What Is a MIPS Security Risk Assessment (SRA)?
You’ve likely heard about MIPS and its importance for Medicare reporting. But what about the Security Risk Assessment, or SRA? In June 2025, the Centers for Medicare & Medicaid Services (CMS) still list completing an SRA as a cornerstone of the Promoting Interoperability category within MIPS. I’ve guided many practices through this process, and I’m here to walk you through the basics. By the end of this post, you’ll know what an SRA involves, why it matters for your practice’s performance score, and how you can get started right away.
1. What Is a Security Risk Assessment?
A Security Risk Assessment is a structured review of how you protect patient data and electronic health information. At its core, an SRA:
Identifies where protected health information (PHI) lives.
Analyzes potential risks and vulnerabilities.
Document your findings and action plan.
Implements security measures to close gaps.
Reviews and updates the assessment at least once a year.
Tip: Think of your SRA like a safety drill. You test your doors and fire alarms today, so you’re ready when something unexpected happens tomorrow.
2. Why SRA Matters for MIPS
Even if you are familiar with MIPS basics, you may wonder why SRA has its own spotlight. Here’s why:
Performance Points: Completing an SRA can earn you up to 100% credit in the Promoting Interoperability category for 2025.
Risk Reduction: An up-to-date SRA helps you avoid breaches, which could lead to audits, fines, or lost trust.
CMS Audits: During an audit, CMS can request your most recent SRA. Having clear documentation demonstrates compliance.
Best Practice: Keep your SRA documentation in a secure, centralized folder. That way, you can pull it up instantly if CMS or an internal reviewer asks.
3. Core Steps to Complete Your First (or Next) SRA
You already have a basic understanding of MIPS, now let’s break down the SRA into manageable steps:
Gather Your Team
Include your compliance officer, IT lead, and a physician champion. Having diverse perspectives uncovers more risks.Map Data Flows
List every system that creates, stores, or transmits PHI: EHR, patient portal, email, mobile apps, even your office copier.Identify Threats & Vulnerabilities
For each system, ask:What could go wrong? (e.g., lost laptop, phishing attack)
How likely is it? (rare, occasional, frequent)
What would the impact be? (low, medium, high)
Assess Current Safeguards
Document your existing controls, including firewalls, encryption, access controls, and staff training.Score Your Risk
Use a simple matrix:Low Risk: Unlikely + low impact
Medium Risk: Either unlikely + high impact, or likely + low impact
High Risk: Likely + high impact
Create Your Action Plan
For every medium or high risk, list:Action: What you’ll do (e.g., install disk encryption)
Owner: Who’s responsible
Deadline: When it will be completed
Document & Sign Off
Compile your findings into a formal report. Have leadership review and sign to confirm accountability.Review Annually
CMS requires at least yearly reassessment, or whenever new technology is added, or after a security incident.
Pause & Act: Grab a blank spreadsheet and start listing your PHI systems right now. You’ve got this.
4. Practical Tips to Streamline Your SRA
Use Templates: Download CMS’s Security Risk Assessment Tool or a trusted third-party template to save time.
Leverage Automation: Consider basic automated scans for network vulnerabilities.
Train Your Team: A quick annual phishing drill can drastically reduce your risk profile.
Stay Informed: Keep an eye on CMS updates—requirements can shift as early as Performance Year 2026.
Completing your MIPS Security Risk Assessment doesn’t have to be a daunting project. By following these clear, step-by-step actions, you can check off a key MIPS requirement and strengthen your practice’s data protection. Next week, we’ll dive into the five core components every SRA must include—so stay tuned and get your team ready. Ready to kick off your first SRA? Let me know in the comments or reach out to schedule a call. Your patients and your bottom line will thank you!