A risk assessment is a mandatory annual task completed by a covered entity and a business associate. It is a HIPAA law created to ensure that all of the HIPAA compliance risks (administrative, ...