If you ask a regulator, an auditor or an insurer what they want to see first, the answer is almost always the same: your security risk analysis. It is the foundation of HIPAA Security Rule compliance, and it is also the item small organizations are most likely to skip, rush or hand to a vendor without understanding it.
A risk analysis does not need to be a hundred-page document. It does need to be accurate, complete and current. Here is how a small skilled nursing facility, assisted-living community or clinic can approach one.
The Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information (ePHI). It then requires you to implement security measures that reduce those risks to a reasonable and appropriate level. HHS and its Office for Civil Rights have published guidance on the analysis, and NIST publishes related material.
A risk analysis is different from a vulnerability scan or a compliance checklist. Those can feed into it, but neither replaces it.
List where ePHI is created, received, stored or transmitted. Think broadly:
EHR or EMR systems and any interfaces to pharmacies, labs and billing
Computers, laptops, tablets and phones, including personal devices if staff use them
File servers, cloud storage and email
Backup systems and media
Copiers, scanners and fax or eFax services
Medical devices and monitoring systems that store resident data
Paper records that are scanned or transcribed into systems
For each system, record what data it holds, who uses it, where it lives and who is responsible for it. Many organizations find unknown systems at this stage, such as an old spreadsheet with resident data on a shared drive or a forgotten laptop in a closet.
A threat is something that could cause harm, and a vulnerability is a weakness it could exploit. Common threats for care organizations include:
Phishing and stolen credentials
Ransomware
Lost or stolen devices
Misdirected faxes or emails
Improper access by staff
Vendor or business associate breaches
Power failures, storms, fire and flooding
Hardware failure and unsupported software
Vulnerabilities might be missing MFA, unpatched systems, unencrypted laptops, old shared accounts, weak backups or untrained staff.
For each threat and system, note what safeguards already exist: administrative (policies, training), physical (locks, cameras, badge access) and technical (encryption, access control, logging, backups). Be honest. Controls that exist on paper but are not followed do not count.
A simple scale works: low, medium and high for both likelihood and impact. Combine them to give each risk a rating. For example, a lack of MFA on remote access to a system holding all resident records might be high likelihood and high impact. A missing cable lock on a rarely used desktop might be low on both.
For each significant risk, decide what you will do: reduce it, transfer it, such as through insurance, avoid it or consciously accept it. Assign an owner, a target date and a budget estimate. This plan is what proves you acted on what you found, and regulators have taken action against organizations that identified risks and never addressed them.
Record your method, findings, ratings and decisions. HIPAA requires documentation to be retained for six years. Review and update the analysis regularly, and whenever you change systems, add a location, move to a new EHR or experience a security incident.
Treating a one-time vendor scan as the analysis
Leaving out cloud services, personal devices or paper workflows
Never updating the analysis after the first year
Producing a list of risks with no plan or follow-through
Having no one in leadership review or sign off on it
Include administration, nursing leadership, HR, the business office and IT. Clinical staff understand the real workflows, and leadership owns the budget decisions. A risk analysis done only by IT often misses how work really gets done.
UnityCare IT conducts security risk analyses for healthcare organizations and helps turn the findings into a prioritized, budgeted plan. If you have not completed one recently, or you are not sure yours would stand up to review, we can help you get a clear picture.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172