Most security risk assessments do not fail because they were done badly. They fail because they never close.
I have opened last year's risk assessment to start this year's and found it ninety percent done. So was the one before it. Nobody had done bad work. We just never finished, because there is always something on fire that is louder.
Findings get assigned to a department, and a department is not a person. Those are the ones still open a year later. An assessment that never closes is worse than none at all, because it is a written record that the organization knew.
Meanwhile the insurance renewal asks for the date of the last completed assessment, the accreditation review asks for the same thing, and the policies on file were written by somebody who left in 2021.
I chair the cycle. That is the whole difference, and it is worth being plain about why it matters: there are software products that will produce a completed assessment document for a few hundred dollars a year, and from the outside their output looks like mine. What they do not do is convene the sessions, keep them moving to completion, pursue the remediation owners between quarters, or stand in front of your board and explain what the organization decided to accept and why.
The assessment itself runs on the ONC and OCR Security Risk Assessment Tool, which is the right backbone because it is the framework a regulator already recognizes. Around it: drafting and updating the policies and procedures the assessment surfaces as gaps, covering access control, workforce training, business associate agreement management, incident response and contingency planning. A prioritized remediation tracker where every finding carries a person and a date. Quarterly review sessions, scheduled before the assessment begins rather than after, because afterward nobody schedules them. And the open count in the board packet, so somebody outside the process is watching that number come down.
Beyond the HIPAA subset, the same discipline applies to the whole policy corpus. Most organizations have policies adopted at different times by different people with no review calendar, which means the answer to "when was this last looked at" is nobody knows.
Who is in scope, which systems hold protected information, who chairs alongside me, and the dates. Every quarterly review is on the calendar before any assessment work begins.
Working sessions with the people who actually operate the systems, not only leadership. The tool structures it; the conversation is where the real exposures come out.
Drafts for every gap the assessment surfaced, written to fit how the organization actually works rather than pulled from a template library. Adopted policies go to counsel before they are final.
Finding, owner by name, due date, evidence of closure. Nothing else in it. "Ongoing" is not a date and does not appear.
Four times a year I chase the open items and report the burn-down. The board sees a count that should be going down, and a short explanation of anything the organization has consciously decided to accept.
The artifacts organized the way an OCR inquiry, an accreditation reviewer, or a cyber insurance application will ask for them, so that assembling them is not a fire drill.
This is facilitation, not audit. It is not an attestation, not a certification, and not assurance of compliance. Your organization is the covered entity, and the assessment, its conclusions and every remediation decision belong to you. I facilitate, advise and draft; you review, adopt and own. This is also not legal advice, and adopted policies should be reviewed by your counsel.
I was the HIPAA Privacy Officer for a Virginia child welfare organization through years of annual risk assessments, and I led the Risk Prevention and Management domain through Council on Accreditation review. What sat in those systems was the most private information those families had: who had hurt them, what they were being treated for, where they were living now. Compliance is the word we use for the paperwork. Stewardship is the actual job, and the paperwork is only how you prove you did it.
This one is recurring by regulation, so it does not need a continuation invented for it. The cycle comes around every year whether or not anyone is ready, and the organizations that stay ahead of it are the ones where somebody owns the calendar rather than rediscovering it each spring. Once the systems are open in front of me, the natural next conversation is usually a different one: what else your data could be telling your board.
Thirty minutes. If you already know the date of your last completed assessment, we can talk about what comes next. If you had to go look it up, that is worth talking about too.