If there is one HIPAA requirement that administrators should understand well, it is the security risk analysis. The Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. Federal enforcement actions have repeatedly cited organizations for not having one, or for having one that was outdated or incomplete.
A risk analysis does not have to be mysterious. It is a structured way to ask what you have, what could go wrong and what you are doing about it.
The scope covers all electronic protected health information your organization creates, receives, maintains or transmits. Think beyond the EHR. Include:
Servers, workstations, laptops, tablets and phones
Email, eFax and messaging tools
Cloud services and hosted applications
Medical and monitoring devices that store or transmit resident data
Backups and portable media
Paper-to-electronic processes such as scanning
List each system that touches resident information, where the data lives and how it moves. A simple spreadsheet works: system name, owner, location, who has access, whether data is encrypted and which vendors are involved. Then sketch how information flows, for example from admission to EHR to pharmacy to billing. Gaps often appear here, such as a shared drive nobody remembered.
A threat is something that could cause harm, such as ransomware, a lost laptop, an employee snooping or a power outage. A vulnerability is a weakness that a threat could use, such as unpatched software, missing multi-factor authentication or an unlocked server closet. For each system, ask which threats are realistic and which weaknesses exist.
Document what is already in place. HIPAA groups safeguards into three categories:
Administrative: policies, training, access approval, incident procedures
Physical: locked rooms, device controls, visitor management
Technical: access controls, audit logs, encryption, transmission security
Be honest. An accurate analysis lists safeguards as they actually operate, not as the policy binder claims.
For each risk, estimate how likely it is and how harmful it would be. A simple low, medium and high scale is acceptable if used consistently. Combine the two into an overall risk level. For example, an unencrypted laptop that regularly leaves the building has a higher likelihood than a server in a locked, monitored room.
The output of the analysis is a risk register: a list of risks, ratings and what you will do about each. Then create a risk management plan with specific actions, owners and target dates. HIPAA expects you to implement security measures sufficient to reduce risks to a reasonable and appropriate level, which means you decide, document and act. Not every risk needs to be eliminated, but accepted risks should be recorded with reasoning.
HIPAA requires documentation to be retained for six years. Keep the analysis, supporting inventories, meeting notes, the risk register and evidence of remediation. If an auditor or investigator asks, being able to show the work matters.
The Security Rule treats risk analysis as an ongoing process. Update it when circumstances change, such as a new EHR, a new building, a major vendor change or a security incident. Many organizations perform a full review annually and smaller updates in between.
You do not have to invent a method. HHS and the Office for Civil Rights have published guidance on the risk analysis requirement, and the Office of the National Coordinator offers a free Security Risk Assessment Tool aimed at smaller practices. NIST Special Publication 800-30 describes a more formal approach. The HHS 405(d) program's Health Industry Cybersecurity Practices also give practical, scaled guidance for small, medium and large organizations.
Treating a vulnerability scan as the entire risk analysis
Leaving out cloud tools, devices or vendors
Doing it once and filing it away
Writing findings but never assigning actions
Having IT complete it alone without input from clinical and administrative leaders
A good analysis combines technical knowledge with an understanding of how your facility actually operates. UnityCare IT assists long-term care and senior-living organizations with risk analyses, remediation planning and documentation. If yours is overdue, we can help you get a defensible one in place.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172