Medical and dental · Who's allowed to read it

The free tool from HHS, and the rule that isn't law yet

Two things worth knowing before you buy anything from anybody. HHS publishes a risk assessment tool built for small practices, free, and it keeps everything on your own computer. And the Security Rule overhaul your inbox keeps warning you about is still a proposal.

We build software. Not legal or compliance advice; sources at the foot of the page.

The tool

The Security Risk Assessment Tool is published by the Office of the National Coordinator for Health IT together with the HHS Office for Civil Rights. It is free. It comes as a Windows desktop application or an Excel workbook, and the current release is version 3.6.1, updated May 2026.

Its own page is unusually clear about who it is for: "The target audience of this tool is medium and small providers; thus, use of this tool may not be appropriate for larger organizations."

And the sentence that matters most to anyone nervous about where their answers end up:

"All information entered into the tool is stored locally on the user's computer. HHS does not collect, view, store, or transmit any information entered into the SRA Tool."

It walks you through a wizard: threats and vulnerabilities, assets and vendors, a run of multiple-choice questions, and a report at the end that you keep. The risk analysis it is built around is not optional decoration — 45 CFR 164.308(a)(1)(ii)(A) requires "an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information".

What it will not do for you

It is not an AI tool and it does not know about your chatbots. It will ask you about assets and about vendors, and an AI tool shows up in those sections only if you put it there.

Which is a decent argument for doing the inventory first. The tool is good at making you systematic about a list. It cannot produce the list.

The rule that is not law yet

On 6 January 2025 HHS published a proposed rule to strengthen the Security Rule — the first significant proposed update since the omnibus changes of 2013. A great deal of the marketing currently landing in practice inboxes is built on it: new mandatory encryption, new controls, deadlines.

It is still a proposal. As of 19 August 2026, no final rule has been published. A firm tracking the docket reported in July 2026 that HHS has moved the proposal to its long-term actions agenda, naming July 2027 as the anticipated timeframe for final action.

So the Security Rule you are actually held to is the existing one. That is not a reason to relax — the existing rule already requires the risk analysis, the written policies, the training and the business associate contracts this series has been walking through, and those are the ones with force behind them today. It is a reason to be suspicious of any urgency built on a requirement that has not been made.

How we checked, and where we came up short. federalregister.gov and ecfr.gov both answered requests from this machine with a redirect to an "unblock" interstitial, twice, so we could not read the register directly. The timeline above is therefore sourced to a firm tracking the docket rather than to the register itself, and it is linked below. The regulatory text quoted throughout this series comes from Cornell's Legal Information Institute, which reproduces the CFR. If any of it is load-bearing for a decision you are making, check it against the register yourself.

Two free things, and then we are done

One. Download the SRA Tool and do the vendor section. Roughly two hours, nothing leaves your computer, and you end up with a document you did not have.

Two. Write the list. Every tool that touches patient information, and beside each one, whether a business associate agreement exists. An hour, a blank page, no software.

If you do the second one and it comes out short and boring, that is the correct result. You have not wasted an hour. You have converted a thing you assumed into a thing you can show someone, and those are different objects.

What to do

Both of the above, this month, in that order. Neither involves buying anything.

They split cleanly if you are handing them out. The SRA Tool run is a two-hour job for whoever knows the systems. The tool list is a one-hour job for whoever knows the people. Ask for the two files back rather than a status update — in both cases the artifact is the result.

The reason to start this month rather than later is unglamorous. 164.316 wants documentation kept six years from creation or last effective date, whichever is later. A record you begin now is a record. One you begin the week after somebody asks for it is a reconstruction, and everyone in the room will be able to tell which is which.

Sources

Want this running in your own practice? Let's talk.