This document provides a user guide for the Security Risk Assessment (SRA) Tool developed by the Office of the National Coordinator for Health Information Technology (ONC). The SRA Tool is designed to help small to medium sized healthcare practices evaluate risks, vulnerabilities, and adherence to the HIPAA Security Rule by completing a risk assessment. The guide explains how to download and use the SRA Tool, which allows users to assess their implementation of the HIPAA Security Rule across basic security practices, risk management, and personnel security. However, the guide also clarifies that use of the SRA Tool alone does not guarantee compliance with HIPAA or other relevant laws and regulations.