What Is a MIPS Security Risk Assessment (SRA)?

You’ve likely heard about MIPS and its importance for Medicare reporting. But what about the Security Risk Assessment, or SRA? In June 2025, the Centers for Medicare & Medicaid Services (CMS) still list completing an SRA as a cornerstone of the Promoting Interoperability category within MIPS. I’ve guided many practices through this process, and I’m here to walk you through the basics. By the end of this post, you’ll know what an SRA involves, why it matters for your practice’s performance score, and how you can get started right away.

1. What Is a Security Risk Assessment?

A Security Risk Assessment is a structured review of how you protect patient data and electronic health information. At its core, an SRA:

  1. Identifies where protected health information (PHI) lives.

  2. Analyzes potential risks and vulnerabilities.

  3. Document your findings and action plan.

  4. Implements security measures to close gaps.

  5. Reviews and updates the assessment at least once a year.

Tip: Think of your SRA like a safety drill. You test your doors and fire alarms today, so you’re ready when something unexpected happens tomorrow.

2. Why SRA Matters for MIPS

Even if you are familiar with MIPS basics, you may wonder why SRA has its own spotlight. Here’s why:

  • Performance Points: Completing an SRA can earn you up to 100% credit in the Promoting Interoperability category for 2025.

  • Risk Reduction: An up-to-date SRA helps you avoid breaches, which could lead to audits, fines, or lost trust.

  • CMS Audits: During an audit, CMS can request your most recent SRA. Having clear documentation demonstrates compliance.

Best Practice: Keep your SRA documentation in a secure, centralized folder. That way, you can pull it up instantly if CMS or an internal reviewer asks.

3. Core Steps to Complete Your First (or Next) SRA

You already have a basic understanding of MIPS, now let’s break down the SRA into manageable steps:

  1. Gather Your Team
    Include your compliance officer, IT lead, and a physician champion. Having diverse perspectives uncovers more risks.

  2. Map Data Flows
    List every system that creates, stores, or transmits PHI: EHR, patient portal, email, mobile apps, even your office copier.

  3. Identify Threats & Vulnerabilities
    For each system, ask:

    • What could go wrong? (e.g., lost laptop, phishing attack)

    • How likely is it? (rare, occasional, frequent)

    • What would the impact be? (low, medium, high)

  4. Assess Current Safeguards
    Document your existing controls, including firewalls, encryption, access controls, and staff training.

  5. Score Your Risk
    Use a simple matrix:

    • Low Risk: Unlikely + low impact

    • Medium Risk: Either unlikely + high impact, or likely + low impact

    • High Risk: Likely + high impact

  6. Create Your Action Plan
    For every medium or high risk, list:

    • Action: What you’ll do (e.g., install disk encryption)

    • Owner: Who’s responsible

    • Deadline: When it will be completed

  7. Document & Sign Off
    Compile your findings into a formal report. Have leadership review and sign to confirm accountability.

  8. Review Annually
    CMS requires at least yearly reassessment, or whenever new technology is added, or after a security incident.

Pause & Act: Grab a blank spreadsheet and start listing your PHI systems right now. You’ve got this.

4. Practical Tips to Streamline Your SRA

  • Use Templates: Download CMS’s Security Risk Assessment Tool or a trusted third-party template to save time.

  • Leverage Automation: Consider basic automated scans for network vulnerabilities.

  • Train Your Team: A quick annual phishing drill can drastically reduce your risk profile.

  • Stay Informed: Keep an eye on CMS updates—requirements can shift as early as Performance Year 2026.

Completing your MIPS Security Risk Assessment doesn’t have to be a daunting project. By following these clear, step-by-step actions, you can check off a key MIPS requirement and strengthen your practice’s data protection. Next week, we’ll dive into the five core components every SRA must include—so stay tuned and get your team ready. Ready to kick off your first SRA? Let me know in the comments or reach out to schedule a call. Your patients and your bottom line will thank you!

Previous
Previous

Automatic Re-Weighting Policies in CY 2025: What Every MIPS Provider Should Know

Next
Next

Meeting the Minimum PI Data Submission Requirements (A Tutorial)