How to Run a HIPAA Security Risk Analysis in Five Steps

If there is one HIPAA requirement that appears again and again in enforcement actions by the HHS Office for Civil Rights (OCR), it is the failure to conduct an accurate and thorough risk analysis. The Security Rule requires covered entities and business associates to assess potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information (ePHI).

A risk analysis is not a one-time document that sits in a binder. It is a living assessment that should be revisited when systems, vendors or operations change. Here is a practical five-step approach.

Step 1: Inventory Where ePHI Lives

You cannot protect what you have not listed. Make a plain inventory that includes:

Your EHR or electronic health record and any related portals

Servers, workstations, laptops, tablets and mobile phones

Email, text messaging and eFax services

Cloud storage and file sharing

Backup systems and offsite copies

Medical devices that store or transmit resident data

Paper that gets scanned, and the scanners and copiers that scan it

Vendors and business associates who hold or access your data

Walk the building. Facilities often discover an old computer or a shared spreadsheet that nobody had on the list.

Step 2: Identify Threats and Vulnerabilities

A threat is something that could cause harm, such as ransomware, a lost laptop, a curious employee, a power failure or a flood. A vulnerability is a weakness that a threat could exploit, such as unpatched software, shared passwords or no encryption.

For each system on your inventory, ask what could go wrong and what weakness would let it happen. Use resources such as the Security Rule itself, HHS guidance and NIST publications for ideas.

Step 3: Evaluate Current Controls

Document what you already have. Do you use multifactor authentication? Are laptops encrypted? Are backups tested? Do you have written policies, and do staff follow them? Controls can be technical, such as encryption, physical, such as locked server rooms, or administrative, such as training and sanctions policies.

Be honest. A control that exists on paper but is not practiced is not a control.

Step 4: Rate Likelihood and Impact

For each risk, estimate how likely it is and how serious the impact would be. A simple scale of low, medium and high is enough for most small organizations. The result is a ranked list. A likely, high-impact risk, such as an unsupported operating system on a computer with resident data, rises to the top.

OCR does not prescribe a specific method. The HHS guidance on risk analysis and the NIST publication SP 800-30 describe accepted approaches.

Step 5: Document and Create a Risk Management Plan

Write down findings, then decide what to do about each risk: reduce it, transfer it through insurance or a vendor, accept it, or avoid it. Assign an owner and a target date to each action. This plan is the second required piece, called risk management, and it is what turns analysis into improvement.

Keep the analysis, the plan and evidence that you followed through. Review at least annually and whenever you add a major system, change vendors, open a new location or experience an incident.

Common Mistakes

Buying a compliance checklist or software tool and calling it an analysis without examining your own environment

Excluding mobile devices, medical devices or vendors

Doing the analysis once and never updating it

Finding risks and doing nothing with them

Leaving it to one person without involving clinical, administrative and IT perspectives

Who Should Be in the Room

Include the administrator or compliance officer, the director of nursing or a clinical leader, whoever manages IT, and someone from the business office. Clinical staff understand how work really happens, which often differs from written policy.

How UnityCare IT Helps

UnityCare IT can support your risk analysis by inventorying systems, testing technical controls and helping you build a prioritized remediation plan. We are not a law firm and do not provide legal advice, but we can supply the technical detail that makes your analysis accurate and useful.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034