Organization Information45 CFR §164.308(a)(1) — Required annually
ePHI System Inventory
Identify every system, device, application, and location where ePHI is stored, processed, or transmitted. This is the foundation of your risk analysis.
—
Avg Risk Score
0
Critical Risks
0
High Risks
0
Medium Risks
0
Low Risks
Threat & Vulnerability Assessment
Score: Likelihood × Impact = Risk Score
| Threat | Category | Likelihood (1–5) | Impact (1–5) | Risk Score | Risk Level |
|---|
Risk Heat Map
↑ Likelihood→ Impact
Risk Distribution
HIPAA Security Rule Safeguard Assessment
R=Required · A=Addressable · Score: 4=Full, 3=Substantial, 2=Partial, 1=Planning, 0=None
Prioritized Risk RegisterAuto-populated from threat assessment — edit as needed
| Risk ID | Risk Description | Level | L | I | Score | Treatment | Owner | Target Date |
|---|
Risk Management & Remediation Plan§164.308(a)(1)(ii)(B) — OCR Evidence Documentation
HIPAA Security Risk Analysis — Executive Summary
Organization · Assessment Period
0
Critical Risks
0
High Risks
—
Safeguard Score
0
Remediation Actions
NIST CSF Function Coverage (Safeguards)
Safeguard Implementation Status
Overall Risk Assessment Narrative
Certification & Sign-Off