A missed or incomplete Security Risk Analysis for MIPS can eliminate 25 percent of a clinician’s total MIPS score, even though the measure itself carries no points. Because 2026 performance data determines 2028 Medicare Part B payment adjustments, an error made this year has no visibility until two years later, when the payment adjustment arrives and the option to correct it is gone. CMS also expanded the attestation requirements for the Security Risk Analysis for MIPS in 2026, meaning a practice that complied fully in prior years is not automatically compliant now. Understanding the current requirements, the deadlines attached to them, and what changed for this performance year is essential for any practice reporting Promoting Interoperability data in 2026.
The MIPS Program in 2026
MIPS scores clinicians across four performance categories: Quality at 30 percent, Cost at 30 percent, Promoting Interoperability at 25 percent, and Improvement Activities at 15 percent. CMS held the performance threshold at 75 points for 2026 and has committed to maintaining that threshold through the 2028 performance year, giving practices a stable target but no additional cushion. Clinicians who score at or below 18.75 points face the maximum penalty of negative 9 percent on Medicare Part B payments. Category weights and eligibility rules did not change for 2026, but the measure inventory within each category was revised, and practices should confirm that any measure or activity used in prior years is still valid before submitting 2026 data.
1) Quality
The Quality category includes 5 new measures for 2026, including 2 electronic clinical quality measures, alongside substantive updates to 30 existing measures and the removal of 10 measures, including Q508: Adult COVID-19 Vaccination Status. CMS also narrowed its definition of high-priority measures, removing health equity from that classification and focusing it on core clinical domains such as outcomes, safety, and care coordination. Practices reporting Quality measures for 2026 should verify that any measure used in a prior performance period remains active and correctly classified.
2) Cost
The Cost category is unchanged in terms of inventory for 2026, with no new measures added and none removed, keeping the total at 35 measures. CMS revised the attribution methodology for the Total Per Capita Cost measure to exclude nurse practitioners, physician assistants, and clinical nurse specialists from cost attribution when all other clinicians in their group are already excluded based on specialty. Any new cost measures finalized in future years will carry a two-year, informational-only feedback period before affecting scoring.
3) Improvement Activities
CMS added 3 new Improvement Activities, modified 7, and removed 8 for 2026. The Achieving Health Equity subcategory was retired and replaced with a new Advancing Health and Wellness subcategory; activities previously classified under Achieving Health Equity, including those addressing care planning for LGBTQ patients and community engagement, are no longer available under their original classification. Practices that reported Improvement Activities under the retired subcategory in prior years should confirm whether an equivalent activity exists under the new structure.
MIPS Value Pathways
MIPS Value Pathways, or MVPs, expanded from 21 to 27 for 2026. CMS added 6 new pathways covering diagnostic radiology, interventional radiology, neuropsychology, pathology, podiatry, and vascular surgery, and modified all 21 previously existing pathways to align with the year’s quality and Improvement Activities changes.
Multispecialty groups can no longer register and report an MVP at the group level starting in 2026, except when the group qualifies as a small practice of 15 or fewer clinicians; larger multispecialty groups must register and report at the subgroup, individual, or APM Entity level.
CMS also changed how specialty composition is determined for MVP registration, requiring groups to attest to their own composition rather than relying on claims-based determination.
Promoting Interoperability and the Security Risk Analysis for MIPS
Promoting Interoperability retains its 25 percent weight in 2026, and it is the category within which the Security Risk Analysis for MIPS requirement is housed. This category evaluates a clinician’s use of certified electronic health record technology, and its Protect Patient Health Information objective is satisfied specifically through completion of the Security Risk Analysis for MIPS. All other Promoting Interoperability measures may be reported correctly, and none of that reporting will offset an incomplete Security Risk Analysis for MIPS.
The Security Risk Analysis for MIPS is not scored and contributes no points toward the MIPS total. However, failure to complete the required actions for the Security Risk Analysis for MIPS results in zero points for the entire Promoting Interoperability performance category, a 25 percent reduction to the overall MIPS score. This is the defining characteristic of the measure: it carries no scoring upside but the most significant downside risk of any single requirement in the program.
What Changed in the Security Risk Analysis for MIPS Attestation in 2026
For 2026, the Security Risk Analysis for MIPS attestation requires two separate statements instead of one. Clinicians must attest that they conducted or reviewed a security risk analysis under the HIPAA Security Rule at 45 CFR 164.308(a)(1)(ii)(A) and separately attest that they conducted security risk management activities under 45 CFR 164.308(a)(1)(ii)(B), meaning they implemented security measures sufficient to reduce identified risks to a reasonable and appropriate level. In prior years, a single attestation covering the analysis itself was sufficient. The added requirement means documentation of remediation, not just identification of risk, is now necessary to satisfy the Security Risk Analysis for MIPS.
Where encryption is reasonable and appropriate, it must be implemented under 45 CFR 164.312(a)(2)(iv); where it is not, an equivalent alternative safeguard must be adopted and documented. This standard applies directly to the risk management component of the Security Risk Analysis for MIPS and should be addressed explicitly in supporting documentation.
SRA Deadlines for MIPS Compliance
The Security Risk Analysis for MIPS must be conducted or reviewed within the calendar year of the performance period, January 1 through December 31, 2026. It is not required to occur during a clinician’s chosen Promoting Interoperability reporting window, but it must be unique to the current performance period and cover that period’s full scope. A Security Risk Analysis for MIPS completed in a prior year does not satisfy the current year’s requirement, regardless of its quality at the time it was conducted.
Clinicians must separately submit Promoting Interoperability data for a minimum of 180 consecutive days within the 2026 calendar year. This submission requirement operates independently of the Security Risk Analysis for MIPS deadline, and failure to meet it can zero out the Promoting Interoperability score regardless of the analysis’s completion status. An additional analysis is required upon installation or upgrade of a certified EHR system, since a prior Security Risk Analysis for MIPS would not have assessed the new system.
SAFER Guide Assessment Requirement
In addition to the Security Risk Analysis for MIPS, clinicians must complete an Annual Assessment using the High-Priority Practices SAFER Guide. For 2026, this assessment must use the updated 2025 edition of the guide. Clinicians attest “Yes” to completing this self-assessment during the calendar year, and both this attestation and the Security Risk Analysis for MIPS are required before a clinician can score above zero in the Promoting Interoperability category.
What the Security Risk Analysis for MIPS Includes
1) Risk Identification
The Security Risk Analysis for MIPS begins with identifying every location where electronic protected health information, or ePHI, is created, stored, accessed, or transmitted, including EHR systems, laptops, mobile devices, cloud storage, and network servers. This step also identifies potential threats to that data, including unauthorized access, data breaches, and natural disasters.
2) Risk Assessment and Prioritization
This step evaluates the likelihood and potential impact of each identified threat and prioritizes high-risk areas that could compromise patient information or disrupt care. Prioritization determines which risks require immediate remediation and directly informs the risk management activities required under the 2026 attestation standard.
3) Security Measures Implementation
Based on the prioritized risks, practices must implement security measures including access controls, encryption, firewall configuration, secure data transmission, and authentication protocols. Under the 2026 requirements, this implementation step constitutes the evidentiary basis for the risk management attestation and cannot be omitted.
4) Review of Current Security Measures
Existing security controls must be reassessed for continued effectiveness against current threats, with adjustments made as needed. A control that met the reasonable and appropriate standard in a prior year may no longer meet that standard given evolving threats and technology.
5) Documentation of Findings and Corrective Actions
Findings from the Security Risk Analysis for MIPS and any corrective actions taken must be documented in detail. This documentation is required for MIPS compliance and will be requested in the event of a CMS or Medicaid audit.
6) Continuous Monitoring and Updates
The Security Risk Analysis for MIPS must be revisited annually and updated following significant changes to technology or workflow. This is a continuous requirement rather than a one-time task.
Best Practices for Completing the Security Risk Analysis for MIPS
1) Plan Early
Practices should begin the Security Risk Analysis for MIPS well in advance of reporting deadlines to allow time for remediation. An assessment conducted solely by an EHR vendor typically does not satisfy MIPS requirements, since vendor assessments generally cover only the EHR platform rather than the full scope of ePHI across a practice.
2) Involve All Staff
Staff members who interact with ePHI should be included in the Security Risk Analysis for MIPS process and trained on relevant security practices, including password protection and phishing recognition.
3) Use Established Tools and Resources
CMS and the HHS Office for Civil Rights provide resources, including the Security Risk Assessment Tool developed by the Office of the National Coordinator for Health IT and OCR, to support a comprehensive Security Risk Analysis for MIPS.
4) Implement Encryption and Access Controls
ePHI should be encrypted where reasonable and appropriate, particularly on portable devices, and access should be restricted based on job role using multi-factor authentication. These controls serve as direct evidence supporting the risk management component of the 2026 attestation.
5) Maintain Documentation
All findings, corrective actions, and security policies related to the Security Risk Analysis for MIPS should be documented and retained to support future assessments and demonstrate compliance during an audit.
6) Provide Ongoing Security Training
Regular security awareness and phishing awareness training should accompany the Security Risk Analysis for MIPS to address the human factors that technical controls alone cannot resolve.
7) Maintain an Incident Response Plan
Practices should develop and regularly test an incident response plan for data breaches or security incidents, ensuring staff can respond effectively if an event occurs.
Data Submission Requirements
CMS calculates a score for each Promoting Interoperability submission when multiple submissions occur and assigns the highest score achieved. Clinicians who delegate data submission to a third-party intermediary may request reweighting if their data becomes inaccessible for reasons outside their control. Automatic reweighting for the Promoting Interoperability category is no longer available to clinical social workers beginning with the 2025 performance period, requiring this group to actively manage the category, including the Security Risk Analysis for MIPS, going forward.
The Impact of the Security Risk Analysis on MIPS Scoring
A properly completed Security Risk Analysis for MIPS satisfies the Protect Patient Health Information objective and supports the practice’s broader resilience against cybersecurity threats. Because Promoting Interoperability represents 25 percent of the total MIPS score, completing the Security Risk Analysis for MIPS is directly tied to a clinician’s ability to receive a positive payment adjustment rather than a penalty.
Completing Your Security Risk Analysis for MIPS in 2026
Given the expanded two-part attestation requirement, practices should begin their Security Risk Analysis for MIPS early in the 2026 calendar year rather than waiting until the fourth quarter. Organizations that support healthcare providers with security risk assessments can assist with risk identification, prioritization, documentation, staff training, and audit support to ensure the requirement is met before the calendar-year deadline.
Meet Your SRA Deadlines and Protect ePHI with databrackets
At databrackets, we are a team of certified and experienced security experts with over 15 years of experience across industries. We have conducted hundreds of SRAs for MIPS and worked with the HHS and their auditors on what is required.
We have been working with Healthcare Providers for over 15 years and offer 3 Engagement Options – our DIY Toolkits (ideal for MSPs and mature in-house IT teams), and Hybrid or Consulting Services for Compliance / Security Standards.
For MIPS, we add value to your application in a variety of ways:
- Our team conducts an end-to-end analysis as part of our Security Risk Analysis (SRA), and helps you to identify areas of improvement, take corrective actions and access relevant staff training modules.
- We support your practice during a CMS / Medicaid Audit, if required.
- We identify key vulnerabilities in your systems which helps you to comply with the HIPAA federal/state requirements as well.
- Time is of essence. Our team helps you plan and complete all tasks within the deadline.
Overview of databrackets
Our team of security experts has supported organizations across a wide variety of industries to align their processes with security frameworks like 21 CFR Part 11, NIST SP 800-53, NIST SP 800-171, NIST Cybersecurity Framework, ISO 27001, SOC 2, CMMC, HIPAA, GDPR etc.
We are an authorized certifying body for ISO 27001 and a C3PAO for CMMC. We are an accredited FedRAMP Independent Assessor / 3PAO with ISO/IEC 17020:2012 accreditation from A2LA. We also have partnerships to help clients prepare for and obtain other security certifications.
We have helped organizations of all sizes comply with cybersecurity best practices, utilize and customize our staff training modules and prove their compliance with security standards. We enable organizations to expand their business opportunities and assure existing clients of their commitment to protecting sensitive information and maintaining high standards of security and privacy.
We are constantly expanding our library of assessments and services to serve organizations across industries. Schedule a Consultation if you would like to Connect with an Expert to understand how we can customize our services to meet your specific requirements.
Srini Kolathur
Co-Author: Aditi Salhotra
Manager – Digital Marketing and Business Development
Aditi is a Digital Marketing and Business Development Professional at databrackets.com. She is a strong advocate of good cyber hygiene and is proud of the company’s mission to safeguard organizations from cyber threats and ensure their business continuity in adverse situations.