If you could do only one thing to strengthen your HIPAA compliance, it would be a thorough security risk analysis. The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. It is also one of the first documents investigators request after a breach.
Many small organizations treat it as a mysterious task. It is really a structured way of asking where your data is, what could go wrong and what you will do about it.
The analysis must cover all electronic PHI your organization creates, receives, maintains or transmits. That includes obvious places and easy-to-miss ones:
The EHR and any connected systems.
Email, shared drives and cloud storage.
Laptops, tablets, phones and removable media.
Fax and eFax systems, scanners and copiers with hard drives.
Backups and archives.
Vendor-hosted systems.
Paper that is scanned or entered into electronic systems.
List each system and note what PHI it holds, where the data comes from and where it goes. A simple diagram showing data moving between your EHR, pharmacy, labs, billing company and family portals helps reveal exposure points. Include who administers each system.
Think about what could harm each system. Threats include ransomware, phishing, lost devices, insider misuse, natural disasters, power failure and vendor outages. Vulnerabilities are the weaknesses that let threats succeed, such as:
No multi-factor authentication.
Unpatched software.
Shared logins.
Unencrypted laptops.
Staff who have not been trained.
Lack of tested backups.
Former employees with active accounts.
Record what safeguards already exist, across the Security Rule's three categories:
Administrative: policies, training, sanctions, incident procedures, contingency planning.
Physical: facility access, workstation placement, device disposal.
Technical: access controls, audit logs, encryption, transmission security.
Be honest. A control that exists on paper but is not followed does not count.
For each risk, estimate how likely it is and how severe the consequences would be. You do not need complex math. A simple scale of low, medium and high for both factors works well. Combine them to find your highest risks. A lost unencrypted laptop with resident data, for example, might be moderately likely and highly impactful.
The analysis is only useful if it leads to action. For each significant risk, decide whether to reduce it, transfer it, accept it or avoid it, and write down the details:
The action to be taken.
The person responsible.
A target date.
The budget or resources needed.
This connects to the Security Rule's separate requirement for risk management, which requires implementing security measures sufficient to reduce risks to a reasonable and appropriate level.
Write down the scope, methods, findings and decisions. Documentation should be retained for six years under HIPAA. Keep dated versions so you can show how your analysis evolved.
The analysis is not a one-time task. Update it when something significant changes, such as:
A new EHR, cloud service or major software.
A merger, new building or new location.
A security incident.
A change in how staff work, like remote access or mobile devices.
Many organizations also repeat it at least annually.
HHS and the Office for Civil Rights offer guidance on the risk analysis requirement. The Office of the National Coordinator for Health IT has also published a Security Risk Assessment Tool aimed at smaller practices. The NIST Cybersecurity Framework 2.0 and the HHS 405(d) HICP publication can help you organize controls and priorities.
Buying a tool or running a vulnerability scan and calling it a risk analysis. Scans are inputs, not the whole assessment.
Ignoring paper, vendors or mobile devices.
Producing a report that is never acted on.
Letting the analysis go years without an update.
UnityCare IT helps healthcare and senior-living organizations perform and document security risk analyses and turn the results into a practical action plan. If your last analysis is out of date, we can help you refresh it.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172