HIPAA Risk Analysis: AI Agent vs Consultant vs SRA Tool
What the Security Rule actually asks for
Under 45 CFR § 164.308(a)(1)(ii)(A), a covered entity must conduct “an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability” of electronic protected health information it creates, receives, maintains, or transmits. HHS Office for Civil Rights published dedicated Guidance on Risk Analysis Requirements under the HIPAA Security Rule, and NIST’s SP 800-66 Revision 2, Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide, walks through a workable method. Both are free; read the primary documents rather than a vendor’s summary of them.
Two things practices commonly get wrong. First, a vulnerability scan, a penetration test, or a checklist questionnaire is not a risk analysis — those are inputs. A risk analysis identifies where ePHI lives and flows, names threats and vulnerabilities against each, and rates likelihood and impact. Second, the rule doesn’t say “annually” in those words; OCR describes it as an ongoing process updated when your environment changes. Separately, CMS’s Quality Payment Program requires clinicians reporting Promoting Interoperability to attest that a security risk analysis was completed in the performance period — verify the current-year specification on the QPP site, because measure language changes.
The three realistic paths
The third path isn’t really a third option; it’s a layer. An AI assistant sits on top of either approach and absorbs the document work. That’s where the agentic angle gets interesting.
Where an AI agent does real work here
The unusual thing about this workflow: the raw material is mostly not patient data. Asset lists, vendor registers, policy documents, help-desk tickets, prior risk registers — sensitive, but generally not PHI. That removes the single biggest blocker that stops practices from using AI on clinical workflows, and it’s why this is one of the better first agentic projects for an office manager.
Start with the cheapest version. Uploading your inventory, BAA register, and policy set into a chat covered by a business associate agreement or equivalent enterprise data commitment — Claude’s enterprise tiers, another general assistant’s enterprise plan, or whatever your EHR or compliance platform already offers for document review — gets you most of the drafting benefit with no engineering at all. Plenty of practices should stop there.
The deeper version connects the assistant through MCP — the Model Context Protocol, an open standard for giving an AI governed access to specific systems and tools — so it reads live sources instead of stale uploads. A custom MCP server for this job might expose four read-only things:
-
Asset and device inventory
Pulled from your RMM or IT management tool: workstations, servers, phones, imaging devices, backup targets, plus where each sits and who administers it. -
Vendor and BAA register
Your contracts folder or spreadsheet of business associates, with BAA status and renewal dates. The agent’s first useful trick is flagging every system in the inventory that has no matching BAA. -
Policy library
Current written policies and procedures, so the agent can cite which policy addresses (or doesn’t address) each Security Rule standard. -
Last year's risk register and remediation tickets
So the analysis becomes an update, not a rewrite — and so “we said we’d fix this last year” items surface instead of quietly disappearing.
Be honest about what that costs. A four-source server means IT or contractor build time, API access from your RMM and document store (which some tools don’t expose on lower tiers), credential handling, and someone maintaining it when a vendor changes its API. If you run this process once a year, re-uploading files may simply be cheaper than owning software.
On top of either setup you define a skill — a reusable, packaged instruction set that makes the assistant do the job the same way every time. A “risk analysis prep” skill would specify the structure (threat source, vulnerability, existing control, likelihood, impact, risk level, remediation owner), the vocabulary from NIST SP 800-66 Rev. 2, the evidence it must cite for every finding, and an explicit rule that it never assigns a final risk rating — it proposes one and marks it for human confirmation. That last constraint is the difference between a useful draft and a document that will embarrass you in an investigation. The same skills-over-prompts logic applies across the practice; we’ve covered how practices should think about AI skills versus one-off prompts.
The agent’s job is to assemble the evidence and draft the language. The risk ratings and the signature belong to a human who can defend them.
Where it breaks
An AI assistant will happily produce a confident, well-formatted risk analysis about systems you don’t have, using controls you never implemented, because it inferred them from context. It does not know that the back-office printer stores scanned records on an internal drive, or that the hygienist logs into the PMS on a personal iPad.
The fix is a physical walkthrough plus ten-minute interviews with each role before the agent touches anything. Walk every room and note what’s plugged in, what screens face the waiting area, and what the copier/scanner retains. Ask each person: what device do you log in from, do you ever use a personal phone or home computer, what do you scan or fax, and what apps do you use that IT didn’t install. Type the answers into a plain document — that document becomes an agent input alongside the inventory, and it’s the piece that makes the draft describe your actual practice.
AI is also the wrong tool for pure reconciliation. Comparing this year’s asset list to last year’s is a spreadsheet diff; a deterministic script or your RMM’s own report is cheaper, faster, and won’t hallucinate. Our breakdown of when to use AI agents versus RPA versus plain rules applies directly.
And a caution people miss: a completed risk analysis is a detailed inventory of your weaknesses. Even with zero PHI in it, treat it as highly sensitive — keep it inside a BAA-covered platform, not a free consumer chat tier that may retain inputs, using the same vendor diligence we lay out in the HIPAA vendor checklist. Confirm your specific setup with your privacy officer or counsel.
Your AI tools are now part of the scope
If your practice adopted an AI scribe, an AI phone agent, or an inbox triage feature in the past year, each one is a new path for ePHI and belongs in this year’s analysis: what data it receives, where it’s stored, how long, whether a BAA is executed, who at the vendor can access it, and what happens on termination. Practices that bolted on three AI features and never updated their risk analysis have a documentation gap that is easy for an investigator to spot.
Modeling the cost without inventing numbers
Don’t trust any published ROI figure for this, including from consultants. Build your own:
A worked example with made-up placeholders, not a benchmark: assume the walkthrough, gathering, and drafting takes 16 hours of your office manager’s time at a $40 loaded hourly rate — that’s $640 of internal cost. Assume an AI-assisted pass shifts that to 6 hours of review at the same rate, or $240, plus whatever your covered platform costs per month. Substitute your own hours and rate; the point is that AI mainly converts writing-and-assembling hours into reviewing hours — usually fewer, but never zero — and those recovered hours only have value if they go back into revenue work or overdue remediation rather than evaporating.
Which practice roles this actually changes
Here’s our operating assumption, stated as opinion rather than finding: the tasks described above that AI absorbs most easily are the pure document-assembly ones — retyping inventories into a register template, restating policy language against each Security Rule standard, formatting remediation plans. What it doesn’t absorb is the walkthrough, the staff interviews, the risk rating, and the signature. So the roles that gain value are the ones carrying judgment and accountability: the privacy officer who can defend a rating, the office manager who knows how the office truly operates, the biller who knows which payer is behaving strangely this month.
You’ll also see various percentages floating around AI discussions about how much of a task automation takes. There’s no authoritative source behind any particular figure, and we’d treat specific numbers as marketing. The useful version is plain: assume partial automation, design for a human checkpoint, and measure your own before-and-after.
If you’re weighing this against a broader automation roadmap, our job-by-job buyer’s map for practice AI puts compliance work in context against front-office and revenue-cycle candidates. Compliance rarely wins on raw ROI — but it’s one of the few workflows where a mistake is measured in enforcement actions rather than rework.
Not sure where to start?
Get a free automation audit: we map your scheduling, intake, insurance, billing, and patient communication and show you what's worth automating — before you spend a dollar.
Get a free automation audit