Your HIPAA Security Risk Analysis: What It Is and How Often

If an auditor or investigator asked to see one HIPAA document from your organization, the security risk analysis would be a strong candidate. The Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information (ePHI). Yet many small and mid-size providers have either never completed one or completed it years ago and filed it away.

What a Risk Analysis Actually Is

A risk analysis is a structured look at where ePHI lives, what could go wrong, how likely it is, and how bad it would be. It is not the same as:

A vulnerability scan, which finds technical weaknesses but does not consider your people, processes or paper.

A generic checklist downloaded from the internet, which may not match your environment.

A policy binder, which says what you intend to do rather than what you actually do.

A scan or checklist can feed into a risk analysis, but it cannot replace one.

The Core Steps

1. Inventory where ePHI is

List every system and location that creates, receives, stores or transmits ePHI. For a long-term care operator that usually includes:

The electronic health record, such as PointClickCare, and any connected systems like pharmacy or lab interfaces

Email, eFax and scanned documents

Shared drives, laptops, tablets and phones

Backup systems and cloud services

Medical devices and nurse-call or telehealth platforms that store resident data

Paper records that are later scanned

2. Identify threats and vulnerabilities

Think broadly: ransomware, lost devices, misdirected faxes, former employees whose accounts are still active, vendor outages, power failures, snooping by staff, and unpatched software.

3. Assess current controls

Document what is already in place: access controls, encryption, audit logs, backups, training, physical locks, and business associate agreements.

4. Rate likelihood and impact

A simple scale of low, medium and high for each is fine for a smaller organization. The point is consistent, documented reasoning.

5. Prioritize and plan

The output should be a risk register: a list of risks, their ratings, and a remediation plan with an owner and target date for each.

6. Document and repeat

Write down the method, the findings and the decisions. Keep the document accessible.

How Often Should You Do It?

The Security Rule requires risk analysis to be an ongoing process and does not set a single mandated interval. A common and defensible practice is a full review at least annually, plus an update whenever something significant changes. Triggers include:

Adopting a new EHR or major software

Opening a new building or acquiring a facility

Moving to a new cloud provider

A security incident or near miss

Major changes in how staff work, such as remote access

Who Should Perform It?

Someone with a clear view of both operations and technology should lead. That may be a compliance officer working with IT, or an outside party. Independence can help, because the person who built a system is not always the best person to critique it. Whoever does it, include clinical and business office staff in interviews, since they know how data really moves.

Common Mistakes

Treating the analysis as a one-time project

Leaving out paper, fax and personal devices

Producing findings but never assigning owners or dates

Confusing risk analysis with risk management; the second is acting on the first

Forgetting vendors who hold your data

Making It Manageable

You do not need a hundred-page report. A clear inventory, a documented method, a risk register and evidence that you are working through the top items goes a long way. Start with your most critical systems and expand each cycle. Keep earlier versions so you can show progress over time.

How UnityCare IT Can Help

UnityCare IT helps healthcare organizations in Oklahoma, Texas and Arkansas build practical risk analyses, including the technical inventory and remediation tracking. If yours is out of date or you are not sure where to start, we can talk through a right-sized approach.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172