A Step-by-Step Way to Run Your HIPAA Security Risk Analysis

If there is one HIPAA Security Rule requirement that comes up again and again in investigations and audits, it is the risk analysis. The Security Rule calls for covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information (ePHI). Many organizations have never completed one, or did it once years ago and filed it away.

The good news is that a risk analysis does not need to be mysterious. Here is a sequence that works for a nursing home, assisted living community or clinic.

Step 1: Define the scope

The analysis should cover all ePHI your organization creates, receives, maintains or transmits, wherever it lives. That includes the EMR, email, shared drives, scanned documents, backups, laptops, tablets, phones, medical devices, fax systems, and vendors who hold data for you. Write down what is in scope and what is not.

Step 2: Inventory your systems and data flows

List every system and device that stores or touches ePHI, and sketch how data moves between them. Where does a resident record start, who sees it, where does it get sent, and where does it end up? Include:

Applications, with the owner and vendor for each.

Hardware, such as servers, workstations, carts, tablets and network equipment.

Locations, including offsite storage and remote workers.

Third parties with access, and whether each has a business associate agreement.

Most organizations discover forgotten systems at this stage, such as an old server, a shared scanner that emails documents, or a shadow spreadsheet.

Step 3: Identify threats and vulnerabilities

A threat is something that could cause harm. A vulnerability is a weakness that the threat could exploit. Consider:

Human threats: phishing, insider snooping, lost devices, mistakes.

Technical threats: ransomware, unpatched software, weak passwords, misconfigured systems.

Environmental threats: fire, flood, power loss and severe weather.

Vendor threats: a business associate suffering a breach.

Then note the weaknesses that exist in your environment, such as no multi-factor authentication on email, shared logins at the nurses' station, or backups that have never been tested.

Step 4: Review the controls you already have

Document what is already protecting each system: access controls, encryption, audit logging, backups, antivirus, physical locks, training, policies. Be honest. A control that exists on paper but is not followed does not count.

Step 5: Rate likelihood and impact

For each threat and vulnerability pair, estimate how likely it is and how serious the effect would be. A simple low, medium and high scale is acceptable, as long as you apply it consistently and explain your reasoning. Combine likelihood and impact to get a risk level for each item.

For example, an unencrypted laptop that leaves the building daily and holds resident data may be high risk. A locked server room with a dedicated cooling unit may be low.

Step 6: Build a risk management plan

The analysis feeds a separate requirement: implementing security measures sufficient to reduce risks to a reasonable and appropriate level. For each significant risk, record:

The action to take.

The person responsible.

A target completion date.

The budget or resources needed.

Status updates.

Prioritize by risk level and cost-effectiveness. It is acceptable to accept some low risks, but document the decision and who made it.

Step 7: Document everything

HIPAA requires documentation to be retained for six years. Keep the scope, inventory, findings, ratings, decisions and plan together, with dates and the names of participants. Reviewers want to see that the work was real and that leadership was involved.

Step 8: Keep it current

A risk analysis is not a one-time event. Update it when you add new systems, open a new location, change vendors, experience an incident or make significant changes to the environment, and review it at least annually. HHS publishes guidance on conducting risk analyses, and the Office of the National Coordinator and OCR have jointly made a Security Risk Assessment Tool available that smaller practices sometimes use as a starting point.

Common pitfalls

Treating a vulnerability scan as a risk analysis. A scan is an input, not the whole assessment.

Ignoring paper records, vendors and physical security.

Writing the report and never acting on it.

Leaving out leadership, who need to own the decisions about risk.

Getting started

If your last analysis is more than a year old or you cannot find one, begin with Step 1 this month. UnityCare IT conducts HIPAA security risk analyses for healthcare and senior-living organizations and can help you move from findings to a prioritized, budgeted plan.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172