Version 3.7 widens the assessment scope to every location that handles electronic protected health information.

 

What happened

The HHS Office of the National Coordinator (ONC) for Health IT and the Office for Civil Rights released version 3.7 of the Security Risk Assessment Tool in September 2026, according to HealthIT.gov. The tool is a free Windows desktop application, also available as an Excel workbook, that walks an organization through the risk analysis the HIPAA Security Rule requires. It uses a wizard-based format covering multiple-choice questions, threat and vulnerability assessments, and asset and vendor management, with references and guidance provided throughout. The ONC states that the intended audience is medium and small providers, and that the tool may not be appropriate for larger organizations. It was first released in March 2014.

 

Going deeper

New questions in this version cover remote access and telework, meaning staff connecting from outside the organization's premises. The scope of the assessment has been widened to account for every location that creates, receives, maintains, or transmits electronic protected health information, rather than a single primary site. System activity logging also receives expanded treatment. Content across questions, responses, and the educational material has been revised. An updated user guide accompanies the release, and the ONC hosted two live training webinars on September 15 and 16 covering installation, use, and the changes in this version.

 

What was said

The tool is "designed to help healthcare providers conduct a security risk assessment as required by the HIPAA Security Rule," ONC states on the tool's page, adding that users are guided through the process using a simple, wizard-based approach with references and additional guidance given along the way. Reports can be saved and printed at the end of the assessment.

 

In the know

Use of the tool "is neither required by nor guarantees compliance with federal, state or local laws," HHS states on the tool's own page. Version 3.7 adds a reminder to that effect inside the application itself, telling users the survey alone may not identify every risk present in their organization. What the tool produces is a documented record of the analysis, and the analysis is what regulators examine. The expanded scope in this version matches a recurring finding in enforcement, where assessments covering one facility, one system, or a single electronic health record have been found insufficient against a requirement reaching every system that holds electronic protected health information.

 

The big picture

Both organizations OCR penalized this year failed at the step this tool exists to support. Spencer Gifts employee health plan paid $450,000 after a ransomware attack encrypted servers holding member data, with the agency finding it had conducted no accurate and thorough risk analysis and implemented no compliant policies, in a June resolution that marked its 14th action under the Risk Analysis Initiative. An Illinois health system paid $552,250 in July over a 2021 attack, where OCR cited the same failure alongside late breach notification, in an announcement making it the 21st ransomware enforcement action. Neither settlement turned on the sophistication of the attack. Both turned on whether an assessment existed and what it covered, which is the gap version 3.7 widens its scope to address. It also adds review triggers, meaning prompts identifying when an existing assessment should be revisited, according to HealthIT.gov. For a compliance officer, the practical questions are when the analysis was last completed, whether it covered every location now handling patient data, and whether anyone acted on what it found.

 

FAQs

Does using the SRA Tool satisfy the Security Rule requirement?

Conducting the analysis satisfies the requirement, and the tool is one way to do it. The output is documentation of the assessment rather than certification of compliance, and an organization still has to implement security measures addressing the risks the analysis identifies.

 

How often should a risk analysis be repeated?

The rule requires it to be accurate and thorough without specifying an interval, and OCR expects updates when the environment changes materially. New systems, new vendors, a change in facilities, or an incident all warrant revisiting the analysis rather than waiting for an annual cycle.

 

What does expanded scope mean for a practice with multiple sites?

Every location that creates, receives, maintains, or transmits electronic protected health information falls within the assessment, including satellite clinics, remote workers' home setups, and cloud environments. A practice assessing only its main office has not covered the required scope.

 

Is the tool suitable for a large health system?

ONC states it is aimed at medium and small providers and may not be appropriate for larger organizations. Health systems with intricate environments generally need a more detailed methodology, though the tool's question set can still serve as a reference for what an assessment should address.

 

What happens to the data entered into the tool?

The application runs locally on the user's device, and the assessment file stays under the organization's control rather than being transmitted to HHS. That file becomes part of the compliance record, so it needs the same protection and retention treatment as other documentation.