HHS has released version 3.7 of its Security Risk Assessment Tool, the free download that walks small and mid-sized HIPAA-regulated organizations through the risk analysis the Security Rule demands.
The tool was built by the Office of the National Coordinator for Health IT with the Office for Civil Rights and first appeared in 2014. The September 2026 release adds questions about newer technologies that practices have adopted, a scope question that forces organizations to account for every location that creates, receives, maintains, or transmits electronic protected health information, fresh remote access and telework items, a modernized asset inventory, and an updated system-activity logging question. Software libraries and bug fixes round out the update.
The refresh lands as OCR keeps pressure on an area it says providers still neglect. Twelve years after the tool debuted, the agency continues to find risk analyses that were never completed, were incomplete, or went undocumented. OCR launched a dedicated risk analysis enforcement initiative in 2024 and has imposed 14 financial penalties under it. At the 2026 NIST/OCR conference, OCR Director Paula Stannard warned that adopting the agency’s cybersecurity performance goals does not satisfy the risk management standard.
Compliance teams should treat the new scope and telework questions as a prompt to revisit assessments that were signed off years ago.