The short answer: a HIPAA security risk assessment is a compliance document — a systematic, written analysis of where electronic patient health information lives and what threatens it, required by the Security Rule. An IT assessment is an operational document — a technical review of your infrastructure’s health, performance, and security. An IT assessment can feed a risk assessment, but it cannot replace one, and auditors know the difference at a glance.
What a HIPAA security risk assessment covers
- Where ePHI lives: every system, device, and vendor that stores, processes, or transmits patient data — including the imaging archive and the billing service everyone forgot.
- Threats and vulnerabilities against each of those locations, from ransomware to a lost laptop to a departed employee’s lingering account.
- Likelihood and impact ratings — documented reasoning, not just a checklist.
- Current safeguards and gaps, with a remediation plan and dates.
- Evidence of review over time. A risk assessment from five years ago demonstrates five years of neglect, not compliance.
What an IT assessment covers
Hardware age and health, network design, software versions and patching, backup status, security tooling, and performance problems — the state of the machinery. It answers “is our IT good?” where the risk assessment answers “is patient data protected, and can we prove we’ve thought about it?”
Why the confusion is expensive
When an audit letter or a breach investigation arrives, the first document requested is typically the security risk assessment. Practices holding a vendor’s “network assessment” PDF discover it lacks the required elements — ePHI inventory, threat analysis, documented reasoning — and the finding becomes “no risk assessment,” one of the most common and most avoidable citations. The technology can be genuinely excellent and the compliance posture still fail on paper.
You need both, on different rhythms
- Risk assessment: reviewed at least annually and after major changes — new location, new practice management system, new imaging platform.
- IT assessment: continuous in spirit — monitoring, quarterly reviews, and lifecycle planning rather than a yearly snapshot.
Done well, the second feeds the first automatically: the same monitoring and documentation that keeps systems healthy generates the evidence the risk assessment needs. That’s how our HIPAA IT compliance support works — the binder fills itself as a byproduct of real work, and it pairs with the security stack that closes the gaps the assessment finds.