Skip to content

Security Risk Analysis for MIPS

 

Learn about SRA for MIPS, what it must cover, SRA attestation, does completing the SRA add points to a MIPS score, deadline and much more, through the Frequently Asked Questions (FAQs) below. Please schedule a consultation if you are looking for a Security Risk Analysis (SRA) for MIPS or Expert Consultants to help you navigate the process. 

Table of Contents

What is the Security Risk Analysis (SRA), and why does MIPS require it? 

 

The Security Risk Analysis (SRA) is a systematic assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) within a clinical practice. Completing the SRA is a prerequisite for earning any score in the Promoting Interoperability category, it functions as a gate, not a scored measure. The SRA requirement is rooted in the HIPAA Security Rule (45 CFR 164.308(a)(1)), which independently mandates regular risk assessments for all covered entities. MIPS reinforces this HIPAA obligation by making attestation to the SRA a non-negotiable condition for PI category participation. 

 

What changed about the SRA attestation requirement for 2026? 

 

Beginning with the 2026 performance year, the SRA attestation requires two separate components rather than one. Previously, clinicians attested to conducting or reviewing the SRA and implementing security updates. For 2026, CMS finalized an additional attestation component: clinicians must now also separately attest that they conducted risk management activities in accordance with the HIPAA Security Rule, confirming that identified vulnerabilities were actively addressed, not merely logged. This second component was already an underlying HIPAA obligation under 45 CFR 164.308(a)(1), but it is now an explicit, standalone requirement within the MIPS PI attestation process. Failing to attest to both components results in a zero score for the entire Promoting Interoperability category. 

 

What must the Security Risk Analysis cover? 

 

The SRA must evaluate three broad domains of safeguards. Administrative safeguards include the policies, procedures, and staff training programs designed to prevent unauthorized access to patient data. Physical safeguards address the mechanisms protecting physical infrastructure, such as restricted access to server rooms, off-site backups, and visitor controls. Technical safeguards cover the automated protections built into systems, such as data encryption, secure authentication, network security, and workstation locking. Beyond these three domains, the SRA should extend across the full clinical environment: the EHR system, network infrastructure, cloud services, telehealth platforms, endpoints, medical devices, and any third-party vendors with access to ePHI.

 

When must the Security Risk Analysis be completed? 

 

The SRA must be completed or reviewed at least once per calendar year. For MIPS purposes, it must be conducted within the calendar year of the performance period, January 1 through December 31, and must be unique to that performance period, covering the full scope of that year. It is acceptable to conduct or review the SRA outside of the PI reporting window, provided it falls within the calendar year. Additionally, a new SRA must be performed whenever a practice installs or upgrades to a new EHR system or CEHRT, because system changes introduce new vulnerabilities to electronic protected health information. 

 

What happens if a practice does not complete the Security Risk Analysis? 

 

Failure to complete the SRA, or to attest to both required components when submitting MIPS data, automatically results in a score of zero for the entire Promoting Interoperability category, regardless of how well the clinician performed on any other PI measures. A zero in the PI category can significantly reduce a clinician’s overall MIPS composite score, potentially pushing it below the 75-point performance threshold and triggering a negative Medicare payment adjustment on 2028 Part B payments. Beyond the MIPS consequences, failing to conduct an SRA also constitutes a potential violation of the HIPAA Security Rule under 45 CFR 164.308(a)(1), which carries its own independent enforcement risk including financial penalties. 

 

Does completing the SRA add points to my MIPS score? 

 

The Security Risk Analysis is a prerequisite gate for the Promoting Interoperability category, not a scored measure, it enables PI scoring entirely but contributes zero points directly to the composite score. Its role is binary: if it is completed and properly attested to, including both attestation components required for 2026, a clinician is eligible to earn points in the Promoting Interoperability category; if it is not, the clinician earns zero in that category regardless of all other PI reporting. Without a completed SRA, no PI points are accessible, but the SRA itself does not add points to the MIPS composite score. 

 

What is the Information Blocking attestation, and what does a clinician attest to? 

 

The Information Blocking attestation is a required, unscored prerequisite for the Promoting Interoperability category, distinct from the Security Risk Analysis attestation. When submitting MIPS PI data, clinicians must attest that, to the best of their knowledge and belief, they have not taken any action that constitutes information blocking as defined in the 21st Century Cures Act (Public Law 114-255) and implemented under the ONC Information Blocking Rule at 45 CFR Part 171. Information blocking is defined as any practice that, except as required by law or covered by a regulatory exception, is likely to interfere with the access, exchange, or use of electronic health information. The attestation confirms that the clinician’s CEHRT has not been configured, restricted, or modified in a way that limits patients’, providers’, or payers’ lawful access to health information. Failure to submit the Information Blocking attestation results in a zero score for the entire PI category, and a false attestation may expose the clinician to separate enforcement action under ONC’s information blocking regulations. 

 

Are there free tools available to help complete the Security Risk Analysis? 

 

The Office of the National Coordinator for Health Information Technology (ONC), in collaboration with the HHS Office for Civil Rights (OCR) and the HHS Office of the General Counsel (OGC), developed a free, downloadable Security Risk Assessment Tool available at healthit.gov, which guides practices through the assessment step by step, covering the required administrative, physical, and technical safeguard domains, and generates a report of findings. Practices may also use dedicated compliance platforms, such as databrackets, which provides structured SRA workflows aligned with both HIPAA Security Rule requirements and MIPS PI attestation standards, or engage other qualified third-party vendors to conduct the SRA on their behalf. If using any vendor, verify that what they deliver is a full SRA meeting both CMS and HIPAA requirements, not simply a general IT review, and retain a complete copy of all documentation. EHR vendors do not typically perform a practice’s SRA as a default service; if you believe yours has, request a copy and confirm it satisfies all applicable requirements before attesting. 

 

What documentation should I keep from my Security Risk Analysis? 

 

Thorough documentation is essential for both MIPS attestation and any potential HIPAA audit. A complete SRA file should include a methodology summary and scope statement covering which systems and data flows were assessed; an asset and vendor inventory; a risk register with likelihood and impact scores for each identified vulnerability; evidence of controls such as policies, procedure logs, training records, and system screenshots; a security incident response plan; a risk mitigation plan showing what corrective actions were taken in response to identified risks; and pre-attestation review notes confirming that required updates were implemented or formally initiated before submitting MIPS data. For 2026, documentation should also include explicit evidence supporting the second attestation component, specifically, records demonstrating that risk management activities were completed in accordance with the HIPAA Security Rule, not merely that the analysis was conducted. 

 

What is the SAFER Guides requirement, and what changed for 2026? 

 

The Safety Assurance Factors for EHR Resilience (SAFER) Guides are a set of best-practice recommendations developed by ONC to help healthcare organizations use electronic health records safely. Attesting to the High-Priority Practices SAFER Guide self-evaluation is a required, unscored prerequisite for the Promoting Interoperability category, failing to attest results in a zero score for the entire PI category. For 2026, CMS finalized a requirement to use the updated 2025 edition of the SAFER Guides rather than the previously required 2016 edition. Clinicians should review the updated guidance before conducting their self-assessment, as the 2025 edition reflects current cybersecurity threats and EHR safety practices not addressed in the older version.

 

Explore Blogs, Webinars and other Resources

Trusted by Reputed Companies

pVerify, Inc.
Electronic Data Solutions
Bernard Robinson & Company
Avance Care
iCliniq
Botsplash
Logically
Mr.Internet Systems
Vision Radiology
Tangible Solutions
Tangible Solutions
WorkSmart
Triyam
Med First Primary and Urgent Care
Arizona State Radiology
DataCaliper
Dose Spot Company Logo
DoseSpot
Forsyte I.T. Solutions
Tego Data

Accreditations and Associations

* Disclaimer: This list of accreditations is held by our team of employees and consultants.

What Our Clients Say

We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center

Our Growing List of Credentials

0 +
Assessments
0 +
Clients
0 +
Assessment Libraries
0 +
Years of Experience
0 +
No. of Staff Trained
0 +
HIPAA
0 +
SOC 2 Readiness
0 +
Pen Testing
0 +
ISO 27001 Certifications
0 +
Dollars Saved in Compliance Penalties