HIPAA Risk Analysis Step by Step for Small Facilities

If you ask a regulator, an auditor or an insurer what they want to see first, the answer is almost always the same: your security risk analysis. It is the foundation of HIPAA Security Rule compliance, and it is also the item small organizations are most likely to skip, rush or hand to a vendor without understanding it.

A risk analysis does not need to be a hundred-page document. It does need to be accurate, complete and current. Here is how a small skilled nursing facility, assisted-living community or clinic can approach one.

What the rule requires

The Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information (ePHI). It then requires you to implement security measures that reduce those risks to a reasonable and appropriate level. HHS and its Office for Civil Rights have published guidance on the analysis, and NIST publishes related material.

A risk analysis is different from a vulnerability scan or a compliance checklist. Those can feed into it, but neither replaces it.

Step 1: Define the scope

List where ePHI is created, received, stored or transmitted. Think broadly:

EHR or EMR systems and any interfaces to pharmacies, labs and billing

Computers, laptops, tablets and phones, including personal devices if staff use them

File servers, cloud storage and email

Backup systems and media

Copiers, scanners and fax or eFax services

Medical devices and monitoring systems that store resident data

Paper records that are scanned or transcribed into systems

Step 2: Build an asset inventory

For each system, record what data it holds, who uses it, where it lives and who is responsible for it. Many organizations find unknown systems at this stage, such as an old spreadsheet with resident data on a shared drive or a forgotten laptop in a closet.

Step 3: Identify threats and vulnerabilities

A threat is something that could cause harm, and a vulnerability is a weakness it could exploit. Common threats for care organizations include:

Phishing and stolen credentials

Ransomware

Lost or stolen devices

Misdirected faxes or emails

Improper access by staff

Vendor or business associate breaches

Power failures, storms, fire and flooding

Hardware failure and unsupported software

Vulnerabilities might be missing MFA, unpatched systems, unencrypted laptops, old shared accounts, weak backups or untrained staff.

Step 4: Assess current controls

For each threat and system, note what safeguards already exist: administrative (policies, training), physical (locks, cameras, badge access) and technical (encryption, access control, logging, backups). Be honest. Controls that exist on paper but are not followed do not count.

Step 5: Rate likelihood and impact

A simple scale works: low, medium and high for both likelihood and impact. Combine them to give each risk a rating. For example, a lack of MFA on remote access to a system holding all resident records might be high likelihood and high impact. A missing cable lock on a rarely used desktop might be low on both.

Step 6: Create a risk management plan

For each significant risk, decide what you will do: reduce it, transfer it, such as through insurance, avoid it or consciously accept it. Assign an owner, a target date and a budget estimate. This plan is what proves you acted on what you found, and regulators have taken action against organizations that identified risks and never addressed them.

Step 7: Document and keep it current

Record your method, findings, ratings and decisions. HIPAA requires documentation to be retained for six years. Review and update the analysis regularly, and whenever you change systems, add a location, move to a new EHR or experience a security incident.

Common mistakes

Treating a one-time vendor scan as the analysis

Leaving out cloud services, personal devices or paper workflows

Never updating the analysis after the first year

Producing a list of risks with no plan or follow-through

Having no one in leadership review or sign off on it

Who should be involved

Include administration, nursing leadership, HR, the business office and IT. Clinical staff understand the real workflows, and leadership owns the budget decisions. A risk analysis done only by IT often misses how work really gets done.

Getting support

UnityCare IT conducts security risk analyses for healthcare organizations and helps turn the findings into a prioritized, budgeted plan. If you have not completed one recently, or you are not sure yours would stand up to review, we can help you get a clear picture.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172