of the tool. It is an accurate description of what a self assessment can and cannot establish, written by the people who built it.

Why scope is where this breaks

A questionnaire can only assess what you tell it exists.

That sounds obvious written down. In practice it is the single most common reason a risk analysis fails to hold up.

The requirement at 45 CFR 164.308(a)(1)(ii)(A) is an accurate and thorough assessment of risks to electronic protected health information held by the covered entity or business associate. All of it, wherever it lives.

When a practice owner sits down with the tool, they describe the practice they picture. The front desk computers. The server. The EHR.

What tends not to get entered is the laptop a departing employee took home two years ago. The satellite location that runs its own scheduling. The cloud backup a former IT vendor set up and nobody has logged into since. The billing company’s portal. The archiving company still holding a complete copy of the records from the last EHR migration.

Version 3.7 adding scope questions is an acknowledgment of exactly this. It helps. It still cannot find what you do not know to declare.

The second half nobody finishes

There is a separate problem that has nothing to do with scope.

Risk analysis is one requirement. Risk management is another. 45 CFR 164.308(a)(1)(ii)(B) requires implementing security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.

The tool’s report is an input to that. It tells you what you found. It does not decide what you are going to do, who owns each fix, or by when.

I have seen practices produce a thorough assessment report, file it, and treat the requirement as closed. The report then sits untouched while the findings inside it stay open. From a regulator’s point of view that is a practice that identified its risks and did nothing, which is a worse position than not having looked, because now the problems are documented.

How to use the tool well

If you are a small practice with nothing on file, run it. Today. A flawed assessment beats an empty folder, and the 3.7 scope questions will surface things you have not considered.

Then do three things the tool will not do for you.

Walk your data before you answer. Before you enter anything, write down every place patient information lives. Every device, every location, every cloud service, every vendor with a login. Answer the questions against that list rather than against memory.

Write the plan the report implies. Take each finding, assign a person, assign a date, and record what you decided and why. That record is your risk management documentation and it is separately required.

Put it on a calendar. The analysis is not a one time event. Systems change, vendors change, staff change. An assessment that describes a practice you no longer run is not accurate or thorough.

The honest position

The free tool is not a trap and it is not a substitute. It is a well built questionnaire published by the regulator, and the regulator has told you in writing that completing it does not answer the requirement.

If your practice is small, your systems are simple, and you will genuinely do the scoping and the follow through yourself, the tool may be all you need.

If you have more than one location, meaningful vendor relationships, or nobody with the time to own the follow through, the gap between the report and the requirement is where the exposure sits. That gap is the work, and it is what a HIPAA Risk Analysis engagement is for.

Last Updated: September 21, 2026