Short answer: At minimum, once a year. But HHS guidance on the HIPAA Security Rule frames risk assessment as an ongoing process, not an annual checkbox — meaning specific events (a new EHR system, a new vendor with data access, a breach or near-miss, significant staff changes) should trigger a fresh assessment regardless of when your last annual one happened.
Why "annual" is a floor, not a complete answer
The Security Rule doesn't specify an exact frequency in the way some other regulations do — instead, it requires that your risk assessment remain an accurate, ongoing reflection of your actual security posture. Most compliance guidance settles on annual as a reasonable minimum cadence. But a risk assessment that's technically annual and also technically out of date the moment your practice changes systems isn't really doing its job, even if it satisfies the letter of "we did one this year."
Specific triggers for an earlier reassessment
A new EHR or practice management system. This is usually where the largest concentration of patient data lives. Switching systems changes your risk profile immediately.
A new vendor with access to PHI. Billing services, cloud storage providers, telehealth platforms, IT support — any new vendor relationship is a new point of exposure your existing assessment doesn't account for.
A security incident or near-miss. Even one that didn't result in a confirmed breach. A near-miss is specific, concrete evidence that a particular safeguard has a gap worth reassessing directly.
Significant staff turnover. New staff need training and appropriately scoped access; departing staff need access revoked. An assessment that doesn't reflect your current team doesn't reflect your current risk.
Physical changes to your practice. A new location, a remote work arrangement, or new physical storage of records all introduce risk factors a prior assessment wouldn't have covered.
Why small practices tend to let this lapse
A risk assessment often gets done under some kind of deadline pressure — an OCR audit request, a new EHR vendor asking for proof, a colleague mentioning theirs — and then isn't revisited until the next similar prompt. In between, the actual state of the practice keeps changing while the documented assessment stays frozen at whatever it captured on the day it was completed.
The cost of relying on a stale assessment
If a breach happens and your risk assessment is meaningfully out of date, that gap becomes part of the story during an OCR investigation — not just that a breach occurred, but that your documented understanding of your own risk hadn't kept pace with your actual operations. That's a harder position to defend than having a current, accurate assessment that simply didn't catch everything.
Making this less of a burden
The reason risk assessments tend to go stale is that redoing one from scratch is time-consuming, especially with an outside consultant. A software-based assessment removes most of that friction — it can be re-run whenever something changes, rather than requiring a full new engagement every time.