The Department of Health and Human Services (HHS) Security Risk Assessment Tool, or SRA Tool, is a questionnaire designed to help healthcare organizations discover potential risks and vulnerabilities with electronic protected health information (ePHI). Created by the Office of the National Coordinator for Health Information Technology and HHS Office for Civil Rights (OCR),
As for the question, does the HHS Security Risk Assessment Tool still apply? Yes. It still applies to many small and medium- sized healthcare providers and business associates who want to assess how ePHI enters, travels through, and exits an organization via email.
Therefore, providers can pinpoint gaps in email security before those gaps lead to unauthorized access or disclosure. The assessment can also help determine which safeguards to implement, such as HIPAA compliant email.
How the HHS Risk Assessment can help
Meeting the risk analysis requirement
The HIPAA Security Rule mandates that covered entities and business associates perform an “accurate and thorough assessment” of risks and vulnerabilities to the confidentiality, integrity and availability of ePHI. As stated in HHS’s risk analysis guidance, risk analysis is step one in determining and implementing appropriate safeguards.
The Security Rule does not require you to use a specific risk analysis method, so you are not obligated to complete the HHS tool. What you are required to do is complete and document a risk analysis that is sufficiently detailed.
In particular, the SRA Tool asks a series of questions regarding security policies, access by workforce members, data encryption, physical security, vendors and contingency planning. These areas of potential weakness can help determine whether an organization has sufficiently incorporated its email into its security program.
Using the latest version
The SRA tool is not an abandoned resource. Version 3.6.1 is currently available from HHS both as a Windows application and as an Excel workbook.
Changes in version 3.6 included new content based on then-current cybersecurity guidance documents and user feedback. New section approval records were added. Terminology was changed to match National Institute of Standards and Technology risk terminology. Questions and education material were updated to reflect the dynamic cybersecurity landscape. Version 3.6.1 included an updated installer certificate and a typo fix to the workbook.
Sources of information used to develop the tool include the HIPAA Security Rule, the Health Information Technology for Economic and Clinical Health Act, National Institute of Standards and Technology publications, and NIST Cybersecurity Framework 2.0.
Identifying where email contains ePHI
When thinking through email, healthcare organizations need to consider where departments send ePHI, what information is included in messages and attachments, where those messages are stored and whether staff forwards them to mobile devices or external mailboxes. Don't forget to consider shared mailboxes, automated notifications, archived mail, and backups/instantiations, as well as any integrations that can read email content.
Assessing email threats and vulnerabilities
Email risks may include phishing, password compromise, misdirected emails, unsafe forwarding practices, improperly implemented authentication, lack of encryption, excessive permissions, and third-party vendors transmitting ePHI without a business associate agreement (BAA).
Tools like the HHS’s establish a framework for organizations to score threats/vulnerabilities based on probability and potential impact. For instance, a practice can note that a vulnerability exists in the form of a phishing email that could result in account compromise. Then they can determine whether mitigations like multifactor authentication and inbound filtering are in place. Lastly, they can apply a score/risk rating based on the anticipated impact should the compromise occur.
It’s important to note that these risks are still prevalent. Paubox’ 2026 Healthcare Email Security Report reviewed 170 email-borne healthcare breaches that occurred in 2025 and impacted the PHI of 2.5 million individuals. The study also revealed that 74% of breached domains had ineffective DMARC implementation.
Assessing email vendors
The SRA Tool walks you through a section on vendors, business associate agreements, and vendor access to PHI. You’ll need to complete this section any time an email provider or security vendor stores, creates, receives, maintains, or transmits ePHI on behalf of your organization.
Use this section of the assessment to document exactly which vendors have access to your email data, whether or not you have signed business associate agreements with each vendor, and what security promises each vendor offers. Don’t forget to note any subcontractors and associated applications that can read, copy, archive or analyze message content.
Remember that signing a business associate agreement won’t make your email service magically secure. Rather, a BAA defines contractual obligations that must work in conjunction with encryption, access controls, monitoring, policies, and other security controls.
Translating findings into solutions
Simply finishing the assessment won’t improve your security. As the summary page of the HIPAA Security Rule puts it, each covered entity must manage the risks it has identified by implementing security measures that reduce those risks to a reasonable and appropriate level.
So if your assessment uncovers that messages with ePHI aren’t being encrypted consistently, employees can send PHI via personal email accounts, or your organization can’t tell if suspicious users accessed a mailbox, your risk management plan may dictate implementing automatic encryption, stronger authentication, data loss prevention (DLP) rules, better audit logging, staff training, documented incident response processes, or other solutions.
A HIPAA compliant email solution like Paubox automatically encrypts outbound emails without staff having to click a button or prepend a subject-line command. Based on your chosen service level, you can also use inbound threat protection, email archiving, and DLP to help mitigate many other common findings.
Why risk assessment should happen before and after email breaches
HIPAA’s HHS SRA Tool is often misunderstood as being interchangeable with the assessment organizations must perform after a potential breach of PHI.
The SRA Tool is meant to support, not replace, the larger Security Rule risk analysis process. As described in the tool’s FAQ, “the primary purpose of the SRA Tool is to help organizations conduct their initial identification and management of risks to ePHI before an incident occurs.” However, organizations should conduct new analyses after a security incident or major operational change affects their current safeguards.
HIPAA’s Breach Notification Rule uses a four-factor assessment to determine whether there is a low probability that PHI has been compromised after an impermissible email disclosure or other breach of unsecured PHI.
The risk assessment considers:
- The nature and extent of the PHI disclosed, including sensitivity of the data and purposes for which it was used
- Whether the person who received the PHI would have known that it was PHI
- Whether the PHI was actually acquired or viewed
- The extent to which the risk of damage to the PHI has been mitigated
Upon completion of that assessment, organizations may want to return to the SRA Tool to document lessons learned from the breach and reassess their safeguards moving forward. But the SRA Tool does not replace the breach risk assessment based on the facts of the incident, or subsequent notification requirements if it was determined that patients’ health information was compromised.
Why HIPAA compliant email needs to be proactive
A reactive approach to email security means waiting for PHI to be disclosed or transmitted and waiting for a cyberattacker to target an employee’s email account. It replaces prevention and threat reduction with containment and breach notification.
In light of the rising threat of ransomware attacks, OCR Director Paula M. Stannard said, “Proactively implementing the HIPAA Security Rule before a breach or an OCR investigation not only is the law but also is a regulated entity’s best opportunity to prevent or mitigate the harmful effects of a successful cyberattack.”
OCR reached settlements with four different healthcare providers as a result of the ransomware attacks they suffered in April 20226. Organizations can use the HHS Risk Assessment Tool to evaluate their current safeguards before an email breach occurs. Then, HIPAA compliant email solutions can automate and enforce best practices for the channel staff use every day.
FAQs
Can the SRA Tool determine whether an email incident is a reportable breach?
The SRA Tool can help an organization reassess its general email risks, but a possible breach requires the separate assessment described in the HIPAA Breach Notification Rule.
Does HHS regulate every email containing health information?
No, HHS’s OCR enforces HIPAA against covered entities and their business associates.
Does HIPAA prohibit healthcare providers from emailing patients?
The HHS permits providers to discuss health issues with patients by email, provided they use reasonable safeguards. These safeguards can include confirming the address, limiting unnecessary PHI, restricting access, and protecting ePHI under the Security Rule.
