Assessment Configuration
Answer these 6 questions to customize your HIPAA Security Risk Assessment. This determines which questions apply to your organization.

BAs have fundamentally different obligations than CEs. This is the primary branching point.

Cloud-only organizations skip most physical safeguards questions.

Software developers receive enhanced technical depth questions (API security, encryption, SDLC).

A 5-person practice vs a 500-bed hospital have fundamentally different SRA needs.

Cloud users inherit physical security from provider. On-prem owns everything.

This affects output format and urgency, not question selection.