If an auditor or investigator asked to see one HIPAA document from your organization, the security risk analysis would be a strong candidate. The Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information (ePHI). Yet many small and mid-size providers have either never completed one or completed it years ago and filed it away.
A risk analysis is a structured look at where ePHI lives, what could go wrong, how likely it is, and how bad it would be. It is not the same as:
A vulnerability scan, which finds technical weaknesses but does not consider your people, processes or paper.
A generic checklist downloaded from the internet, which may not match your environment.
A policy binder, which says what you intend to do rather than what you actually do.
A scan or checklist can feed into a risk analysis, but it cannot replace one.
List every system and location that creates, receives, stores or transmits ePHI. For a long-term care operator that usually includes:
The electronic health record, such as PointClickCare, and any connected systems like pharmacy or lab interfaces
Email, eFax and scanned documents
Shared drives, laptops, tablets and phones
Backup systems and cloud services
Medical devices and nurse-call or telehealth platforms that store resident data
Paper records that are later scanned
Think broadly: ransomware, lost devices, misdirected faxes, former employees whose accounts are still active, vendor outages, power failures, snooping by staff, and unpatched software.
Document what is already in place: access controls, encryption, audit logs, backups, training, physical locks, and business associate agreements.
A simple scale of low, medium and high for each is fine for a smaller organization. The point is consistent, documented reasoning.
The output should be a risk register: a list of risks, their ratings, and a remediation plan with an owner and target date for each.
Write down the method, the findings and the decisions. Keep the document accessible.
The Security Rule requires risk analysis to be an ongoing process and does not set a single mandated interval. A common and defensible practice is a full review at least annually, plus an update whenever something significant changes. Triggers include:
Adopting a new EHR or major software
Opening a new building or acquiring a facility
Moving to a new cloud provider
A security incident or near miss
Major changes in how staff work, such as remote access
Someone with a clear view of both operations and technology should lead. That may be a compliance officer working with IT, or an outside party. Independence can help, because the person who built a system is not always the best person to critique it. Whoever does it, include clinical and business office staff in interviews, since they know how data really moves.
Treating the analysis as a one-time project
Leaving out paper, fax and personal devices
Producing findings but never assigning owners or dates
Confusing risk analysis with risk management; the second is acting on the first
Forgetting vendors who hold your data
You do not need a hundred-page report. A clear inventory, a documented method, a risk register and evidence that you are working through the top items goes a long way. Start with your most critical systems and expand each cycle. Keep earlier versions so you can show progress over time.
UnityCare IT helps healthcare organizations in Oklahoma, Texas and Arkansas build practical risk analyses, including the technical inventory and remediation tracking. If yours is out of date or you are not sure where to start, we can talk through a right-sized approach.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172