How to Run a HIPAA Security Risk Analysis Step by Step

If there is one document regulators ask for first after a breach, it is your security risk analysis. The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. Many small organizations either have never done one, or did one years ago and filed it away.

A risk analysis is not a scan, and it is not a checklist of yes-or-no questions. It is a documented process of finding where resident information lives, what could go wrong, how likely and how damaging it would be, and what you are going to do about it. Here is a practical way to approach it.

Step 1: Define the Scope

Include every place electronic protected health information is created, received, stored or transmitted. For a care facility, that usually means:

Your EHR or EMR and any connected systems such as pharmacy, lab and billing

Servers, desktops, laptops, tablets and phones

Network equipment, Wi-Fi and remote access tools

Email, file shares and cloud storage

Fax, copiers and scanners that store images

Backups and removable media

Medical and monitoring devices that hold or transmit resident data

Vendor-hosted systems

If you manage multiple locations, include each of them.

Step 2: Inventory Your Assets and Data Flows

Create a list of each system, who owns it, where it is located, and what kind of information it holds. Then note how data moves, such as from your EHR to a pharmacy or from a scanner to email. You cannot protect what you have not identified, and gaps in the inventory are a common finding in audits.

Step 3: Identify Threats and Vulnerabilities

A threat is something that could cause harm, and a vulnerability is a weakness it could exploit. Consider the following categories:

Human: phishing, mistakes, lost devices, curious or malicious insiders

Technical: ransomware, unpatched software, weak passwords, misconfigured systems

Environmental: fire, flood, storms, power outages

Third-party: vendor outages, vendor breaches, expired support for old software

Information for this step can come from vulnerability scans, configuration reviews, staff interviews, incident history and vendor documentation.

Step 4: Review Current Safeguards

For each risk, note what controls already exist. Group them as the Security Rule does:

Administrative: policies, training, access approval, incident procedures

Physical: locked server closets, workstation placement, device disposal

Technical: unique user IDs, encryption, audit logging, automatic logoff, multi-factor authentication

Step 5: Rate Likelihood and Impact

Keep the method simple and consistent. A common approach rates likelihood as low, medium or high, and impact as low, medium or high, then combines them into a risk level. For example, a facility with an unpatched server reachable from the internet might rate both as high. A document should explain why each rating was chosen so a future reviewer understands your reasoning.

Step 6: Build a Risk Management Plan

The analysis is only half of the requirement. The Security Rule also expects you to implement security measures sufficient to reduce risks to a reasonable and appropriate level. For each significant risk, record:

The planned action, such as enabling MFA or replacing an end-of-life system

The person responsible

A target completion date

Estimated cost or effort

Status updates as work proceeds

Prioritize high risks first, and be honest if some will take time to fix. A documented plan with progress is far better than an empty folder.

Step 7: Document Everything

Save your methodology, inventory, findings, ratings and plan. Keep the records for at least six years, in line with HIPAA's documentation retention requirement.

Step 8: Keep It Current

The analysis is not a one-time event. Review and update it:

At least annually

When you add or retire major systems

After a security incident

When you open a new location or change vendors

When there are significant changes to your environment or regulations

Common Mistakes

Treating a vulnerability scan as the entire risk analysis

Leaving out vendor-hosted systems and medical devices

Using a generic template without tailoring it to your facility

Identifying risks but never creating a plan

Forgetting to involve clinical and administrative leaders, not just IT

Support Available

A well-run risk analysis takes time and technical knowledge, and an outside perspective often finds issues that internal teams overlook. UnityCare IT can guide you through the process, perform the technical assessment and help you turn the findings into a practical remediation plan.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034