Ask a surveyor, an insurer or an attorney which HIPAA document matters most after a breach, and the answer is almost always the same: the security risk analysis. It is the foundation of the Security Rule, and it is the item that small skilled nursing, assisted living and clinic operators most often have out of date, incomplete or missing. The good news is that a risk analysis is a structured exercise, not a mystery. You can do a solid one with a clear process and a few focused weeks.
This walkthrough breaks the work into steps an administrator or director of nursing can follow alongside an IT partner.
The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information (ePHI). It does not prescribe a specific tool or template. HHS has published guidance on the topic, and the NIST publication SP 800-30 is a commonly used method. What matters is that your analysis is documented, covers all of your ePHI, and leads to action.
Start by deciding what is in bounds. For most care organizations, the answer is everything that creates, receives, stores or transmits resident information. That is broader than the EMR alone.
The electronic medical record, such as PointClickCare, and any pharmacy, lab or therapy systems connected to it
Workstations, laptops, tablets and medication cart computers
Phones used for texting or email about residents
Fax services, scanners and copiers with storage drives
File shares, email and cloud storage
Backups, both on-site and off-site
Billing, payroll and HR systems that hold resident or staff data
You cannot protect what you cannot list. Create a simple spreadsheet with each system, where it lives, who owns it, what data it holds, and who can access it. Include vendors. Many facilities discover forgotten items during this step, such as an old server in a closet, a former employee's shared mailbox, or a free file-sharing account someone opened years ago.
For each system, ask what could go wrong and what weakness would let it happen. Think in three buckets.
Human threats: phishing, stolen credentials, curiosity snooping, lost devices, mistakes with fax or email
Technical threats: unpatched software, missing multi-factor authentication, weak Wi-Fi, malware, failed backups
Environmental threats: power loss, water damage, fire, storm outages, which matter a great deal across Oklahoma and Texas
Vulnerabilities are the gaps: an unsupported operating system, shared logins on a nurse station PC, no encryption on laptops, or a vendor with permanent remote access.
Keep the scoring simple. A three-level scale of low, medium and high for both likelihood and impact is enough for most small organizations. Multiply or map the two ratings to a risk level. For example, a shared login on a medication cart might have a high likelihood and a medium impact, which lands it near the top of the list. The point is to rank the work, not to produce false precision.
Note what already reduces each risk: policies, training, access controls, encryption, backups, physical locks, and contracts with vendors. A risk rating should reflect the residual risk after those controls, which is why honest evaluation of whether a control actually works matters. A backup that has never been test-restored is a hope, not a safeguard.
Write down the results in a form you could hand to an auditor. For each significant risk, record the finding, the rating, the planned fix, the person responsible and a target date. This risk management plan is the second half of the requirement. HIPAA expects you to implement security measures sufficient to reduce risks to a reasonable and appropriate level, not to eliminate every risk.
The analysis is not a one-time project. Review it at least annually and whenever something significant changes, such as a new EMR module, a move to a new building, a new vendor with data access, or a security incident. Keep prior versions so you can show progress over time.
A risk analysis goes faster when someone already knows your network and systems. UnityCare IT works with long-term care and healthcare organizations across Oklahoma, Texas and Arkansas, and we can help you inventory systems, gather evidence and turn findings into a practical remediation plan. If it has been a while since your last analysis, a conversation is a reasonable place to start.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172