healthit.gov HHS Releases Updated Security Risk Assessment Tool for HIPAA Compliance
Article Content
- •HHS released version 3.7 of the SRA Tool on September 11, 2026.
- •The tool helps small and medium-sized healthcare entities comply with HIPAA Security Rule requirements.
- •New features include updated questions on remote access and a modernized asset inventory.
The U.S. Department of Health and Human Services (HHS) has launched version 3.7 of the Security Risk Assessment (SRA) Tool, designed to assist small and medium-sized healthcare entities in conducting risk assessments as mandated by the HIPAA Security Rule. This update includes enhancements to usability and content, addressing evolving cybersecurity threats. Key features of the new version include new questions regarding remote access, telework, and a modernized asset inventory. The tool aims to help organizations identify vulnerabilities to electronic protected health information (ePHI) and ensure compliance with HIPAA regulations. The SRA Tool is available for download and is intended primarily for smaller healthcare providers, as larger organizations may require more comprehensive solutions. The updates reflect ongoing feedback and aim to improve the overall effectiveness of risk assessments. The tool has been in use since its initial release in 2014 and has undergone several upgrades to maintain relevance in the changing cybersecurity landscape.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…