The short version
- The HIPAA Security Rule does not specify a frequency. It requires the analysis to be kept current, which OCR interprets as an ongoing obligation, not a one-time event.
- Annual has become the de facto standard, and MIPS makes it explicit: clinicians in the Promoting Interoperability category must conduct or review an analysis within each calendar-year performance period.
- Certain events require a fresh analysis regardless of when the last one was done: new systems, breaches, moves, mergers, new vendors, and significant staffing or workflow changes.
- A proposed update to the Security Rule would require review at least every twelve months. It is not yet final, but it signals where the standard is heading.
"How often do we have to do this?" is one of the most common questions in HIPAA compliance, and the honest answer frustrates people: the rule does not say. That frustration is understandable. It is also the reason so many organizations have a risk analysis from 2019 and nothing since.
What the rule actually says
The risk analysis requirement at 45 CFR 164.308(a)(1)(ii)(A) says nothing about frequency. It requires an accurate and thorough assessment. Elsewhere, the Security Rule requires at 164.308(a)(8) that organizations "perform a periodic technical and nontechnical evaluation" in response to environmental or operational changes. And the general documentation rules at 164.316(b)(2)(iii) require that documentation be reviewed periodically and updated as needed.
"Periodic" and "as needed" are the operative words. HHS chose flexibility deliberately, reasoning that a small practice and a large health system face different environments and should not be held to a single schedule.
OCR's guidance fills in the intent. The risk analysis is described as an ongoing process, not a one-time exercise. Organizations are expected to update it when their environment changes and to review it regularly enough that it remains accurate. An analysis that no longer describes the organization is, by definition, not accurate, and therefore no longer satisfies the rule.
Why annual became the standard
In the absence of a stated frequency, the industry settled on annual, for several converging reasons.
MIPS requires it. Clinicians reporting the Promoting Interoperability category must attest each year that they conducted or reviewed a security risk analysis within the calendar year of the performance period. For any practice participating in MIPS, annual is not a best practice. It is the rule, and for 2026 the attestation also requires confirming that risk management activities were conducted.
OCR expects it in practice. While OCR has not published a number, the pattern in enforcement is clear. Organizations whose most recent analysis is several years old are treated as having failed the requirement. An annual cadence is the interval OCR investigators appear to regard as reasonable.
Environments change faster than that. In a typical year, a practice adds or replaces software, changes staff, adopts a new vendor, shifts some work remote, or experiences at least one security incident. Any one of those alters the risk picture. A year is roughly the longest interval over which an analysis is likely to remain approximately true.
Cyber insurers ask for it. Most cyber liability applications now ask when the last risk assessment was performed. An answer older than a year affects premiums and, in some cases, eligibility.
Events that require a fresh look
Annual is the floor, not the ceiling. Certain events change the risk landscape enough that waiting for the next scheduled review is not defensible. When any of these happens, the analysis should be revisited, at minimum for the affected areas:
- A new system or a major upgrade. A new EHR, a new practice management platform, a migration to the cloud. CMS guidance for MIPS states this directly: an analysis must be done upon installation or upgrade of a new system.
- A security incident or breach. Whether or not it triggered notification obligations, an incident is evidence that the prior analysis missed something. Understanding what, and whether the same gap exists elsewhere, is the point.
- A new business associate or cloud service. Every vendor that touches ePHI is a new pathway for it to leave your control. Each should be assessed when onboarded.
- An office move, expansion, or new location. Physical safeguards change entirely. Network topology usually does too.
- A merger, acquisition, or practice affiliation. Two risk profiles become one, and the combined environment has never been analyzed.
- A significant shift in how work happens. The move to remote work in 2020 is the obvious example. Telehealth adoption, a new patient portal, or allowing personal devices all qualify.
- Departure of key IT or compliance staff. Institutional knowledge leaves with them. What remains documented may not match what was actually being done.
- A regulatory change. New requirements shift what "reasonable and appropriate" means.
A practical approach. Conduct a full analysis annually. In between, maintain a simple log of changes to systems, vendors, locations, and staff. When something on the trigger list occurs, do a focused review of the affected areas and document it as an update to the standing analysis. This keeps the analysis current without requiring a full effort every time something changes, and it produces exactly the kind of evidence of ongoing attention that OCR wants to see.
Full analysis or review?
MIPS guidance draws a distinction worth understanding: an analysis must be conducted when a system is installed or upgraded, and a review covering each performance period is otherwise acceptable.
A review is not a lighter version of the same thing. It is a documented examination of the existing analysis against the current environment: what has changed, whether the prior findings still hold, whether any new risks have emerged, and whether the remediation plan has progressed. If the environment is genuinely stable, a review may conclude that the prior analysis remains valid, with a signed and dated record saying so.
What a review is not is a new date on an old document. If nobody examined anything, no review took place, and the attestation that follows is not truthful.
What the proposed rule would change
In January 2025, HHS proposed the first major revision to the Security Rule since 2013. Among many changes, the proposal would require organizations to review and update the risk analysis at least once every twelve months, and more often in response to changes. It would also require a written technology asset inventory and network map, reviewed on the same schedule.
As of this writing the rule remains proposed, not final. Its details may change. But the direction is clear: the flexibility that let organizations interpret "periodic" generously is likely to narrow to an explicit annual minimum. Organizations already on an annual cycle will need to adjust little. Those that have let years pass will find the gap harder to close later than now.
If it has been a while
If your most recent risk analysis is more than a year old, or if you cannot locate it, or if it predates a significant change to your environment, the practical answer to "how often" is: now. The requirement is ongoing, the working standard is annual, and the cost of an outdated analysis shows up at exactly the moment you most need it to hold up.
