Your MIPS Score Has a Single Point of Failure and It's Due by December 31
If you participate in Medicare's Merit-based Incentive Payment System (MIPS), you already know that your performance score determines whether you receive a bonus, a penalty, or nothing at all on your future Medicare payments. What many practices don't realize is that one requirement, the HIPAA Security Risk Assessment (SRA), can wipe out an entire performance category on its own.
That category is Promoting Interoperability (PI). It accounts for 25% of your total MIPS score. And if you fail to properly attest to your Security Risk Assessment by December 31, 2026, your PI score goes to zero. Not low - zero.
What Is the Promoting Interoperability Category?
The PI category measures how effectively your practice uses certified EHR technology to support care coordination, patient engagement, and data exchange. It replaced the old Meaningful Use program and covers things like patient access to records, electronic prescribing, health information exchange, and public health reporting.
CMS weights PI at 25% of your composite MIPS score. A strong PI performance can meaningfully boost your payment adjustment. A zero in PI, caused by a single missed attestation, can drag your total score below the threshold that triggers a Medicare payment penalty.
For 2026, that penalty is up to a 9% reduction on your Medicare Part B payments. For a practice billing even modest Medicare volume, that is a significant number.
Where the SRA Fits
The Security Risk Analysis measure sits at the foundation of the entire PI category. Unlike the other PI measures, it is not scored on a performance rate, it is a yes/no attestation. But answering "No", or failing to attest at all triggers an automatic zero for the entire PI category, regardless of how well you performed on every other measure.
CMS treats it this way because the SRA is not optional under HIPAA. The HIPAA Security Rule has required covered entities to conduct a thorough assessment of the risks to electronic protected health information (ePHI) since 2005. MIPS simply enforces that requirement with a payment consequence.
The Deadline Is Real
The performance period for 2026 MIPS is January 1 through December 31, 2026. Your SRA must be conducted within that calendar year. You cannot use last year's assessment. You cannot back-date one in January. The clock is running now.
For practices that have been putting this off, or that completed a cursory review that wouldn't hold up to scrutiny, this is the year to get it right because the requirements in 2026 are more demanding than they have ever been.
What's New in 2026
CMS's 2026 final rule added a second attestation to the SRA measure. It is no longer enough to confirm that you conducted a risk assessment. You must now also attest that you conducted security risk management activities, meaning you identified vulnerabilities and took documented action to address them. We'll cover exactly what that means in the next post.
The short version: an SRA you did but didn't act on is no longer sufficient.
The Bottom Line
The Promoting Interoperability category represents a quarter of your MIPS score. The Security Risk Assessment is the key that unlocks it. In 2026, that key has two teeth instead of one. Practices that treat the SRA as a paperwork exercise - or skip it entirely - are handing CMS a reason to cut their Medicare reimbursements.
There is time to get this done correctly before December 31. But not unlimited time.
Chirpy Bird Inc. helps medical practices complete their HIPAA Security Risk Assessment with confidence. Whether you prefer to work through it yourself with our guided, web-based DIY tool or want our experts to handle the full assessment for you, we provide the comprehensive documentation and reports your practice needs to satisfy both CMS attestation requirements and OCR audit standards. Get started today.