If there is one document regulators ask for first after a breach, it is your security risk analysis. The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. Many small organizations either have never done one, or did one years ago and filed it away.
A risk analysis is not a scan, and it is not a checklist of yes-or-no questions. It is a documented process of finding where resident information lives, what could go wrong, how likely and how damaging it would be, and what you are going to do about it. Here is a practical way to approach it.
Include every place electronic protected health information is created, received, stored or transmitted. For a care facility, that usually means:
Your EHR or EMR and any connected systems such as pharmacy, lab and billing
Servers, desktops, laptops, tablets and phones
Network equipment, Wi-Fi and remote access tools
Email, file shares and cloud storage
Fax, copiers and scanners that store images
Backups and removable media
Medical and monitoring devices that hold or transmit resident data
Vendor-hosted systems
If you manage multiple locations, include each of them.
Create a list of each system, who owns it, where it is located, and what kind of information it holds. Then note how data moves, such as from your EHR to a pharmacy or from a scanner to email. You cannot protect what you have not identified, and gaps in the inventory are a common finding in audits.
A threat is something that could cause harm, and a vulnerability is a weakness it could exploit. Consider the following categories:
Human: phishing, mistakes, lost devices, curious or malicious insiders
Technical: ransomware, unpatched software, weak passwords, misconfigured systems
Environmental: fire, flood, storms, power outages
Third-party: vendor outages, vendor breaches, expired support for old software
Information for this step can come from vulnerability scans, configuration reviews, staff interviews, incident history and vendor documentation.
For each risk, note what controls already exist. Group them as the Security Rule does:
Administrative: policies, training, access approval, incident procedures
Physical: locked server closets, workstation placement, device disposal
Technical: unique user IDs, encryption, audit logging, automatic logoff, multi-factor authentication
Keep the method simple and consistent. A common approach rates likelihood as low, medium or high, and impact as low, medium or high, then combines them into a risk level. For example, a facility with an unpatched server reachable from the internet might rate both as high. A document should explain why each rating was chosen so a future reviewer understands your reasoning.
The analysis is only half of the requirement. The Security Rule also expects you to implement security measures sufficient to reduce risks to a reasonable and appropriate level. For each significant risk, record:
The planned action, such as enabling MFA or replacing an end-of-life system
The person responsible
A target completion date
Estimated cost or effort
Status updates as work proceeds
Prioritize high risks first, and be honest if some will take time to fix. A documented plan with progress is far better than an empty folder.
Save your methodology, inventory, findings, ratings and plan. Keep the records for at least six years, in line with HIPAA's documentation retention requirement.
The analysis is not a one-time event. Review and update it:
At least annually
When you add or retire major systems
After a security incident
When you open a new location or change vendors
When there are significant changes to your environment or regulations
Treating a vulnerability scan as the entire risk analysis
Leaving out vendor-hosted systems and medical devices
Using a generic template without tailoring it to your facility
Identifying risks but never creating a plan
Forgetting to involve clinical and administrative leaders, not just IT
A well-run risk analysis takes time and technical knowledge, and an outside perspective often finds issues that internal teams overlook. UnityCare IT can guide you through the process, perform the technical assessment and help you turn the findings into a practical remediation plan.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034