PHI Breach Risk Assessment Generator
Generate a PHI breach risk assessment PDF with source-backed hazards, controls, risk ratings and review actions.
How to generate your draft PDF

Edit or add hazards
Choose a preloaded hazard, add your own, and adjust the initial risk details.

Fill the assessment
Add controls, optional action details, and residual risk ratings.

Review and export
Review all hazards, then generate the draft PDF for internal review.
Interactive Assessment
What should be included in scope?
Include the assets, systems, and data that matter most to your organization for a complete and meaningful risk assessment.
5
key scope areas
Focus on the areas that have the greatest impact on your risk posture.
- Unauthorised disclosure of PHI through lost, stolen or misdirected data
- Compromised user account retaining access to ePHI
- Delayed containment of a suspected breach
- Incomplete preservation of logs and affected records
- Incorrect scope assessment of impacted individuals
- 1
Activate a documented breach-response process and appoint an incident lead
Shows the primary activity-specific control is established.
- 2
Contain accounts, devices, connections and sharing links without destroying evidence
Confirms the relevant equipment, materials, systems, or arrangements are suitable.
- 3
Preserve audit logs, communications and relevant system records
Supports review of how the identified exposure or operational risk is managed.
- 4
Determine affected ePHI, individuals, systems and business associates
Provides traceable evidence for the assessment and its safeguards.
- 5
Engage privacy, security, legal and clinical stakeholders in decisions
Helps confirm the control is applied and remains effective in practice.
Assessment details
Category
Cyber Security
Frameworks and guidance
HHS HIPAA Breach Notification Rule guidance; NIST incident-response guidance; CISA cyber-incident resources
Last verified
June 30, 2026
Review status
Source mapped / Not human reviewed
Related risk assessment generators
Explore related draft assessment generators that use similar source-mapped risk and control guidance.
Cyber Security Risk Assessment Generator
Generate a risk assessment for cyber security PDF with source-backed hazards, controls, risk ratings and review actions.
Information Security Risk Assessment Generator
Generate a risk assessment for information security PDF with source-backed hazards, controls, risk ratings and review actions.
HIPAA Security Risk Assessment for a Small Physician Practice Generator
Generate a HIPAA security risk assessment for a small physician practice PDF with source-backed hazards, controls, risk ratings and review actions.
Security Risk Analysis for MIPS Generator
Generate a security risk analysis for MIPS PDF with source-backed hazards, controls, risk ratings and review actions.
Cyber Security Risk Assessment for SCADA and DCS Networks Generator
Generate a cyber security risk assessment for SCADA and DCS networks PDF with source-backed hazards, controls, risk ratings and review actions.
Information Security Risk Assessment for Banks Generator
Generate a information security risk assessment for banks PDF with source-backed hazards, controls, risk ratings and review actions.
PHI Breach Risk Assessment FAQs
This assessment supports response to an actual or suspected PHI breach by structuring containment, evidence review, impact analysis, notification decisions and corrective actions. It helps teams document a defensible draft while professional privacy and legal review remains essential.
Generate your PHI Breach Risk Assessment PDF
Use preloaded hazards, suggested controls, and source-mapped guidance to create a draft assessment for review.