Running a HIPAA Security Risk Analysis Without Overcomplicating It

If there is one HIPAA document that regulators ask about again and again, it is the security risk analysis. The Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. Yet many organizations either have not done one, did one years ago, or bought a template and filled it in once.

A risk analysis does not have to be mysterious. It is a structured way of asking: where is our resident and patient data, what could go wrong, and what are we doing about it?

What a Risk Analysis Is, and Is Not

A risk analysis is a documented assessment. It is not simply a vulnerability scan, a policy binder, or a checklist of yes and no answers. A scan is one input. Policies are one control. The analysis ties them together and evaluates likelihood and impact.

HHS and its Office for Civil Rights have published guidance on what a risk analysis should include, and the NIST SP 800-30 publication is a commonly used method. You do not need to follow it word for word, but your approach should be consistent and documented.

Step 1: Inventory Where ePHI Lives

You cannot protect what you have not listed. Walk through every place electronic protected health information is created, received, stored or transmitted:

The electronic health record and related applications

Workstations, laptops, tablets and medication carts

Servers, shared drives and cloud storage

Email, eFax and messaging tools

Phones and personal devices used for work

Backups and removable media

Vendors and business associates who handle your data

Medical and connected devices that store or transmit information

Include who owns each system and who has access.

Step 2: Identify Threats and Vulnerabilities

For each system, ask what could go wrong. Think broadly:

Ransomware and phishing

Lost or stolen devices

Staff snooping or mistakes

Vendor outage or breach

Power loss, fire, flood or tornado, which matters in Oklahoma and Texas

Unpatched or unsupported software

Weak passwords or missing multi-factor authentication

Then note existing weaknesses, such as an old server, shared logins, or missing encryption.

Step 3: Review Current Controls

List what you already have in place. Examples include encryption, access controls, audit logging, backups, endpoint protection, firewalls, training, physical locks and sanctions policies. Be honest about which controls are actually working and which exist only on paper.

Step 4: Rate Likelihood and Impact

A simple scale works well. Rate each risk as low, medium or high for likelihood, and for impact on residents, operations and privacy. Combine them to prioritize. A high-impact, high-likelihood risk, such as an unpatched internet-facing system, goes to the top.

Avoid false precision. The goal is a sensible ranking that guides decisions.

Step 5: Build a Risk Management Plan

The risk analysis feeds a risk management plan. For each significant risk, document:

The action you will take, such as enable MFA, replace an unsupported server, or encrypt laptops

Who is responsible

A target date

Budget or resources needed

How you will confirm it is done

Some risks may be accepted by leadership with a documented rationale. That is allowed, but it should be a deliberate decision, not an oversight.

Step 6: Document and Keep It Current

The Security Rule expects documentation to be retained for six years. Keep the analysis, the plan and evidence of follow-up. Update it when something changes, such as a new EHR, a new building or wing, a merger, a major vendor change, or after a security incident. At minimum, review it on a regular schedule, commonly annually.

Common Mistakes

Treating a vulnerability scan as the full risk analysis

Forgetting vendors, personal devices, and paper-to-digital processes like eFax

Never acting on findings

Letting one person complete it without input from clinical and operations leaders

Not documenting the results

Involve the Right People

IT staff know systems, but administrators, DONs, medical records staff and business office leaders know how information really flows. A short working session with these groups often reveals systems IT did not know existed.

How UnityCare IT Can Help

UnityCare IT helps long-term care and clinic organizations complete and maintain security risk analyses, then turn findings into a practical work plan. If your last analysis is more than a year old, or you are not sure you have one, we can help you get started.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172