If there is one HIPAA document that regulators ask about again and again, it is the security risk analysis. The Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. Yet many organizations either have not done one, did one years ago, or bought a template and filled it in once.
A risk analysis does not have to be mysterious. It is a structured way of asking: where is our resident and patient data, what could go wrong, and what are we doing about it?
A risk analysis is a documented assessment. It is not simply a vulnerability scan, a policy binder, or a checklist of yes and no answers. A scan is one input. Policies are one control. The analysis ties them together and evaluates likelihood and impact.
HHS and its Office for Civil Rights have published guidance on what a risk analysis should include, and the NIST SP 800-30 publication is a commonly used method. You do not need to follow it word for word, but your approach should be consistent and documented.
You cannot protect what you have not listed. Walk through every place electronic protected health information is created, received, stored or transmitted:
The electronic health record and related applications
Workstations, laptops, tablets and medication carts
Servers, shared drives and cloud storage
Email, eFax and messaging tools
Phones and personal devices used for work
Backups and removable media
Vendors and business associates who handle your data
Medical and connected devices that store or transmit information
Include who owns each system and who has access.
For each system, ask what could go wrong. Think broadly:
Ransomware and phishing
Lost or stolen devices
Staff snooping or mistakes
Vendor outage or breach
Power loss, fire, flood or tornado, which matters in Oklahoma and Texas
Unpatched or unsupported software
Weak passwords or missing multi-factor authentication
Then note existing weaknesses, such as an old server, shared logins, or missing encryption.
List what you already have in place. Examples include encryption, access controls, audit logging, backups, endpoint protection, firewalls, training, physical locks and sanctions policies. Be honest about which controls are actually working and which exist only on paper.
A simple scale works well. Rate each risk as low, medium or high for likelihood, and for impact on residents, operations and privacy. Combine them to prioritize. A high-impact, high-likelihood risk, such as an unpatched internet-facing system, goes to the top.
Avoid false precision. The goal is a sensible ranking that guides decisions.
The risk analysis feeds a risk management plan. For each significant risk, document:
The action you will take, such as enable MFA, replace an unsupported server, or encrypt laptops
Who is responsible
A target date
Budget or resources needed
How you will confirm it is done
Some risks may be accepted by leadership with a documented rationale. That is allowed, but it should be a deliberate decision, not an oversight.
The Security Rule expects documentation to be retained for six years. Keep the analysis, the plan and evidence of follow-up. Update it when something changes, such as a new EHR, a new building or wing, a merger, a major vendor change, or after a security incident. At minimum, review it on a regular schedule, commonly annually.
Treating a vulnerability scan as the full risk analysis
Forgetting vendors, personal devices, and paper-to-digital processes like eFax
Never acting on findings
Letting one person complete it without input from clinical and operations leaders
Not documenting the results
IT staff know systems, but administrators, DONs, medical records staff and business office leaders know how information really flows. A short working session with these groups often reveals systems IT did not know existed.
UnityCare IT helps long-term care and clinic organizations complete and maintain security risk analyses, then turn findings into a practical work plan. If your last analysis is more than a year old, or you are not sure you have one, we can help you get started.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172