
HIPAA Security Risk Assessment for Small Practices: What’s Required, What’s Optional, and What Evidence to Keep
A decision-oriented explainer on the HIPAA Security Rule risk analysis requirement for small healthcare and dental practices: which obligations are non-negotiable and where they are codified, how to scope an ePHI inventory that does not miss imaging or cloud systems, the six-year documentation retention rule at 45 CFR § 164.316(b)(2)(i), and how business associate agreements and vendor SOC 2 reports change the scope of your assessment without removing your own obligation.
