HIPAA Security Risk Analysis: What Auditors Expect to See

If there is one HIPAA document that regulators ask about again and again, it is the security risk analysis. The Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. Many organizations believe they have done one, only to discover that what they have is a vendor questionnaire or a compliance checklist.

This post explains what a real risk analysis includes, how it differs from related activities, and what to keep on file so you can demonstrate your effort.

What a risk analysis is, and is not

A risk analysis identifies where electronic protected health information (ePHI) lives, what could threaten it, how likely those threats are, and how severe the impact would be. It leads to a prioritized list of actions.

It is not:

A penetration test or vulnerability scan alone, though both can feed into it

A yes-or-no checklist with no analysis behind the answers

A one-time project that is filed and forgotten

Something you can simply buy as a template without tailoring it to your operation

The core elements

1. Scope and inventory

List every system, device and location that creates, receives, stores or transmits ePHI. For a long-term care operator this typically includes the EHR or EMR, the nurse call and pharmacy interfaces, email, eFax, shared drives, laptops, tablets, mobile phones, backup systems, and cloud services. Do not forget copiers, voicemail systems and legacy servers.

2. Threats and vulnerabilities

For each system, consider realistic threats such as ransomware, phishing, lost devices, insider misuse, vendor outages, power failure and natural events. Then identify the weaknesses that make those threats possible, such as missing patches, shared passwords, or untested backups.

3. Current controls

Document what is already in place, including technical safeguards, policies, training and physical protections.

4. Likelihood and impact

Rate each risk using a simple, consistent scale such as low, medium and high. A clear method matters more than a complicated one.

5. Risk level and priority

Combine likelihood and impact to rank the risks. This ranking drives your remediation plan.

How often should you update it

The Security Rule expects the risk analysis to be an ongoing process. Practical triggers for an update include:

At least once a year, on a schedule you set

When you adopt a new system, such as a new EHR module or telehealth tool

After a security incident or near miss

When you open a new location, merge, or change vendors

After major changes to your network or remote work arrangements

Turning findings into action

A risk analysis without a risk management plan is only half of the requirement. For each high-priority item, record the decision you made: reduce the risk, accept it, transfer it, or avoid it. Assign an owner, a target date and a status. Review progress quarterly and update the document as items close.

Typical remediation items for smaller operators include enabling multi-factor authentication, encrypting laptops, replacing unsupported operating systems, improving backup testing and tightening vendor agreements.

Documentation to keep

If an auditor or investigator asks, you should be able to produce:

The current risk analysis and prior versions

The system and data inventory used to build it

The risk management plan with owners and dates

Evidence that you acted on the findings, such as change tickets or invoices

Meeting notes showing leadership reviewed the results

HIPAA requires you to keep required documentation for six years from the date of creation or the date it was last in effect.

Getting help

Smaller organizations often struggle to find the time and expertise to do this well. The HHS Office for Civil Rights and ONC have published guidance and a free Security Risk Assessment Tool that can serve as a starting point. UnityCare IT can also help you build a risk analysis tailored to your facility, translate the results into a plain-English action plan, and support the remediation work. Reach out if you would like a hand getting started.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172