RiskASMRiskASM
Cyber Security

PHI Breach Risk Assessment Generator

Generate a PHI breach risk assessment PDF with source-backed hazards, controls, risk ratings and review actions.

How to generate your draft PDF

1

Edit or add hazards

Choose a preloaded hazard, add your own, and adjust the initial risk details.

2

Fill the assessment

Add controls, optional action details, and residual risk ratings.

3

Review and export

Review all hazards, then generate the draft PDF for internal review.

Interactive Assessment

What should be included in scope?

Include the assets, systems, and data that matter most to your organization for a complete and meaningful risk assessment.

5

key scope areas

Focus on the areas that have the greatest impact on your risk posture.

  • Unauthorised disclosure of PHI through lost, stolen or misdirected data
  • Compromised user account retaining access to ePHI
  • Delayed containment of a suspected breach
  • Incomplete preservation of logs and affected records
  • Incorrect scope assessment of impacted individuals

  • 1

    Activate a documented breach-response process and appoint an incident lead

    Shows the primary activity-specific control is established.

  • 2

    Contain accounts, devices, connections and sharing links without destroying evidence

    Confirms the relevant equipment, materials, systems, or arrangements are suitable.

  • 3

    Preserve audit logs, communications and relevant system records

    Supports review of how the identified exposure or operational risk is managed.

  • 4

    Determine affected ePHI, individuals, systems and business associates

    Provides traceable evidence for the assessment and its safeguards.

  • 5

    Engage privacy, security, legal and clinical stakeholders in decisions

    Helps confirm the control is applied and remains effective in practice.

Assessment details

Category

Cyber Security

Frameworks and guidance

HHS HIPAA Breach Notification Rule guidance; NIST incident-response guidance; CISA cyber-incident resources

Last verified

June 30, 2026

Review status

Source mapped / Not human reviewed

PHI Breach Risk Assessment FAQs

This assessment supports response to an actual or suspected PHI breach by structuring containment, evidence review, impact analysis, notification decisions and corrective actions. It helps teams document a defensible draft while professional privacy and legal review remains essential.

Generate your PHI Breach Risk Assessment PDF

Use preloaded hazards, suggested controls, and source-mapped guidance to create a draft assessment for review.