How to Run a HIPAA Security Risk Analysis, Step by Step

If there is one HIPAA document regulators ask for again and again, it is the security risk analysis. The Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. Many small and mid-size providers either have not done one or completed one years ago and never updated it.

This is a practical outline of how to do one well.

What a risk analysis is, and is not

A risk analysis is a documented process of identifying where ePHI lives, what could go wrong, how likely it is and how serious the impact would be, and what you are doing about it. It is not a vulnerability scan alone, a policy binder or a checklist you tick once. A scan is one input. The analysis looks at people, processes and technology together.

Step 1: Define the scope

Start by deciding what is included. Be broad. Cover every location, every system and every vendor that creates, receives, maintains or transmits ePHI.

Step 2: Inventory where ePHI lives

Make a list of:

Servers, workstations, laptops, tablets and phones.

Cloud services such as your EMR, email, file sharing and eFax.

Medical and network-connected devices.

Backup media and storage, including old devices and copiers with hard drives.

Paper that is scanned or faxed into systems.

Vendors and business associates with access.

Trace the flow: how information comes in, where it is stored, who uses it and where it goes.

Step 3: Identify threats and vulnerabilities

For each asset or system, ask what could realistically go wrong. Examples include:

Phishing leading to account compromise.

Ransomware.

Lost or stolen devices.

Snooping by employees.

Unpatched software.

Weak or shared passwords.

Power loss, fire, flood or severe weather, which Oklahoma and Texas facilities know well.

A vendor failure or breach.

Step 4: Review current safeguards

Document what is already in place: access controls, encryption, multi-factor authentication, backups, logging, training, physical security and policies. Be honest. The goal is accuracy, not a perfect score.

Step 5: Rate likelihood and impact

Assign each risk a likelihood (low, medium, high) and an impact (low, medium, high). A simple matrix works. Combine them into an overall risk rating. A consistent method matters more than a complicated one.

Step 6: Build a risk management plan

For each significant risk, decide what to do:

Reduce it with a new control.

Transfer part of it, for instance through insurance or a vendor.

Accept it, with documented reasoning from leadership.

Avoid it by stopping the risky activity.

Assign an owner, a target date and a budget estimate. The Security Rule separately requires you to implement security measures that reduce risks to a reasonable and appropriate level, so the analysis should lead to action.

Step 7: Document everything

Keep the written analysis, the inventory, your risk ratings, the plan and any evidence such as screenshots or reports. HIPAA documentation requirements generally call for retaining records for six years.

Step 8: Review and update

The risk analysis is not a one-time project. Update it when you:

Adopt a new system or vendor.

Open a new location or renovate.

Experience a security incident.

Change your network or move to the cloud.

Many organizations also schedule a full review annually.

Common mistakes

Confusing a vendor-supplied scan with a full analysis.

Leaving out cloud services, personal devices or business associates.

Having no remediation plan, so the same findings reappear next year.

Letting the document sit unsigned with no leadership involvement.

The HHS Office for Civil Rights and the Office of the National Coordinator have published guidance and a free Security Risk Assessment Tool that can help smaller practices structure the work.

How UnityCare IT can help

UnityCare IT helps healthcare and senior living organizations conduct and document risk analyses, translate the findings into a prioritized plan and carry out the technical fixes. If your last assessment is out of date, we can help you start fresh.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034