How to Conduct a HIPAA Security Risk Analysis Step by Step

If you could do only one thing to strengthen your HIPAA program, a thorough security risk analysis would be a strong candidate. The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. It is also a common gap when regulators review a breach, because many organizations have never completed one, or completed one years ago and filed it away.

Here is a practical way to do it without turning it into a never-ending project.

Step 1: Define the scope

The analysis must cover all electronic PHI your organization creates, receives, maintains or transmits. That is broader than the EHR. Start a list:

Clinical systems such as your EHR, pharmacy and lab interfaces

Computers, laptops, tablets and phones used by staff

Servers, cloud services and backup copies

Email, eFax and messaging tools

Medical and network-connected devices

Paper-to-digital workflows such as scanners and copiers with hard drives

Vendors and business associates that hold or access your data

Step 2: Map where information lives and moves

For each system, note how PHI enters, where it is stored, who can reach it and where it goes next. A simple diagram or spreadsheet is enough. You will often discover surprises, such as spreadsheets of resident information on a shared drive or a staff member forwarding documents to a personal account.

Step 3: Identify threats and vulnerabilities

Think broadly. Threats include ransomware, stolen credentials, lost devices, misdirected email, power failure, natural events and insider misuse, whether intentional or not. Vulnerabilities are the weaknesses that let those threats succeed:

Unpatched or unsupported operating systems

Accounts without multi-factor authentication

Shared logins

Unencrypted laptops or backups

Vendors with unmanaged remote access

Staff who have never had security training

Step 4: Assess current controls

Record what you already do: encryption, access controls, audit logging, backups, training, physical safeguards, incident procedures. Be honest about whether each control is actually in place and working, not only written in a policy.

Step 5: Rate likelihood and impact

For each risk, estimate how likely it is and how serious the effect would be. A simple high, medium and low scale is acceptable. The goal is to rank risks so you can address the important ones first, not to produce precise numbers. Guidance from NIST, including Special Publication 800-30, and the HHS Office for Civil Rights offer approaches you can adapt.

Step 6: Build a risk management plan

The analysis is only useful if it leads to action. For each higher-rated risk, document:

The action you will take

Who is responsible

The target date

The budget, if needed

How you will verify it is done

Some risks you will accept, and that is allowed when it is a documented decision made by leadership.

Step 7: Document and keep it current

Keep the written analysis, supporting inventories and your plan. Review and update it when something significant changes, such as a new EHR, a new location, a major vendor change or a security incident, and at least annually as a routine. Under current rules, documentation is generally retained for six years.

Common mistakes

Treating a vulnerability scan or a compliance checklist as a risk analysis. These can feed into it, but they are not the same thing.

Leaving out vendors, mobile devices or cloud services

Completing it once and never updating it

Producing a report without a plan or owners

Having IT do it alone, without input from clinical and administrative leaders who know how information is actually used

In January 2025, HHS published a proposed update to the Security Rule that would, among other things, make requirements such as asset inventories and network maps more explicit. It is a proposal and not final, but building those inventories now is sound practice either way.

Getting help

UnityCare IT works with senior-living and clinic operators to complete risk analyses that are practical, documented and tied to a real remediation plan. If yours is overdue or you are not sure it would hold up to review, we can help you assess where you stand.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172