For Privacy Officers
Security Risk Assessment
Answer, save, complete, and export your Security Risk Assessment (Step 2).
The Security Risk Assessment (SRA) is 63 questions in 13 sections on one scrolling page. Each question shows its HIPAA reference. Open it from sidebar Security Risk Assessment or dashboard Step 2.
Want the why behind the SRA? See the Support Center.

Before you start

Answer and come back anytime

- Click Yes or No (or choose an option) for each question. Add a note in the box under a question if you like.
- Your work saves automatically. The Assessment Progress card shows how many of the 63 you've answered.
- Leave and come back whenever you want. Other Privacy Officers in your organization see the same answers.
Complete it
Answer all 63 questions
Complete Assessment stays greyed out until every question has an answer.
Read the warning
Once you press Complete, your answers are locked and can't be changed.

Click Complete Assessment
You'll see "Security Risk Assessment Completed".
Export your results
Click Export Markdown or Export CSV. We highly recommend exporting for safekeeping. The Markdown export includes your overall score, a category breakdown, and every gap with its recommended fix.

What happens next
- Every No automatically becomes an open, high-priority remediation plan, due in 90 days. Head to Remediation Plans.
- Review Submitted Answers shows your answers read-only.
Changing answers or starting next year's SRA
There's no reset button. To reopen your SRA or set up next year's, email hello@oneguyconsulting.com and we'll help.
About 30 days before your SRA's one-year anniversary, and again when it's due, the portal emails a reminder to your Privacy Officer and admin accounts. See Reminders and emails.