Built for HIPAA Security Risk Analysis

Threat Modeling
for Healthcare

The HIPAA Security Rule requires a Security Risk Analysis of every system that touches electronic protected health information -- threat identification, vulnerability identification, and risk determination. ThreatTree gives your team a structured place to build that analysis and keep it current as systems change.

Free forever plan Scope threat models to ePHI systems Export anytime, no lock-in
HIPAA Security Rule

Security Risk Analysis, mapped to ThreatTree

OCR guidance points to NIST SP 800-30 for how a Security Risk Analysis should be structured. Here's where each step fits in a ThreatTree forest.

NIST 800-30 step In ThreatTree
1 System & asset characterization
Where ePHI is created, received, maintained, or transmitted
DFD processes and data stores tagged for ePHI, with trust boundaries around each system boundary
2 Threat identification
Sources and events that could compromise ePHI confidentiality, integrity, or availability
STRIDE tagging across every DFD element surfaces spoofing, tampering, and disclosure threats systematically
3 Vulnerability identification
Weaknesses a threat could exploit
Attack Trees decompose each threat scenario into AND/OR attack steps down to the exploitable weakness, tagged with CAPEC and MITRE ATT&CK
4 Likelihood & impact determination
Probability of occurrence and severity of harm to ePHI
Likelihood x Impact scoring per attack tree node, weighted toward confidentiality and availability of ePHI
5 Risk determination & documentation
Combine likelihood and impact, document for OCR review
A ranked risk register generated automatically across the forest, exportable as a PDF for your risk analysis file

What this is, and isn't: ThreatTree addresses the technical system-level threat and risk analysis a HIPAA Security Risk Analysis requires. It does not cover administrative or physical safeguards, workforce training, or Business Associate Agreement management -- and it isn't a substitute for your compliance and legal teams' judgment on whether your overall risk analysis satisfies the Security Rule.

Why teams use ThreatTree

A risk analysis you can keep current

Every threat traces back to an ePHI system, and every risk decision traces back to a rated attack path.

  • Architecture-Anchored ePHI Flows

    Model EHR systems, medical devices, and third-party integrations as DFD elements, with trust boundaries around each. Every threat traces back to a real system, not a floating assumption.

  • Attack Path Decomposition

    Break each threat into an Attack Tree with AND/OR logic, from attacker goal to atomic step, so vulnerabilities are documented, not just implied.

  • Prioritized Risk Register

    Likelihood x Impact scoring generates a ranked risk register automatically across every tree in a forest -- the risk determination step, backed by traceable evidence.

  • Team Collaboration & RBAC

    Invite IT, security, and compliance leads with owner, editor, or viewer roles, so the risk analysis stays a living document instead of an annual one-off exercise.

FAQ

Healthcare threat modeling, answered

What covered entities and business associates ask before adopting ThreatTree.

Still have questions?

We usually reply within a day.

Get in touch
Is ThreatTree a full HIPAA Security Risk Assessment tool?

No. ThreatTree addresses the technical system-level threat and risk analysis a HIPAA Security Risk Analysis requires -- it does not cover administrative or physical safeguard questionnaires, workforce training tracking, or Business Associate Agreement management.

Does using ThreatTree satisfy 45 CFR 164.308(a)(1)(ii)(A)?

ThreatTree helps you build and document the threat identification, vulnerability identification, and risk determination steps that provision describes, following the structure OCR guidance points to in NIST SP 800-30. Whether your overall risk analysis satisfies the Security Rule is a determination your compliance and legal teams make, not something this page or product can guarantee.

Can I scope a threat model to just our ePHI systems?

Yes. Tag the data stores, processes, and interfaces that touch electronic protected health information and draw a trust boundary around them, so the threat model stays focused on where PHI actually flows.

How often should we update the risk analysis?

OCR guidance treats risk analysis as ongoing, not a once-a-year checkbox. Because a ThreatTree forest is a living model, you can update it whenever a system changes rather than re-doing the whole analysis from scratch annually.

Start your Security Risk Analysis in ThreatTree

Free plan available -- no credit card required. Be up and running in minutes.