HIPAA Security Risk Analysis for Critical Access Hospitals

A Critical Access Hospital carries the same HIPAA Security, Privacy, and Breach Notification obligations as a 500-bed medical center, with a fraction of the staff to carry them. Compliance officers and IT directors at CAHs are usually doing this work alongside several other roles, often across a facility that also runs attached clinics. Medcurity builds the Security Risk Analysis around that reality: one engagement across your sites, an assessor who walks your facility rather than a form that asks you to describe it, and a named advisor who stays with you after the report ships.

The constraint every CAH compliance officer works inside

The HIPAA Security Rule at 45 CFR Part 164 does not scale down for a 25-bed facility. The Security Risk Analysis requirement at 45 CFR 164.308(a)(1)(ii)(A), the administrative, physical, and technical safeguards at 164.308, 164.310, and 164.312, and the Breach Notification Rule all apply in full. What changes is who is doing the work: often a compliance officer or IT director covering the role alongside other duties, leaning on shared regional IT services, with a budget that has to justify every line against patient care. A generic risk assessment template built for a large system does not fit that environment, and a form that asks someone to describe their own facility from memory misses what a walkthrough catches.

Medcurity’s approach for Critical Access Hospitals

What rural hospital leaders say about working with Medcurity

“Medcurity has been a trustworthy resource for Harbor Regional Health Community Hospital. As a rural hospital, we value partners who help us stay on top of policy and federal program changes. Thank you for providing an intuitive and comprehensive platform, as well as expert advice, that enables our staff to focus on providing exceptional care for our community.”

Tom Jensen, Chief Executive Officer, Harbor Regional Health Community Hospital

“Medcurity has quickly become a trusted partner in ensuring our organization is compliant with our regulations, applying best practices and ensuring the best outcome for all of our patients with our Security Risk Assessment. Joe and his team are top notch and support our rural communities with technical assistance with real-time feedback.”

Desiree Sweeney, Chief Executive Officer, NEW Health

Pricing scoped to your hospital

Every CAH is a different size, with a different number of attached sites, a different shared-IT arrangement, and a different scope of PHI systems. Rather than quote a number that will not match your facility, Medcurity scopes pricing to your sites and your team. Request pricing and we will size the engagement to your hospital, not the other way around.

Request a demo to walk through the engagement, or let’s talk if you would rather start with a conversation.

Start this week. Your assessment can be complete and audit-ready before December 31.

A CAH that scopes and kicks off its engagement now has a realistic runway to finish before the calendar turns, with documentation in hand heading into next year’s budget cycle and any MIPS Promoting Interoperability attestation on your calendar.

Frequently asked questions

How often does a Critical Access Hospital need to complete a Security Risk Analysis?

HIPAA requires a Security Risk Analysis that is kept current and redone after any material change, such as a new EHR, a facility expansion, or a new telehealth platform. It does not set a fixed annual deadline; an annual cycle is part of the proposed 2026 Security Rule update and is not current law. Separately, a CAH billing under Medicare’s Merit-based Incentive Payment System (MIPS) needs a current SRA to earn the Promoting Interoperability credit, which means the analysis has to be completed within each performance period regardless of what HIPAA itself requires.

Are the 2026 HIPAA Security Rule updates already in effect?

No. The 2026 Security Rule changes are a Notice of Proposed Rulemaking (NPRM) from the HHS Office for Civil Rights. They have not been finalized, and OMB’s current target for final action is July 2027. Treat the proposal as direction for where requirements are heading, such as encryption and multi-factor authentication expectations, not as a rule your hospital is already out of compliance with.

Can Medcurity assess our hospital and an attached rural health clinic under one engagement?

Yes. Organizations running several delivery sites, including a CAH with attached rural health clinics or outpatient service lines, are assessed under a single engagement, with roll-up reporting across the program and site-level detail underneath.

What does OCR look for in a hospital’s Security Risk Analysis?

OCR looks for a documented, formal process: the systems in scope, the threats and vulnerabilities identified, a risk rating for each gap, a mitigation plan with owners and timelines, and evidence that the assessment was kept current after significant changes. A hospital without a documented SRA has effectively told OCR it has not systematically evaluated whether it is protecting patient data, which is a finding on its own regardless of how secure the underlying systems actually are.