How to Conduct a HIPAA Security Risk Analysis, Step by Step

If you could do only one thing to strengthen your HIPAA compliance, it would be a thorough security risk analysis. The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. It is also one of the first documents investigators request after a breach.

Many small organizations treat it as a mysterious task. It is really a structured way of asking where your data is, what could go wrong and what you will do about it.

Step 1: Define the scope

The analysis must cover all electronic PHI your organization creates, receives, maintains or transmits. That includes obvious places and easy-to-miss ones:

The EHR and any connected systems.

Email, shared drives and cloud storage.

Laptops, tablets, phones and removable media.

Fax and eFax systems, scanners and copiers with hard drives.

Backups and archives.

Vendor-hosted systems.

Paper that is scanned or entered into electronic systems.

Step 2: Inventory systems and data flows

List each system and note what PHI it holds, where the data comes from and where it goes. A simple diagram showing data moving between your EHR, pharmacy, labs, billing company and family portals helps reveal exposure points. Include who administers each system.

Step 3: Identify threats and vulnerabilities

Think about what could harm each system. Threats include ransomware, phishing, lost devices, insider misuse, natural disasters, power failure and vendor outages. Vulnerabilities are the weaknesses that let threats succeed, such as:

No multi-factor authentication.

Unpatched software.

Shared logins.

Unencrypted laptops.

Staff who have not been trained.

Lack of tested backups.

Former employees with active accounts.

Step 4: Assess current controls

Record what safeguards already exist, across the Security Rule's three categories:

Administrative: policies, training, sanctions, incident procedures, contingency planning.

Physical: facility access, workstation placement, device disposal.

Technical: access controls, audit logs, encryption, transmission security.

Be honest. A control that exists on paper but is not followed does not count.

Step 5: Rate likelihood and impact

For each risk, estimate how likely it is and how severe the consequences would be. You do not need complex math. A simple scale of low, medium and high for both factors works well. Combine them to find your highest risks. A lost unencrypted laptop with resident data, for example, might be moderately likely and highly impactful.

Step 6: Build a risk management plan

The analysis is only useful if it leads to action. For each significant risk, decide whether to reduce it, transfer it, accept it or avoid it, and write down the details:

The action to be taken.

The person responsible.

A target date.

The budget or resources needed.

This connects to the Security Rule's separate requirement for risk management, which requires implementing security measures sufficient to reduce risks to a reasonable and appropriate level.

Step 7: Document everything

Write down the scope, methods, findings and decisions. Documentation should be retained for six years under HIPAA. Keep dated versions so you can show how your analysis evolved.

Step 8: Review and update

The analysis is not a one-time task. Update it when something significant changes, such as:

A new EHR, cloud service or major software.

A merger, new building or new location.

A security incident.

A change in how staff work, like remote access or mobile devices.

Many organizations also repeat it at least annually.

Useful tools and references

HHS and the Office for Civil Rights offer guidance on the risk analysis requirement. The Office of the National Coordinator for Health IT has also published a Security Risk Assessment Tool aimed at smaller practices. The NIST Cybersecurity Framework 2.0 and the HHS 405(d) HICP publication can help you organize controls and priorities.

Common mistakes

Buying a tool or running a vulnerability scan and calling it a risk analysis. Scans are inputs, not the whole assessment.

Ignoring paper, vendors or mobile devices.

Producing a report that is never acted on.

Letting the analysis go years without an update.

How UnityCare IT can help

UnityCare IT helps healthcare and senior-living organizations perform and document security risk analyses and turn the results into a practical action plan. If your last analysis is out of date, we can help you refresh it.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172