If a regulator ever reviews your HIPAA compliance, one of the first documents they are likely to ask for is your security risk analysis. It is also one of the items most frequently found missing, outdated or too thin in enforcement actions. The requirement itself is straightforward: the HIPAA Security Rule expects covered entities and business associates to conduct an accurate and thorough assessment of potential risks to the confidentiality, integrity and availability of electronic protected health information.
It does not need to be mysterious. Here is a practical way to run one.
Decide what is included. The answer should be everything that creates, receives, maintains or transmits ePHI:
Computers, laptops, tablets and phones
Servers and cloud services, including your EMR and email
Networks, Wi-Fi and remote access
Medical and building devices that touch resident data
Paper-to-electronic processes, such as fax and scanning
Every facility or location
Vendors and business associates
A common mistake is limiting the analysis to the main EMR system and forgetting email, shared drives, text messaging and backups.
For each system, note what data it holds, who uses it, and how it is transmitted. Draw a simple diagram if it helps: resident information enters at admission, flows to the EMR, is printed, faxed to a physician, emailed to a pharmacy and backed up at night. Each step is a place something can go wrong.
Threats are things that could cause harm: ransomware, a lost laptop, a curious employee, a flood, a power outage, a vendor breach. Vulnerabilities are weaknesses that threats could exploit: unpatched software, missing MFA, no encryption, shared logins, a server room with no cooling backup.
Useful sources include:
The HHS 405(d) program and its Health Industry Cybersecurity Practices
NIST guidance on risk assessment and the NIST Cybersecurity Framework
HHS Office for Civil Rights guidance on risk analysis
Vulnerability scans and configuration reviews
Staff interviews. People often know where the workarounds are.
List what you already have: access controls, antivirus or endpoint protection, encryption, backups, training, policies, physical locks, camera coverage, audit logs. Note where a safeguard is missing, partial or not followed in practice. Honest assessment matters more than a polished one.
For each risk, estimate how likely it is and how damaging it would be. Simple categories of low, medium and high work fine. For example, a laptop without disk encryption that leaves the building daily might be high likelihood and high impact, while a flood in a well-drained server room might be low likelihood and high impact. Multiply or combine the ratings to produce a priority.
The analysis is only half the requirement. The Security Rule also expects you to implement security measures sufficient to reduce risks to a reasonable and appropriate level. For each significant risk record:
The action you will take: fix, reduce, transfer such as through insurance, or accept
Who is responsible
A target date
The status
Accepting a risk is allowed, but it should be a documented decision by someone with authority, not an oversight.
Keep the final report, the inventory, the ratings, the plan and any supporting evidence. HIPAA requires you to retain required documentation for six years. Include who participated and when it was completed.
The risk analysis is not a one-time project. Update it when something significant changes: a new EMR, an acquisition, a move to the cloud, a new facility, a breach, or a major new threat. Many organizations also review it at least annually.
Treating a vulnerability scan or a checklist as the whole analysis
Buying a template and filling in generic answers
Leaving out vendors, cloud services or mobile devices
Never turning findings into a plan with owners and dates
Letting the document sit untouched for years
IT may lead the technical part, but the administrator, compliance officer, director of nursing, HR and facilities all see risks IT does not. Include them.
UnityCare IT supports healthcare providers with risk analyses and the follow-up work of remediation, so the document becomes a working plan rather than a shelf item. If yours is old, incomplete or missing, we are happy to talk about where to begin.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172