The short version
- Beginning with the 2026 performance year, MIPS clinicians must attest "yes" to two things: that they conducted or reviewed a Security Risk Analysis, and that they conducted risk management activities under the HIPAA Security Rule.
- The measure is worth zero points on its own. But failing it means zero for the whole Promoting Interoperability category, which is 25 percent of your MIPS score.
- The analysis must be performed within the calendar year of the performance period, must be unique to that year, and must cover every certified EHR system you use to report.
- The proposed overhaul of the HIPAA Security Rule is still proposed. It is not in force. Anyone telling you otherwise is either mistaken or selling urgency.
- If you have not completed your 2026 analysis yet, you have until December 31. That is enough time if you start now.
Every year around this time, practice managers start asking the same question we first heard during the Meaningful Use program more than a decade ago: who actually does the security risk analysis? The question has not changed. The answer has gotten more consequential.
This article explains what the MIPS Security Risk Analysis measure requires for 2026, what changed from prior years, what a CMS auditor would want to see if your attestation were selected for review, and the handful of mistakes that account for most of the trouble practices get into.
Where the SRA fits in MIPS
MIPS scores are built from four performance categories. Quality and Cost are each 30 percent. Improvement Activities is 15 percent. Promoting Interoperability, the category that grew out of Meaningful Use, is 25 percent.
Within Promoting Interoperability, the Security Risk Analysis is what CMS calls an unscored measure. Completing it earns you no points. But it is a required measure, and here is the part that matters: if you fail to complete it, or cannot attest to it truthfully, CMS assigns a score of zero for the entire Promoting Interoperability category, regardless of how well you performed on every other measure in it.
Put differently, the SRA is not a way to gain 25 percent of your score. It is the way to avoid losing 25 percent of it.
What changed for 2026
Through the 2025 performance year, the attestation was a single statement: you conducted or reviewed a security risk analysis in accordance with 45 CFR 164.308(a)(1), including addressing the encryption of ePHI, and you implemented security updates and corrected identified deficiencies.
For 2026, CMS split that into two separate attestations, each requiring its own "yes":
- You conducted or reviewed a security risk analysis in accordance with the requirements at 45 CFR 164.308(a)(1)(ii)(A), the HIPAA Security Rule's risk analysis implementation specification.
- You conducted security risk management activities in accordance with 45 CFR 164.308(a)(1)(ii)(B), the Security Rule's risk management implementation specification.
The second attestation is new. It is worth pausing on why CMS added it.
For years, a common pattern was to conduct an analysis, produce a report listing risks, file the report, and attest. The risks themselves were never addressed. The report became a compliance artifact rather than a management tool. Risk management, meaning the work of deciding what to do about each identified risk and then doing it, has always been required under HIPAA. CMS is now asking clinicians to state explicitly that they did it.
What "risk management activities" means in practice. You reviewed each risk the analysis identified. You decided, for each one, whether to remediate it, reduce it, transfer it, or accept it, and you documented that decision along with the reasoning. For risks you chose to address, you have a plan with owners and dates, and you can show progress against it. That is the standard. A report sitting in a folder does not meet it.
Timing, scope, and the details that trip people up
The measure specification is precise about several things that practices frequently get wrong.
It has to happen within the calendar year
The analysis must be conducted or reviewed during the calendar year of the performance period. For 2026, that means between January 1 and December 31, 2026. An analysis completed in November 2025 does not satisfy the 2026 requirement, no matter how thorough it was.
It has to be unique to the performance period
You cannot reuse last year's analysis by changing the date. Each performance year needs its own analysis or documented review. If little has changed in your environment, a review may be appropriate, but it must be a real review, with evidence that someone examined the current state and confirmed or updated the prior findings.
Its scope has to cover the full performance period
If your Promoting Interoperability reporting period runs for the required minimum of 180 continuous days, the analysis must account for your environment across that entire span. An analysis scoped narrowly to a single system or a single point in time will not hold up.
It has to cover every certified EHR you report on
CMS states plainly that the analysis should be completed for each certified EHR technology used to report the Promoting Interoperability measures. A practice running two systems needs both in scope.
It has to cover all ePHI, not just the EHR
This is the most common misunderstanding. The HIPAA requirement covers all electronic protected health information your organization creates, receives, maintains, or transmits. That includes the EHR, but also billing systems, email, file shares, backups, laptops, mobile devices, scanners with hard drives, cloud services, and anything else where patient information lives. An analysis that looks only at the EHR is incomplete by definition.
What a CMS auditor actually looks for
CMS conducts data validation and audits of MIPS submissions, and attestations can be selected for review. If yours is, you will be asked to produce documentation supporting the "yes" you submitted. In our experience, the reviewer is looking for a specific set of things:
| They want to see | Why it matters |
|---|---|
| A dated report | Proves the analysis falls within the performance year and was not recycled |
| A defined scope | Shows what systems, locations, and data flows were examined, and that certified EHRs were included |
| An inventory of where ePHI lives | Demonstrates the analysis considered all ePHI, not just the EHR |
| Identified threats and vulnerabilities | The substance of the analysis. Generic lists copied from a template are a red flag |
| Risk ratings with rationale | Shows you assessed likelihood and impact rather than just listing findings |
| A risk management plan | The new 2026 attestation. Decisions, owners, timelines, and status for each risk |
| Evidence of action | Policies updated, controls implemented, tickets closed. Proof the plan was executed, not just written |
| Who did the work | Names and roles of the people who conducted the analysis and who approved the risk decisions |
Notice what is not on that list. The auditor does not need a perfect score. Organizations with identified, documented, actively managed risks pass audits routinely. What fails is the absence of documentation, or documentation that does not match the attestation.
Five mistakes that account for most of the trouble
1. Assuming the EHR vendor does it for you
Your EHR vendor secures their product. They do not analyze your practice. They have no visibility into your network, your workstations, your staff's habits, your backup process, or the fifteen other places ePHI ends up. Vendor security documentation is useful input to your analysis. It is not a substitute for it, and no vendor will attest to MIPS on your behalf.
2. Treating a vulnerability scan as an analysis
A scan tells you which systems have known technical weaknesses. That is one input among many. It says nothing about administrative safeguards, workforce training, physical security, business associate oversight, or contingency planning, all of which the Security Rule requires you to assess. A scan report alone is not a risk analysis and will not survive audit as one.
3. Using a checklist tool without doing the thinking
The HHS Security Risk Assessment Tool is a legitimate, free resource, and small practices use it successfully. But it produces a defensible result only when someone with real knowledge of your environment answers its questions honestly and follows through on what it surfaces. Filling it out quickly to generate a report is exactly the pattern the 2026 risk management attestation was designed to catch.
4. Finishing the report and stopping
The analysis identifies risks. Risk management does something about them. Until 2026, practices could technically complete the first and neglect the second while still attesting. That door is now closed. If your risk register from last year has the same open items on it as the year before, you have a problem to fix before you attest.
5. Waiting for the HIPAA Security Rule changes to be finalized
You have likely read that the HIPAA Security Rule is being overhauled: mandatory encryption, mandatory multi-factor authentication, annual penetration testing, and more. That is a real proposal. HHS published it in January 2025. As of this writing, it remains a proposed rule. A final rule was expected in May 2026 and did not arrive on schedule. Nothing in it is currently enforceable, and its final form may differ from the proposal.
Two things follow. First, be skeptical of anyone who tells you the new requirements are already in effect. Several compliance vendors have published material that blurs this line, and it is not accurate. Second, do not use the pending rule as a reason to delay. The current Security Rule already requires a risk analysis and risk management, MIPS already requires you to attest to both, and every control in the proposed rule is a reasonable thing to be evaluating in your analysis today. Preparing for the direction of travel costs nothing extra. Waiting costs you the 2026 performance year.
A word on SAFER Guides
Separate from the SRA, the Promoting Interoperability category also requires an annual self-assessment using the SAFER Guides, specifically the High Priority Practices guide. For 2026, CMS requires the updated 2025 edition. This is a distinct measure with its own attestation. Some practices conflate the two because both involve assessing safety and security. They are not the same requirement and one does not satisfy the other.
If you have not done your 2026 analysis yet
It is September. You have roughly four months. That is enough time to do this properly if you begin now, and it is worth doing properly because the alternative is a 25 percent hole in your MIPS score that no other measure can fill.
A reasonable sequence:
- Inventory where ePHI lives. Not just the EHR. Everything.
- Identify the threats and vulnerabilities that apply to each location, and rate them for likelihood and impact.
- Decide what to do about each risk, document the decision and the reasoning, and assign owners and dates to the ones you are addressing.
- Start executing. You do not need every item closed by December 31, but you need evidence that the plan is real and in motion.
- Package the documentation so that if an auditor asks in eighteen months, you can hand it over without scrambling.
Whether you do this internally, with the HHS tool, or with outside help depends on your staffing and how complex your environment is. All three can produce a defensible result. What does not produce one is a report generated in an afternoon with no follow-through, and that is the thing the 2026 changes are specifically designed to expose.
