If there is one HIPAA requirement every covered entity and business associate must meet, it is the security risk analysis. The HIPAA Security Rule requires an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. Federal enforcement announcements have repeatedly cited the lack of a proper risk analysis, so it is worth getting right.
Many small providers assume it requires an expensive consultant. It does not have to, though outside help is useful. Here is a practical six-step approach.
Electronic protected health information, or ePHI, lives in more places than most people realize. Define your scope to include every system that creates, receives, stores or transmits it.
The EHR and any other clinical software
Email, fax and eFax services
Billing and accounting systems
Laptops, tablets, phones and medication carts
Servers, backups and cloud storage
Printers and copiers with hard drives
Vendor systems that hold your data
Create a list of the hardware, software and services in scope, and note who owns each one. Then sketch how information moves: from admission, to charting, to billing, to storage and to outside parties. Gaps in your inventory are gaps in your protection, and you cannot protect what you do not know you have.
For each asset, ask what could go wrong and what weaknesses exist.
These include ransomware, phishing, lost or stolen devices, insider misuse, power failures, natural disasters and vendor breaches.
These include unpatched software, weak or shared passwords, missing multi-factor authentication, unencrypted laptops, lack of staff training, and no tested backups.
Resources such as the HHS 405(d) Health Industry Cybersecurity Practices and the NIST guidance on risk assessments offer useful checklists.
Write down what you already do: firewalls, antivirus, encryption, access controls, training, policies and physical safeguards. Be honest about whether each one is actually in place and working, not merely written in a policy.
For each threat and vulnerability pair, estimate how likely it is and how damaging it would be. A simple high, medium and low scale is acceptable. The goal is to rank risks so you can address the most serious first. For example, a facility might rate missing multi-factor authentication on email as high because of both likelihood and impact.
A simple table works well:
Risk description
Likelihood
Impact
Overall rating
Owner
Planned action and due date
The analysis is not complete until you record it and act on it. HIPAA requires documentation, and a risk analysis without a risk management plan leaves you exposed. Assign each high-rated risk to a named person with a deadline, and track progress.
Treating a vulnerability scan alone as a risk analysis. A scan is one input, not the whole thing.
Using a generic template with no facility-specific detail
Completing it once and never revisiting it
Ignoring vendors and cloud services
Keeping the findings away from leadership, who control the budget
The Security Rule expects the analysis to be reviewed and updated periodically and when operations or the environment change, such as a new EHR, a new building, a merger or a significant security incident. Many organizations perform a full review annually and update it in between as needed.
IT staff alone cannot complete this. Include the administrator, the director of nursing, the privacy officer, human resources and anyone who manages vendors. They know how information is actually handled, which often differs from the official procedure.
UnityCare IT can walk your team through the process, gather the technical inventory and help turn the findings into a practical remediation plan you can show to leadership.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172