A Step-by-Step Walkthrough of the HIPAA Security Risk Analysis

If a regulator ever reviews your HIPAA compliance, one of the first documents they are likely to ask for is your security risk analysis. It is also one of the items most frequently found missing, outdated or too thin in enforcement actions. The requirement itself is straightforward: the HIPAA Security Rule expects covered entities and business associates to conduct an accurate and thorough assessment of potential risks to the confidentiality, integrity and availability of electronic protected health information.

It does not need to be mysterious. Here is a practical way to run one.

Step 1: Define the Scope

Decide what is included. The answer should be everything that creates, receives, maintains or transmits ePHI:

Computers, laptops, tablets and phones

Servers and cloud services, including your EMR and email

Networks, Wi-Fi and remote access

Medical and building devices that touch resident data

Paper-to-electronic processes, such as fax and scanning

Every facility or location

Vendors and business associates

A common mistake is limiting the analysis to the main EMR system and forgetting email, shared drives, text messaging and backups.

Step 2: Inventory Where ePHI Lives and Moves

For each system, note what data it holds, who uses it, and how it is transmitted. Draw a simple diagram if it helps: resident information enters at admission, flows to the EMR, is printed, faxed to a physician, emailed to a pharmacy and backed up at night. Each step is a place something can go wrong.

Step 3: Identify Threats and Vulnerabilities

Threats are things that could cause harm: ransomware, a lost laptop, a curious employee, a flood, a power outage, a vendor breach. Vulnerabilities are weaknesses that threats could exploit: unpatched software, missing MFA, no encryption, shared logins, a server room with no cooling backup.

Useful sources include:

The HHS 405(d) program and its Health Industry Cybersecurity Practices

NIST guidance on risk assessment and the NIST Cybersecurity Framework

HHS Office for Civil Rights guidance on risk analysis

Vulnerability scans and configuration reviews

Staff interviews. People often know where the workarounds are.

Step 4: Review Current Safeguards

List what you already have: access controls, antivirus or endpoint protection, encryption, backups, training, policies, physical locks, camera coverage, audit logs. Note where a safeguard is missing, partial or not followed in practice. Honest assessment matters more than a polished one.

Step 5: Rate Likelihood and Impact

For each risk, estimate how likely it is and how damaging it would be. Simple categories of low, medium and high work fine. For example, a laptop without disk encryption that leaves the building daily might be high likelihood and high impact, while a flood in a well-drained server room might be low likelihood and high impact. Multiply or combine the ratings to produce a priority.

Step 6: Build a Risk Management Plan

The analysis is only half the requirement. The Security Rule also expects you to implement security measures sufficient to reduce risks to a reasonable and appropriate level. For each significant risk record:

The action you will take: fix, reduce, transfer such as through insurance, or accept

Who is responsible

A target date

The status

Accepting a risk is allowed, but it should be a documented decision by someone with authority, not an oversight.

Step 7: Document and Date Everything

Keep the final report, the inventory, the ratings, the plan and any supporting evidence. HIPAA requires you to retain required documentation for six years. Include who participated and when it was completed.

Step 8: Repeat

The risk analysis is not a one-time project. Update it when something significant changes: a new EMR, an acquisition, a move to the cloud, a new facility, a breach, or a major new threat. Many organizations also review it at least annually.

Common Mistakes

Treating a vulnerability scan or a checklist as the whole analysis

Buying a template and filling in generic answers

Leaving out vendors, cloud services or mobile devices

Never turning findings into a plan with owners and dates

Letting the document sit untouched for years

Who Should Be Involved

IT may lead the technical part, but the administrator, compliance officer, director of nursing, HR and facilities all see risks IT does not. Include them.

How UnityCare IT Can Help

UnityCare IT supports healthcare providers with risk analyses and the follow-up work of remediation, so the document becomes a working plan rather than a shelf item. If yours is old, incomplete or missing, we are happy to talk about where to begin.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172