HIPAA risk analysis template: find where rider data could leak, then fix it
A HIPAA risk assessment template gives you a fill-in record of the Security Rule's required risk analysis. You list every place rider data lives, such as driver phones, dispatch software, email, broker portals, and paper manifests, then name the realistic threats at each, note the safeguards already in place, score likelihood and impact, and turn the worst scores into a dated fix list with owners. Keep it six years.
On this page
What the Security Rule asks for
The requirement is one sentence. A covered entity or business associate must “conduct an accurate and thorough assessment” covering potential risks and weaknesses that could affect the confidentiality, integrity, or availability of the electronic protected health information it holds (45 CFR 164.308). The next line requires risk management: safeguards that bring those risks down to a reasonable and appropriate level. Both are marked Required, and they open the rule’s list of administrative safeguards.
HHS says there is no single method or best practice that guarantees compliance, and the rule sets no format. Its guidance does name what every risk analysis must cover, whatever the method:
- Scope: all electronic rider data, on every device and system, wherever it is.
- Data gathering: where the data is stored, received, and sent, written down.
- Threats and weaknesses: the realistic ones, written down.
- Current safeguards: what is in place, and whether it is set up and used correctly.
- Likelihood and impact: for each threat and weakness pair.
- Risk level: assigned to each pair, with a corrective action for each.
- Review: kept current as things change.
You choose safeguards with your size, technical setup, costs, and the likelihood and severity of each risk in mind (45 CFR 164.306). A three-van company will not buy what a hospital buys, but it still has to show its reasoning. Our guide to HIPAA for NEMT providers explains which transportation companies HIPAA covers directly and which work under it as business associates.
The template
Part A: Where rider data lives
Follow one trip from the booking call to the paid invoice and write down every place rider details land. Include home offices and anyone who dispatches remotely.
| Place or system | Rider data it holds | Who can reach it | Company device, personal device, vendor, or paper | Business associate agreement on file (vendors) |
|---|---|---|---|---|
| Driver phones and tablets | ||||
| Dispatch and scheduling software | ||||
| Broker portals and downloaded trip files | ||||
| Email inboxes (shared and personal) | ||||
| Text messages and messaging apps | ||||
| Office and home computers | ||||
| Shared drives and cloud storage | ||||
| Phone system, voicemail, call recordings | ||||
| Fax | ||||
| Printed manifests, trip sheets, signature logs | ||||
| Billing files and payer portals | ||||
| Backups | ||||
| Accounts of former staff | ||||
| Old phones, laptops, and paper waiting for disposal |
Part B: Risk register
One row per threat at a location. The first rows are examples; replace them with your own.
| No. | Place (from Part A) | Threat (what might happen) | Gap that makes it possible | Safeguards in place now | Likelihood (1 to 3) | Impact (1 to 3) | Score | Level |
|---|---|---|---|---|---|---|---|---|
| Example 1 | Driver phones | Phone lost with the day’s manifest open | No screen lock on personal phones | None | 3 | 2 | 6 | High |
| Example 2 | Dispatch software | Former driver still signs in | No checklist for ending access | Unique logins | 2 | 2 | 4 | Moderate |
| Example 3 | Printed manifests | Manifest left on a dashboard at a clinic | Paper is the backup plan | Drivers told to keep it face down | 2 | 1 | 2 | Low |
| Example 4 | Office computers | Ransomware locks the schedule and billing files | Backups on a drive that stays plugged in | Antivirus | 2 | 3 | 6 | High |
Scoring key
Any consistent method works. HHS gives averaging likelihood and impact as one example; this template multiplies them, which spreads the scores out more.
| Score | Likelihood | Impact |
|---|---|---|
| 1 | Unlikely within 12 months | A few records, little chance of harm, no disruption |
| 2 | Possible within 12 months | Many records, or sensitive details such as diagnoses or dialysis schedules, or a day of disruption |
| 3 | Likely within 12 months, or it has already happened here | Most of the company’s rider records, or service stops for days |
Levels: 1 to 2 is Low, 3 to 4 is Moderate, 6 to 9 is High. Fix High rows first.
Part C: Fix list
This is the risk management plan. Every Moderate and High row gets a line.
| Risk no. | Fix | Owner | Due date | Date done | Proof (policy, setting, training roster, signed agreement) |
|---|---|---|---|---|---|
Part D: Sign-off
| Item | Entry |
|---|---|
| Date completed | |
| Covers every location, including home offices and vans (yes or no) | |
| People who took part (owner, dispatcher, lead driver, biller) | |
| Security official responsible for the fixes | |
| Next scheduled review | |
| Reviews triggered by a change since the last version (describe) |
Filling it in
- Walk the day with the people who do it. HHS lists interviews and document reviews as ways to gather the data. A dispatcher and a driver will name places the owner forgets, such as a personal texting app or a notebook in the glovebox.
- Name threats and weaknesses separately. HHS borrows its definitions from NIST: a weakness is a flaw in procedures, design, or controls, and a threat is the chance that someone or something triggers it. A lost phone is the threat; no screen lock is the weakness.
- Check safeguards honestly. A policy nobody follows is not a safeguard. HHS asks whether each measure is set up and used properly.
- Score, then rank. Put likelihood and impact on every row, not only the ones that worry you.
- Turn the ranking into Part C. Every fix gets one owner and a due date. The HHS tool’s remediation report uses the same fields.
- Sign, date, and file it. Keep Security Rule documents for six years, counted from when each was written or last in effect, whichever comes later (45 CFR 164.316).
Risks to look at first in a transport company
Phones. Rider names, addresses, and appointment details sit on driver phones all day. NIST’s mobile device guide describes an automatic lock after a short idle period (its examples are 45 seconds and 5 minutes) and remote lock and wipe for lost devices. It also warns that remote wipe alone is “a fundamentally unreliable security control,” because a thief can read the device or switch it off before the wipe arrives. Texting rider details has its own risks, covered in our guide to HIPAA and texting.
Logins. A shared dispatch password is a finding on its own, since the rule calls for a unique name or number to identify every user (45 CFR 164.312). So is a login that outlives the job: procedures for ending access when someone leaves are part of the rule’s workforce security standard. Regular review of activity records, such as audit logs and access reports, is required too.
Laptops and encryption. Encryption is addressable, which means you adopt it or document why an equivalent measure is reasonable. In 2019, West Georgia Ambulance, a Georgia emergency and non-emergency ambulance company, paid the HHS Office for Civil Rights $65,000 and took on two years of monitoring. The case began with a breach report about a lost unencrypted laptop holding records of 500 people. The investigation found no risk analysis, no security awareness training, and no Security Rule policies.
Ransomware. Comstar, a Massachusetts company that handles billing and collection for emergency ambulance services, paid $75,000 in 2025 under a two-year corrective action plan. An intruder reached its servers on March 19, 2022, went unnoticed until March 26, and ransomware affected about 585,621 people. OCR found Comstar had not done an accurate and thorough risk analysis. Our NEMT cybersecurity guide covers backups and account protection.
Paper. Covered entities must reasonably safeguard protected health information in every form, and limit incidental disclosures (45 CFR 164.530). Manifests on dashboards and signature logs on clipboards belong in Part B.
Keeping it current
Today’s rule sets no schedule. HHS describes the process as ongoing and mentions yearly and as-needed cycles, with every three years as one example. It also names events that call for a fresh look: a security incident, a change in ownership, turnover in key staff or management, and new technology. Put a yearly review on your compliance calendar and add a review whenever one of those happens.
A yearly review may become mandatory. HHS’s January 6, 2025 proposal to update the Security Rule would require a written risk assessment reviewed at least every 12 months, a written technology asset inventory and network map, and multi-factor authentication. Through September 30, 2026 only the proposal has appeared in the Federal Register, and the most recent federal regulatory agenda puts final action at July 2027.
If a risk turns into a breach of unsecured data, the clock starts. Affected people must be told without unreasonable delay, within 60 calendar days of discovery. Smaller breaches, under 500 people, are logged and sent to HHS once a year, within 60 days after the year closes (45 CFR 164.408).
For a guided version of the same exercise, HealthIT.gov offers the Security Risk Assessment Tool, version 3.7, as a Windows program or an Excel workbook. Version 3.7 added a question confirming the assessment covers every location that handles rider data and another on remote access and telework, and its risk report sorts findings into Low, Moderate, High, and Critical.
Rider data in HealthRide
If HealthRide is one of the systems in Part A, several safeguards come built in. HealthRide is HIPAA compliant: each person on your team sees only what their role allows, sign-ins can use passkeys or two-step codes, and every change is recorded. Rider details never show on the lock screen in the driver app, and HealthRide signs business associate agreements with its providers.
Frequently asked questions
- Is a HIPAA risk analysis required for a small transportation company?
- Yes, when the company holds rider data electronically and HIPAA applies to it, either as a covered entity or as a business associate. The Security Rule lists risk analysis as a required implementation specification for both. Size changes how much work it takes, not whether it is needed: the rule lets you weigh your size, technical setup, and costs when choosing safeguards, and HHS notes that small organizations have fewer people and systems to account for.
- How often does the risk analysis have to be updated?
- The rule in force today names no interval. HHS guidance calls the process ongoing and notes that frequency varies, from yearly to as needed, with every three years given as one example. It also calls for a new look after a security incident, a change of ownership, key staff leaving, or new technology coming in. A proposed rule from January 2025 would require a review at least every 12 months; by September 30, 2026 no final version had been published.
- Does HHS offer a tool for doing the assessment?
- Yes. HealthIT.gov offers the Security Risk Assessment Tool, version 3.7, as a Windows program and as an Excel workbook with the same questions. Its intended users are small and medium providers, your answers stay on your own computer, and it produces a risk report and a remediation report. HealthIT.gov notes that the tool is optional and that using it does not by itself make you compliant.
- Do paper manifests belong in a Security Rule risk analysis?
- The Security Rule covers electronic data only. Paper falls under the Privacy Rule, which tells covered entities to take reasonable safeguards for protected health information whatever its form, so printed manifests, trip sheets, and signature logs count. Reviewing paper in the same pass is simpler than running two exercises, so this template includes it.
- How is a risk analysis different from a gap analysis?
- A gap analysis ticks off which required safeguards are in place. A risk analysis starts from the data instead: where it sits, what could realistically happen to it, how likely and how damaging each event would be, and which fixes come first. The HHS Office for Civil Rights has said a gap analysis of that kind may not satisfy the risk analysis requirement, because it does not assess the risks to all of the electronic data you hold.
- How long must the risk analysis be kept?
- Six years, counted from whichever date is later: the day you wrote it or the last day it was in effect. That rule covers every document the Security Rule requires, including the fix list and the policies that came out of it. Keep earlier versions too, because they show the work was done each time.