4 Ways Using the HHS Security Risk Assessment Tool Can Help Your Organization

As ONC works to advance the development and use of health IT, we know that you play an important and equal role in maintaining the public’s confidence and trust. The privacy and security of health information is always at the forefront of our work and your organization’s business practices. In the spirit of National Cyber Security Awareness Month (NCSAM), we want to highlight the HHS Security Risk Assessment (SRA) Tool, which you can use to assess your organization’s security risks. If you are responsible for the privacy or security of electronic protected health information (ePHI), you may be particularly interested in the SRA Tool.

In the health care sector, security is the way your organization implements administrative, technical, and physical safeguards to provide for the confidentiality, integrity, and availability of health information. Conducting a security risk assessment is one way to identify and assess risks to ePHI within your organization, check if your organization has appropriate safeguards in place, and reveal any areas where ePHI may be at risk. You can then take action to mitigate any risks that are found. For example, assessing security risks can help your organization reduce the chance of being impacted by a variety of cyber-attacks, malware, ransomware, and other online scams.

Conducting a security risk assessment is one way to identify and assess risks to ePHI within your organization, check if your organization has appropriate safeguards in place, and reveal any areas where ePHI may be at risk.

With known and emerging cyber security risks in the health care sector, using the SRA Tool can help your organization in the following 4 ways. Best of all, it’s free!

All you need to do to get started is download the SRA Tool. Be sure to review the User Guide for tips on using the SRA Tool. Questions? Email the Help Desk or check out the materials from and audio recording of our August webinar. The current version of the SRA Tool includes functionality updates based on public input. We want to continue to make improvements, so if you have suggestions after using the SRA Tool, please reach out to us via the Health IT Feedback Form.

Assessing risk is an important step in your security management process and helps your organization recognize where safeguards are needed to protect ePHI, including guarding against ransomware and other types of cyber-attacks. Get started today – download and use the SRA Tool.

Categories