Important Update to the MIPS Security Risk Analysis Requirement in 2026
The 2026 Quality Payment Program (QPP) Final Rule included many changes to the MIPS Promoting Interoperability (PI) category. One of these changes is an additional component to the Security Risk Analysis (SRA) attestation requirement.
In this blog, we’ll review elements of the SRA, what has changed for the MIPS SRA requirement, and how you can make sure you’re compliant in 2026.
What Is the Security Risk Analysis?
The SRA elements were established through the HIPAA Security Rule. This means that the SRA is not just a box to check for PI—your security practices must meet the necessary standards to ensure HIPAA compliance.
Your SRA must:
- Document potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic Protected Health Information (ePHI) of the eligible clinician,
- Address the encryption/security of data stored in your Certified EHR Technology (CEHRT), and
- Be performed specifically for your system.
It’s important to note that assessing security risks and vulnerabilities goes beyond software. It includes all of the following factors:
- Physical Safeguards in your office environment, such as privacy screens on your computers.
- Administrative Safeguards, such as workforce training.
- Technical Safeguards, such as having access restrictions on your EHR.
- Organizational Policies, Procedures, and Documentation Requirements, such as having written policies, documentation, and business associate agreements.
You can review the Department of Health and Human Services (HHS)’ guidance on the SRA for additional information on what constitutes a risk or vulnerability.
What is the Change to the MIPS SRA Attestation?
Beginning in 2026, MIPS clinicians reporting PI must attest “yes” not only to conducting or reviewing an SRA, but also to conducing risk management activities (already required under HIPAA). This means that you must implement security measures to address weaknesses identified during the SRA.
If you do not attest “yes” to both of these elements, you will receive a zero in the MIPS PI category.
Because HHS recognizes the need for flexibility, the HIPAA Security Rule intentionally does not prescribe a particular method for conducting the SRA or managing risks. Instead, the rule is to “implement reasonable and appropriate security measures.”
If you are an Anatomy IT client, we will review risk management recommendations for your practice based on the results of your SRA. Our team can also help if you need assistance conducting the SRA.
When Do I Need to Complete the SRA?
The SRA can be completed at any time during 2026. It does not have to coincide with your 180-day PI performance period. However, the analysis must be unique for each performance period. This means you cannot reuse your analysis from 2025 for the 2026 performance year.
In addition to completing an SRA annually, you must conduct one anytime you install or upgrade to a new system.
CMS recognizes that organizations conducting their SRA towards the end of 2026 may not be able to implement risk management activities in the same calendar year. As a result, having a risk management implementation plan is enough to attest “yes” to the second component of the SRA requirement. Note that creating the plan must occur in the same calendar year as the SRA.
Next Steps
- Share this information with your colleagues.
- If you are an Anatomy IT client, contact your MIPS Expert if you have any questions.
- If you are not an Anatomy IT client, contact us to learn more about our MIPS Success Plan and to reap the rewards of our combined decades of experience.
If you have any questions on this, let us know!
Written By: Sarrah Hakim, MHSA
About the Author: Sarrah is the Director of Health Policy at Anatomy IT.