If there is one HIPAA requirement that appears again and again in enforcement actions by the HHS Office for Civil Rights (OCR), it is the failure to conduct an accurate and thorough risk analysis. The Security Rule requires covered entities and business associates to assess potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information (ePHI).
A risk analysis is not a one-time document that sits in a binder. It is a living assessment that should be revisited when systems, vendors or operations change. Here is a practical five-step approach.
You cannot protect what you have not listed. Make a plain inventory that includes:
Your EHR or electronic health record and any related portals
Servers, workstations, laptops, tablets and mobile phones
Email, text messaging and eFax services
Cloud storage and file sharing
Backup systems and offsite copies
Medical devices that store or transmit resident data
Paper that gets scanned, and the scanners and copiers that scan it
Vendors and business associates who hold or access your data
Walk the building. Facilities often discover an old computer or a shared spreadsheet that nobody had on the list.
A threat is something that could cause harm, such as ransomware, a lost laptop, a curious employee, a power failure or a flood. A vulnerability is a weakness that a threat could exploit, such as unpatched software, shared passwords or no encryption.
For each system on your inventory, ask what could go wrong and what weakness would let it happen. Use resources such as the Security Rule itself, HHS guidance and NIST publications for ideas.
Document what you already have. Do you use multifactor authentication? Are laptops encrypted? Are backups tested? Do you have written policies, and do staff follow them? Controls can be technical, such as encryption, physical, such as locked server rooms, or administrative, such as training and sanctions policies.
Be honest. A control that exists on paper but is not practiced is not a control.
For each risk, estimate how likely it is and how serious the impact would be. A simple scale of low, medium and high is enough for most small organizations. The result is a ranked list. A likely, high-impact risk, such as an unsupported operating system on a computer with resident data, rises to the top.
OCR does not prescribe a specific method. The HHS guidance on risk analysis and the NIST publication SP 800-30 describe accepted approaches.
Write down findings, then decide what to do about each risk: reduce it, transfer it through insurance or a vendor, accept it, or avoid it. Assign an owner and a target date to each action. This plan is the second required piece, called risk management, and it is what turns analysis into improvement.
Keep the analysis, the plan and evidence that you followed through. Review at least annually and whenever you add a major system, change vendors, open a new location or experience an incident.
Buying a compliance checklist or software tool and calling it an analysis without examining your own environment
Excluding mobile devices, medical devices or vendors
Doing the analysis once and never updating it
Finding risks and doing nothing with them
Leaving it to one person without involving clinical, administrative and IT perspectives
Include the administrator or compliance officer, the director of nursing or a clinical leader, whoever manages IT, and someone from the business office. Clinical staff understand how work really happens, which often differs from written policy.
UnityCare IT can support your risk analysis by inventorying systems, testing technical controls and helping you build a prioritized remediation plan. We are not a law firm and do not provide legal advice, but we can supply the technical detail that makes your analysis accurate and useful.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034