The full risk register with scoring methodology, treatment decisions, owners, dates, and accepted-risk rationales.
Primary audience: Auditors and assessors
The risk analysis is the foundation the entire Security Rule builds on — it is the first thing OCR asks for in an investigation, and “insufficient risk analysis” is among the most common findings in enforcement history. But a risk analysis is only as credible as the register behind it. This export is that register, complete and unedited: every identified risk, how it was scored, what was decided about it, who owns it, and — critically — the written rationale for every risk the organisation chose to accept.
What is inside
The export shares the standard SuperHIPAA report spine:
- Scope statement: entities, systems, and ePHI flows covered
- Assessment date and methodology
- Findings with rule citation, risk rating, and recommendation
- Prioritised remediation plan with effort estimates
- Evidence appendix listing what was reviewed
- Shareable summary version with finding detail suppressed
Each register entry then carries the full record an assessor expects: the threat and vulnerability pairing, the assets and ePHI flows affected, likelihood and impact scores under the published methodology, the resulting rating, the treatment decision — mitigate, transfer, accept, or avoid — the named owner, target and review dates, and the history of how the entry has changed over time. The scoring methodology itself is printed in the export, so a reviewer can check that ratings follow the method rather than the politics.
Why accepted risks get their own spotlight
Accepting a risk is legitimate — HIPAA’s flexibility-of-approach provisions expect organisations to make reasonable, documented judgements, not to eliminate every risk regardless of cost. What is not legitimate is silent acceptance: a risk everyone knows about that appears nowhere, with no rationale and no owner. The export makes every acceptance explicit — what was accepted, by whom, on what reasoning, and when it will be reviewed. In front of an auditor, a documented acceptance is a defensible management decision; an undocumented one is negligence with better lighting. The difference between those two positions is exactly this document.
Who reads it, and for what
Auditors and external assessors treat the register as primary evidence that risk analysis is a living process. A register with owners, dates, and a visible change history reads as an operating discipline; a register last touched at the previous audit reads as theatre, and assessors can tell the difference in minutes.
Regulators. In an OCR inquiry, the risk analysis and its management are the first substantive requests. Being able to produce a dated, methodical register — including the accepted-risk rationales — materially changes the tone of that exchange.
Internal governance. The register is where the executive summary’s “top five risks” comes from; the two documents cite the same entries, so leadership and assessors are looking at one truth rather than two versions of it.
Insurers and enterprise customers, occasionally, for specific entries relevant to them — the export’s structure makes partial disclosure practical without handing over the whole register.
How it is produced
Generated from your live workspace, then reviewed and signed by a named healthcare compliance lead. It is not an automated export with a logo on it, and it is not a consultant’s Word document disconnected from your data. It is both: the data is live, the judgement is human.
Review matters here because a register invites quiet gaming — scores nudged down, awkward risks worded into vagueness. The signing reviewer checks that scores follow the methodology and that treatment decisions have real rationales attached, so the document holds up when someone hostile reads it.
Refresh cadence
Point-in-time reports carry a date and a validity note. Most customers refresh annually, or ahead of a major procurement cycle, funding round, or insurance renewal.
The register itself is maintained continuously in the workspace; the export is a snapshot for whoever needs it in document form. Exports are typically generated for audits, assessments, and formal reviews — and archived, because the sequence of dated exports is itself proof that risk management here is a practice, not an annual performance.
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.