If your facility has ever been asked to prove HIPAA compliance, the first document anyone requests is your security risk analysis. It is required by the HIPAA Security Rule, and it is also the item regulators most often find missing or out of date. For a skilled nursing facility, assisted living community or small clinic, the analysis does not need to be a 200-page report. It does need to be real, current and tied to the systems you actually use.
Here are five mistakes we see again and again, and what to do instead.
A downloaded questionnaire filled out once and filed in a binder is not a risk analysis. The Security Rule expects an accurate and thorough assessment of the risks to electronic protected health information (ePHI), and it expects you to keep it current.
What to do instead:
Schedule the analysis at least annually.
Revisit it whenever something major changes, such as a new EHR module, a new building, a merger or a new vendor.
Keep dated versions so you can show how your thinking evolved.
Most facilities remember the electronic health record. Fewer remember the places ePHI quietly collects.
Shared network drives with scanned face sheets and care plans
Email inboxes and eFax services
Staff phones used for photos or text messages
Copiers and multifunction printers with internal hard drives
Backup media and cloud storage
Vendor portals for pharmacy, lab and therapy
Start with an inventory. If you cannot list where ePHI lives, you cannot protect it. Walk each department and ask, where do you save, send or print resident information?
A list of 60 findings with no priorities usually leads to no action. A useful analysis rates each risk by how likely it is and how much harm it could cause, then sorts the results.
A simple approach works well for smaller organizations:
Rate likelihood as low, medium or high.
Rate impact as low, medium or high.
Address high-high items first, and document why lower items can wait.
For example, an unpatched server that is reachable from the internet is a higher priority than a break-room printer that lacks a nicer password policy.
The analysis tells you what is wrong. The Security Rule also requires you to implement security measures sufficient to reduce those risks to a reasonable and appropriate level. That means a written plan with owners and dates.
For each significant finding, record:
The action you will take
Who is responsible
A target completion date
Evidence of completion, such as a screenshot or a ticket number
This turns the report from a snapshot into a working document. If you are audited, evidence of steady progress counts for a lot.
Your risk does not stop at your own walls. The pharmacy, the therapy contractor, your IT provider and your cloud EHR host all handle ePHI on your behalf. A good analysis notes which vendors have access, whether a business associate agreement is in place, and what safeguards they describe.
A quick vendor table helps: vendor name, what data they touch, BAA on file (yes or no), last review date, and how they notify you of an incident.
If your analysis is overdue, you do not have to fix everything at once. Try this sequence over a few weeks:
Build the ePHI inventory with input from each department.
List threats and weaknesses for each system, such as lost devices, phishing, missing patches or weak access controls.
Score and rank the risks.
Write the management plan with owners and dates.
Put a recurring review on the calendar.
Keep the documents themselves. HIPAA requires you to retain required documentation for six years from the date it was created or last in effect, so store each version in a place that will survive staff turnover.
A risk analysis goes faster with someone who knows both the regulation and the technology. UnityCare IT helps long-term care and clinic teams inventory their systems, score the risks in plain English and turn the findings into a practical to-do list. If your last analysis is more than a year old, we are happy to talk through where to begin.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172