HIPAA Security Risk Analysis: A Step-by-Step Walkthrough

If there is one HIPAA requirement that administrators should understand well, it is the security risk analysis. The Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. Federal enforcement actions have repeatedly cited organizations for not having one, or for having one that was outdated or incomplete.

A risk analysis does not have to be mysterious. It is a structured way to ask what you have, what could go wrong and what you are doing about it.

Step 1: Define the Scope

The scope covers all electronic protected health information your organization creates, receives, maintains or transmits. Think beyond the EHR. Include:

Servers, workstations, laptops, tablets and phones

Email, eFax and messaging tools

Cloud services and hosted applications

Medical and monitoring devices that store or transmit resident data

Backups and portable media

Paper-to-electronic processes such as scanning

Step 2: Inventory Your Assets and Data Flows

List each system that touches resident information, where the data lives and how it moves. A simple spreadsheet works: system name, owner, location, who has access, whether data is encrypted and which vendors are involved. Then sketch how information flows, for example from admission to EHR to pharmacy to billing. Gaps often appear here, such as a shared drive nobody remembered.

Step 3: Identify Threats and Vulnerabilities

A threat is something that could cause harm, such as ransomware, a lost laptop, an employee snooping or a power outage. A vulnerability is a weakness that a threat could use, such as unpatched software, missing multi-factor authentication or an unlocked server closet. For each system, ask which threats are realistic and which weaknesses exist.

Step 4: Review Current Safeguards

Document what is already in place. HIPAA groups safeguards into three categories:

Administrative: policies, training, access approval, incident procedures

Physical: locked rooms, device controls, visitor management

Technical: access controls, audit logs, encryption, transmission security

Be honest. An accurate analysis lists safeguards as they actually operate, not as the policy binder claims.

Step 5: Rate Likelihood and Impact

For each risk, estimate how likely it is and how harmful it would be. A simple low, medium and high scale is acceptable if used consistently. Combine the two into an overall risk level. For example, an unencrypted laptop that regularly leaves the building has a higher likelihood than a server in a locked, monitored room.

Step 6: Prioritize and Plan

The output of the analysis is a risk register: a list of risks, ratings and what you will do about each. Then create a risk management plan with specific actions, owners and target dates. HIPAA expects you to implement security measures sufficient to reduce risks to a reasonable and appropriate level, which means you decide, document and act. Not every risk needs to be eliminated, but accepted risks should be recorded with reasoning.

Step 7: Document Everything

HIPAA requires documentation to be retained for six years. Keep the analysis, supporting inventories, meeting notes, the risk register and evidence of remediation. If an auditor or investigator asks, being able to show the work matters.

Step 8: Repeat and Update

The Security Rule treats risk analysis as an ongoing process. Update it when circumstances change, such as a new EHR, a new building, a major vendor change or a security incident. Many organizations perform a full review annually and smaller updates in between.

Helpful Resources

You do not have to invent a method. HHS and the Office for Civil Rights have published guidance on the risk analysis requirement, and the Office of the National Coordinator offers a free Security Risk Assessment Tool aimed at smaller practices. NIST Special Publication 800-30 describes a more formal approach. The HHS 405(d) program's Health Industry Cybersecurity Practices also give practical, scaled guidance for small, medium and large organizations.

Common Mistakes

Treating a vulnerability scan as the entire risk analysis

Leaving out cloud tools, devices or vendors

Doing it once and filing it away

Writing findings but never assigning actions

Having IT complete it alone without input from clinical and administrative leaders

Where UnityCare IT Can Help

A good analysis combines technical knowledge with an understanding of how your facility actually operates. UnityCare IT assists long-term care and senior-living organizations with risk analyses, remediation planning and documentation. If yours is overdue, we can help you get a defensible one in place.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172