If there is one HIPAA document that regulators ask about again and again, it is the security risk analysis. The Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. Many organizations believe they have done one, only to discover that what they have is a vendor questionnaire or a compliance checklist.
This post explains what a real risk analysis includes, how it differs from related activities, and what to keep on file so you can demonstrate your effort.
A risk analysis identifies where electronic protected health information (ePHI) lives, what could threaten it, how likely those threats are, and how severe the impact would be. It leads to a prioritized list of actions.
It is not:
A penetration test or vulnerability scan alone, though both can feed into it
A yes-or-no checklist with no analysis behind the answers
A one-time project that is filed and forgotten
Something you can simply buy as a template without tailoring it to your operation
List every system, device and location that creates, receives, stores or transmits ePHI. For a long-term care operator this typically includes the EHR or EMR, the nurse call and pharmacy interfaces, email, eFax, shared drives, laptops, tablets, mobile phones, backup systems, and cloud services. Do not forget copiers, voicemail systems and legacy servers.
For each system, consider realistic threats such as ransomware, phishing, lost devices, insider misuse, vendor outages, power failure and natural events. Then identify the weaknesses that make those threats possible, such as missing patches, shared passwords, or untested backups.
Document what is already in place, including technical safeguards, policies, training and physical protections.
Rate each risk using a simple, consistent scale such as low, medium and high. A clear method matters more than a complicated one.
Combine likelihood and impact to rank the risks. This ranking drives your remediation plan.
The Security Rule expects the risk analysis to be an ongoing process. Practical triggers for an update include:
At least once a year, on a schedule you set
When you adopt a new system, such as a new EHR module or telehealth tool
After a security incident or near miss
When you open a new location, merge, or change vendors
After major changes to your network or remote work arrangements
A risk analysis without a risk management plan is only half of the requirement. For each high-priority item, record the decision you made: reduce the risk, accept it, transfer it, or avoid it. Assign an owner, a target date and a status. Review progress quarterly and update the document as items close.
Typical remediation items for smaller operators include enabling multi-factor authentication, encrypting laptops, replacing unsupported operating systems, improving backup testing and tightening vendor agreements.
If an auditor or investigator asks, you should be able to produce:
The current risk analysis and prior versions
The system and data inventory used to build it
The risk management plan with owners and dates
Evidence that you acted on the findings, such as change tickets or invoices
Meeting notes showing leadership reviewed the results
HIPAA requires you to keep required documentation for six years from the date of creation or the date it was last in effect.
Smaller organizations often struggle to find the time and expertise to do this well. The HHS Office for Civil Rights and ONC have published guidance and a free Security Risk Assessment Tool that can serve as a starting point. UnityCare IT can also help you build a risk analysis tailored to your facility, translate the results into a plain-English action plan, and support the remediation work. Reach out if you would like a hand getting started.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172