How to Run a HIPAA Security Risk Analysis in Six Steps

If there is one HIPAA requirement every covered entity and business associate must meet, it is the security risk analysis. The HIPAA Security Rule requires an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. Federal enforcement announcements have repeatedly cited the lack of a proper risk analysis, so it is worth getting right.

Many small providers assume it requires an expensive consultant. It does not have to, though outside help is useful. Here is a practical six-step approach.

Step 1: Define the Scope

Electronic protected health information, or ePHI, lives in more places than most people realize. Define your scope to include every system that creates, receives, stores or transmits it.

The EHR and any other clinical software

Email, fax and eFax services

Billing and accounting systems

Laptops, tablets, phones and medication carts

Servers, backups and cloud storage

Printers and copiers with hard drives

Vendor systems that hold your data

Step 2: Inventory Assets and Data Flows

Create a list of the hardware, software and services in scope, and note who owns each one. Then sketch how information moves: from admission, to charting, to billing, to storage and to outside parties. Gaps in your inventory are gaps in your protection, and you cannot protect what you do not know you have.

Step 3: Identify Threats and Vulnerabilities

For each asset, ask what could go wrong and what weaknesses exist.

Threats

These include ransomware, phishing, lost or stolen devices, insider misuse, power failures, natural disasters and vendor breaches.

Vulnerabilities

These include unpatched software, weak or shared passwords, missing multi-factor authentication, unencrypted laptops, lack of staff training, and no tested backups.

Resources such as the HHS 405(d) Health Industry Cybersecurity Practices and the NIST guidance on risk assessments offer useful checklists.

Step 4: Evaluate Current Controls

Write down what you already do: firewalls, antivirus, encryption, access controls, training, policies and physical safeguards. Be honest about whether each one is actually in place and working, not merely written in a policy.

Step 5: Rate the Risk

For each threat and vulnerability pair, estimate how likely it is and how damaging it would be. A simple high, medium and low scale is acceptable. The goal is to rank risks so you can address the most serious first. For example, a facility might rate missing multi-factor authentication on email as high because of both likelihood and impact.

A simple table works well:

Risk description

Likelihood

Impact

Overall rating

Owner

Planned action and due date

Step 6: Document and Plan Remediation

The analysis is not complete until you record it and act on it. HIPAA requires documentation, and a risk analysis without a risk management plan leaves you exposed. Assign each high-rated risk to a named person with a deadline, and track progress.

Common Mistakes

Treating a vulnerability scan alone as a risk analysis. A scan is one input, not the whole thing.

Using a generic template with no facility-specific detail

Completing it once and never revisiting it

Ignoring vendors and cloud services

Keeping the findings away from leadership, who control the budget

How Often to Update

The Security Rule expects the analysis to be reviewed and updated periodically and when operations or the environment change, such as a new EHR, a new building, a merger or a significant security incident. Many organizations perform a full review annually and update it in between as needed.

Involve the Right People

IT staff alone cannot complete this. Include the administrator, the director of nursing, the privacy officer, human resources and anyone who manages vendors. They know how information is actually handled, which often differs from the official procedure.

UnityCare IT can walk your team through the process, gather the technical inventory and help turn the findings into a practical remediation plan you can show to leadership.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172