
Ask a room of dentists what a HIPAA risk analysis is and you will get two answers: "something we did at some point" and "something we are quietly worried about." The worry is usually justified, but the task itself is smaller than it feels. A risk analysis is not a legal document written in an ancient dialect. It is a structured answer to three plain questions:
- Where does patient information live in our practice?
- What could go wrong with it?
- What are we doing about that, and is it enough?
That's it. The regulation (45 CFR 164.308(a)(1)(ii)(A), if you want to cite it at dinner) requires the analysis as the foundation of the Security Rule, and regulators treat its absence as the original sin of compliance failures: nearly every enforcement story in healthcare starts with a missing or stale risk analysis.
Here is a walkthrough of doing one for a small dental practice, in plain steps, sized for an office with one or two locations and no compliance department.
Key takeaways
- The risk analysis is a required, documented, repeatable process, not a one-time form. Expect to refresh it annually and after major changes.
- Small practices can complete a credible first-pass analysis themselves in a few focused sessions; specialized software is optional, documentation is not.
- The output that matters is the risk register: a prioritized list of risks with your decisions attached. Regulators and auditors want to see that you made decisions, not that you bought tools.
Step 1: Inventory where patient information lives
Walk the practice and write down every place electronic protected health information (ePHI) exists or passes through. For a typical dental office:
- The practice-management system (on a local server or in the cloud)
- The imaging software and its archive (often the largest ePHI store in the building)
- Workstations and what staff store locally, including the desktop habit
- Email (cloud or on-site mail) and text/patient-communication platforms
- Backup drives and services, on-site and off-site
- Phones and tablets used for clinical photos or patient contact
- Cloud services staff signed up for without telling anyone (shadow IT is small but real; ask about it kindly)
- Paper that gets scanned in later, and printed schedules sitting at the front desk
- Any vendor that touches those systems (they are business associates and belong on your list)
The inventory is the least glamorous step and the foundation of everything after it. An incomplete inventory is how risks get missed, because you cannot analyze the drive nobody remembered.
Step 2: Identify threats and vulnerabilities
For each item in the inventory, ask what could realistically happen. Keep it practical; you are a dental practice, not a national security agency. The honest short list:
- Loss of confidentiality: someone sees patient information who shouldn't. Weak passwords, shared logins, unlocked screens at the front desk, an email sent to the wrong address, a lost laptop or phone.
- Loss of integrity: information gets changed or corrupted, an imaging record mislabeled, a charting entry altered, ransomware (the extreme case, since encryption changes everything at once).
- Loss of availability: you cannot get to the information when needed. Server failure, internet outage with cloud-hosted software, ransomware again, a backup that turns out not to work.
Most small practices find that a handful of scenarios cover nearly everything: a stolen or misplaced device, a phishing compromise of an email account, ransomware, a failed backup, an insider mistake. Write them down against the inventory.
Step 3: Rate the risks
For each threat, assess two things:
- Likelihood: given how the practice actually operates, how plausible is this? (Be honest about the shared front-desk login.)
- Impact: if it happened, how bad? Scheduling downtime for an hour is one thing; a ransomware event that encrypts the imaging archive is another.
A simple High/Medium/Low scale is fully acceptable for a small practice. Sophisticated scoring models are not the requirement; a judgment you can defend is. HHS has free risk-assessment material to guide the process, and its Security Rule guidance is written to be usable by small providers.
Step 4: Decide and document
Here is the step that makes the whole exercise real. For each rated risk, you make one of three decisions:
- Implement a safeguard (add MFA to email, move backups off-network, enable screen locks)
- Accept the risk with a written reason (the cost of the safeguard genuinely outweighs the risk for your situation)
- Transfer or mitigate through a vendor, insurance, or a process change
Every decision gets written down with a date. This produces your risk register, the document regulators and your own future self actually want. A register that says "risk: shared front-desk login; decision: individual accounts, implemented March 2026" is compliance. A register that says nothing while the shared login persists is a finding waiting for its moment.
Step 5: Build the remediation plan and follow it
The risks you decided to fix get a plan: what, who, when. Keep it modest and real:
- 2 to 4 items per quarter, not 40 (an unachievable plan is a liability, because regulators and insurers ask about progress against the plan you wrote)
- Quick wins first: MFA, unique accounts, backup verification. These are cheap, fast, and they close the biggest doors.
- Revisit the whole analysis annually and after any significant change (new software, new location, new imaging hardware, a move to cloud hosting).
Step 6: Connect it to the rest of your compliance
The risk analysis is the foundation, but a few nearby pieces keep the building code satisfied:
- Business Associate Agreements for every vendor from Step 1 that touches ePHI. No BAA, no vendor.
- Policies and training: the decisions from your register become policies, and staff get trained on them once a year. A decision nobody knows about protects nobody.
- Contingency planning: your backup and outage procedures flow directly from the "availability" risks you rated.
Frequently Asked Questions
Does a small dental practice really need a formal HIPAA risk analysis?
Yes. The requirement applies to covered entities of every size, and it is the first thing regulators ask for after an incident. The good news is that "formal" means structured and documented, not expensive: a completed template with real decisions, reviewed annually, satisfies the obligation for a small practice far better than a glossy consultant binder nobody has opened since delivery.
How often should a dental practice update its risk analysis?
Review it annually at minimum, and after meaningful changes: new practice-management or imaging software, a new location, a move to cloud hosting, a security incident. Treat it like your clinical equipment inventory: living documentation that drifts out of date quietly.
What is the difference between a risk analysis and a security risk assessment?
In practice the terms are used interchangeably; the Security Rule's required "risk analysis" is often called a security risk assessment in vendor materials. What matters is the substance: a documented review of where ePHI lives, what threatens it, and what you decided to do, refreshed on a schedule.
Can we do the risk analysis ourselves or must we hire a consultant?
A small practice can complete a credible first-pass analysis internally in a few focused sessions, using HHS's free guidance. The case for outside help is a fresh set of eyes and documentation weight for insurers and auditors, not permission to begin. Doing it yourself this quarter beats hiring someone to do it someday.
Conclusion
A HIPAA risk analysis for a small dental practice is three questions, honestly answered and written down: where is patient information, what could go wrong, and what did we decide about it. Do it once properly, refresh it annually, and the quiet worry goes away, replaced by a document you can hand to an auditor, an insurer, or your own successor without flinching.
Our managed IT services include the technical side of the safeguards this walkthrough recommends (access controls, backup verification, patching, logging), and our HIPAA-focused article covers the IT solutions that support compliance end to end. The FAQ page collects the questions practice owners ask most.
Sources/References
- HHS, Guidance on Risk Analysis Requirements under the HIPAA Security Rule: https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis-requirements-hipaa-security-rule/index.html
- 45 CFR 164.308(a)(1)(ii)(A), Security Standards: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164
- HHS Office for Civil Rights, Security Rule Guidance Material: https://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html
- NIST, Security and Privacy Controls (SP 800-53) risk-management context: https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final


