When the HHS Office for Civil Rights investigates a breach or complaint, one of the first things requested is the organization's security risk analysis. Enforcement actions have repeatedly cited the lack of an accurate and thorough one. Yet many small facilities either have no analysis, or have a document from years ago that no longer describes their environment.
This post explains what a risk analysis is, what it should contain and how to keep it useful rather than letting it sit on a shelf.
The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. It also requires a risk management process to reduce those risks to a reasonable and appropriate level.
Two points matter. First, the analysis is not a one-time event. It must be reviewed and updated as your environment changes. Second, a risk analysis is different from a vulnerability scan or a generic checklist. It looks at where ePHI lives, what threatens it and how likely and damaging those threats are.
Identify every place ePHI is created, received, stored or transmitted:
EHR and billing systems, including hosted ones
Workstations, laptops, tablets and phones
Servers and backups
Email, eFax and messaging tools
Copiers and scanners with storage
Removable media
Vendor and cloud systems
Paper that is scanned or entered into systems
Many facilities discover systems nobody had listed, such as an old file share or a personal device used for photos.
List realistic threats: phishing, ransomware, lost devices, insider mistakes, power failure, flood or fire, vendor breaches and unauthorized access. Then identify weaknesses that make each possible, such as missing MFA, unpatched systems or untested backups.
Document what is already in place, such as encryption, access controls, audit logs, training and physical locks.
For each risk, estimate how likely it is and how serious the effect would be. A simple scale of low, medium and high is acceptable, as long as you apply it consistently and explain your reasoning.
Combine likelihood and impact to produce a ranking. This tells you where to spend limited time and money first.
For every significant risk, record the action, owner, target date and status. This risk management plan is where the analysis turns into protection.
No analysis at all, or one that was never updated after a system change
Scope that omits mobile devices, cloud services or vendors
A generic template with no facility-specific details
Risks identified but no plan to address them
No evidence of follow-through
Analysis performed only by IT and never seen by leadership
No record of decisions to accept a risk
The analysis should not be written by IT alone. Include the privacy and security officers, the administrator, clinical leaders, the business office and your IT provider. People on the floor often know about workarounds IT does not. Leadership must review the results, since decisions about spending and risk acceptance are business decisions.
At minimum, review annually. Also update after significant changes, such as a new EHR, a move or renovation, a merger, a security incident or the adoption of new technology such as telehealth. Keep prior versions to show progress over time.
You do not need to invent your own method. The HHS Office for Civil Rights and ONC publish a Security Risk Assessment Tool aimed at smaller providers. The NIST Cybersecurity Framework 2.0 and the HHS 405(d) Health Industry Cybersecurity Practices provide structure for identifying and prioritizing risks. Using a recognized approach makes your work easier to explain.
HHS published a proposed update to the Security Rule in January 2025. It was a proposal, and organizations should keep following the rule as it stands unless and until HHS finalizes changes. Either way, a current risk analysis is the foundation of whatever comes next.
Treat the risk analysis as a working document. Revisit the remediation plan quarterly, mark completed items and add new ones. Share a summary at leadership meetings.
UnityCare IT assists healthcare organizations with security risk analyses, from identifying where ePHI lives to building a prioritized remediation plan. If your last analysis is more than a year old, we can help you update it.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034