If you could do only one thing to strengthen your HIPAA program, a thorough security risk analysis would be a strong candidate. The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. It is also a common gap when regulators review a breach, because many organizations have never completed one, or completed one years ago and filed it away.
Here is a practical way to do it without turning it into a never-ending project.
The analysis must cover all electronic PHI your organization creates, receives, maintains or transmits. That is broader than the EHR. Start a list:
Clinical systems such as your EHR, pharmacy and lab interfaces
Computers, laptops, tablets and phones used by staff
Servers, cloud services and backup copies
Email, eFax and messaging tools
Medical and network-connected devices
Paper-to-digital workflows such as scanners and copiers with hard drives
Vendors and business associates that hold or access your data
For each system, note how PHI enters, where it is stored, who can reach it and where it goes next. A simple diagram or spreadsheet is enough. You will often discover surprises, such as spreadsheets of resident information on a shared drive or a staff member forwarding documents to a personal account.
Think broadly. Threats include ransomware, stolen credentials, lost devices, misdirected email, power failure, natural events and insider misuse, whether intentional or not. Vulnerabilities are the weaknesses that let those threats succeed:
Unpatched or unsupported operating systems
Accounts without multi-factor authentication
Shared logins
Unencrypted laptops or backups
Vendors with unmanaged remote access
Staff who have never had security training
Record what you already do: encryption, access controls, audit logging, backups, training, physical safeguards, incident procedures. Be honest about whether each control is actually in place and working, not only written in a policy.
For each risk, estimate how likely it is and how serious the effect would be. A simple high, medium and low scale is acceptable. The goal is to rank risks so you can address the important ones first, not to produce precise numbers. Guidance from NIST, including Special Publication 800-30, and the HHS Office for Civil Rights offer approaches you can adapt.
The analysis is only useful if it leads to action. For each higher-rated risk, document:
The action you will take
Who is responsible
The target date
The budget, if needed
How you will verify it is done
Some risks you will accept, and that is allowed when it is a documented decision made by leadership.
Keep the written analysis, supporting inventories and your plan. Review and update it when something significant changes, such as a new EHR, a new location, a major vendor change or a security incident, and at least annually as a routine. Under current rules, documentation is generally retained for six years.
Treating a vulnerability scan or a compliance checklist as a risk analysis. These can feed into it, but they are not the same thing.
Leaving out vendors, mobile devices or cloud services
Completing it once and never updating it
Producing a report without a plan or owners
Having IT do it alone, without input from clinical and administrative leaders who know how information is actually used
In January 2025, HHS published a proposed update to the Security Rule that would, among other things, make requirements such as asset inventories and network maps more explicit. It is a proposal and not final, but building those inventories now is sound practice either way.
UnityCare IT works with senior-living and clinic operators to complete risk analyses that are practical, documented and tied to a real remediation plan. If yours is overdue or you are not sure it would hold up to review, we can help you assess where you stand.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172