Back to Intelligence

HHS Releases SRA Tool v3.7: How Healthcare Organizations Should Operationalize the Updated Security Risk Assessment in 2026

SA
Security Arsenal Team
September 12, 2026
8 min read

The U.S. Department of Health and Human Services (HHS), through the Office for Civil Rights (OCR) and the Office of the National Coordinator for Health IT (ONC), has released version 3.7 of the Security Risk Assessment (SRA) Tool. The tool is a free, downloadable Windows-based application designed to help small and medium-sized healthcare providers and business associates conduct the security risk analysis required under the HIPAA Security Rule (45 C.F.R. §§ 164.308(a)(1)(ii)(A)–(B)).

Version 3.7 continues the iterative refinement of a tool that HHS co-developed to lower the barrier for organizations that lack the staff or budget for a formal enterprise risk assessment engagement. For defenders and compliance leads, this release lands at a pivotal moment: OCR has made risk analysis failures the single most-cited violation in its enforcement actions for over a decade, and the December 2024 Notice of Proposed Rulemaking (NPRM) to update the HIPAA Security Rule would make written, asset-inventoried, technically tested risk analyses a hard requirement rather than an addressable one.

If you are a covered entity or business associate and your last documented risk analysis is more than 12 months old — or worse, doesn't exist — this update is your cue to close that gap now, not after an OCR investigation or a ransomware event forces the issue.

Why This Matters to Defenders

A security risk analysis is not paperwork. It is the diagnostic step that determines where your electronic protected health information (ePHI) actually lives, what can reach it, and what breaks first under stress. In my IR work, I have never walked into a healthcare ransomware engagement where the organization had a current, honest risk analysis on file and was surprised by the attack path. The path was always already visible — it was just never written down, and therefore never remediated.

OCR's enforcement record reinforces this:

  • Risk analysis failures have been a factor in the overwhelming majority of OCR's six- and seven-figure resolution agreements, including cases arising from phishing compromises, stolen laptops, and ransomware encryption of ePHI.
  • Following the 2024 Change Healthcare ransomware incident — one of the largest healthcare breaches in U.S. history — OCR explicitly reminded the sector that a thorough, accurate, and current risk analysis is the foundational obligation under the Security Rule.
  • The pending Security Rule NPRM proposes eliminating the "addressable" flexibility, mandating asset inventories, network mapping, and annual technical testing — all of which start with the exact workflow the SRA Tool structures.

Version 3.7 of the SRA Tool matters because it removes the two most common excuses we hear: "we don't have the budget for a consultant" and "we don't know where to start."

Technical Analysis: What the SRA Tool Does

The SRA Tool is a self-contained desktop application (Windows, with a printable report workflow) that walks an organization through a structured questionnaire aligned to the HIPAA Security Rule's administrative, physical, and technical safeguard standards. Key functional characteristics:

  • Scope: It systematically covers each Security Rule standard and implementation specification — security management processes, workforce security, information access management, security awareness and training, evaluation, access controls, audit controls, integrity, authentication, and transmission security.
  • Methodology: For each area, the assessor identifies threats and vulnerabilities, rates the likelihood of exploitation and the potential impact, and documents current controls. The tool aggregates these into a risk register with prioritized remediation areas.
  • Output: It produces a documented risk analysis report — the artifact OCR requests first in any data request letter following a breach report or complaint.
  • Target audience: Small and medium providers and business associates. Larger health systems should treat it as a baseline, not a substitute for an enterprise assessment against NIST SP 800-30 or NIST CSF 2.0.

Version 3.7 is an incremental maintenance release of the v3.x line. Organizations running earlier versions should download the current release from the official HHS/ONC page and re-baseline their assessment, since questionnaire refinements and content corrections accumulate across point releases.

Exploitation status caveat: Unlike the vulnerability disclosures we typically cover, there is no CVE or exploit chain here — the "threat" is the unassessed attack surface itself. In 2025 and into 2026, healthcare remains one of the most-targeted sectors for ransomware, with groups continuing to exploit exactly the control gaps a proper risk analysis surfaces: unmanaged internet-facing assets, flat networks, unpatched VPN and remote access appliances, weak MFA coverage on email and EHR portals, and third-party/business-associate pathways. The SRA Tool exists to find those gaps before an adversary does.

Executive Takeaways

This is a compliance tooling update rather than a technical threat, so instead of detection rules, here are the actions that matter:

  1. Download SRA Tool v3.7 from the official HHS source and re-baseline. If your last risk analysis predates this version (or is older than 12 months), schedule a full refresh now. Version drift matters — document which tool version you used, and retain the prior analysis as evidence of continuous process.

  2. Treat the risk analysis as an annual, living process — not a one-time checkbox. OCR expects the analysis to be updated when you adopt new technology, open new facilities, add business associates, or experience security incidents. Build the refresh into your compliance calendar and assign a named owner.

  3. Don't stop at the questionnaire. The SRA Tool structures your thinking, but it cannot validate technical controls. Pair it with hands-on verification: external attack surface scanning, MFA coverage auditing on email/EHR/remote access, EDR deployment validation, backup restoration testing, and a review of business associate agreements and their security posture.

  4. Prepare for the post-NPRM Security Rule. The proposed rule would require a written asset inventory, a network map of ePHI flows, annual vulnerability scanning and penetration testing, and 72-hour restoration capabilities. Start building these artifacts now — the organizations that will struggle after finalization are the ones treating the current rule as static.

  5. Escalate findings into a funded remediation plan. A risk analysis with no risk management plan is, in OCR's eyes, worse than none — it proves you knew about the gap and did nothing. Every identified high-risk item should have an owner, a target date, and either a fix or a documented, leadership-accepted risk decision.

  6. If you lack internal capacity, bring in help before an incident — not after. A third-party assessment against NIST CSF 2.0 or the HIPAA Security Rule, combined with tabletop IR exercises, costs a fraction of a single breach response. For organizations holding ePHI at scale, this is not optional economics.

Remediation

Concrete steps for this week:

  • Obtain the tool: Download SRA Tool v3.7 only from the official HHS/ONC distribution page (healthit.gov — navigate to the Security Risk Assessment Tool). Verify the download source; never install "SRA tools" from third-party download sites.
  • Scope your assessment: Identify every system that creates, receives, maintains, or transmits ePHI — EHR, PACS/imaging, billing, patient portals, email, file shares, cloud SaaS, and medical devices. Document business associates who touch ePHI and confirm current BAAs are in place.
  • Complete the assessment honestly: Answer for the environment you actually have, not the one your policies describe. Inflate nothing. The tool's risk output is only as good as the inputs.
  • Generate and file the report: Produce the documented risk analysis, have leadership sign off, and retain it with your HIPAA documentation. This is the first document OCR will request.
  • Convert findings to a remediation backlog: Prioritize by risk score. For most healthcare environments, the top items are consistently: MFA everywhere (especially email and remote access), patching of internet-facing systems, network segmentation between clinical and administrative zones, EDR on all endpoints, and tested offline/immutable backups.
  • Track regulatory movement: Monitor the HIPAA Security Rule NPRM status at regulations.gov and OCR guidance at hhs.gov/hipaa. Adjust your compliance program roadmap so you are not rebuilding from scratch when the final rule lands.

The Bottom Line

The SRA Tool v3.7 release is a small software update carrying a large message: HHS continues to invest in making HIPAA risk analysis accessible, which means OCR will continue to be unforgiving when organizations skip it. In a sector where ransomware operators are monetizing ePHI at industrial scale, an undocumented attack surface is an unmanaged one. Download the tool, run the assessment, fund the fixes — and do it before the regulator or the adversary does the scoping for you.

Related Resources

Security Arsenal Healthcare Cybersecurity AlertMonitor Platform Book a SOC Assessment healthcare Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.