If a compliance officer could do only one thing for the Security Rule, it would be a thorough, current risk analysis. The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. The HHS Office for Civil Rights has repeatedly pointed to missing or incomplete risk analyses in its enforcement actions, so it is worth getting right.
Many organizations confuse a risk analysis with a vulnerability scan, a policy binder or a one-time checklist. None of these alone satisfies the requirement. Here is what a defensible analysis includes.
Start by defining the scope broadly. Electronic PHI is not only in your EMR. Build an inventory that covers:
Servers, workstations, laptops, tablets and phones that create, receive, store or transmit ePHI
Cloud services and software vendors, including email, file sharing, eFax and backup
Medical and connected devices, such as nurse call systems, medication carts and imaging equipment
Removable media and printers or copiers with storage
Paper-to-digital processes, such as scanning stations
Where data travels, including interfaces to pharmacies, labs, hospitals and payers
If you do not know where information is, you cannot protect it. This inventory is usually the most eye-opening part of the process.
For each asset or group of assets, consider what could go wrong and what weaknesses make it more likely.
Ransomware and other malware
Phishing and account takeover
Lost or stolen devices
Insider misuse or curiosity
Hardware failure, power loss, fire and severe weather
Vendor outages or breaches
Unsupported operating systems or unpatched software
Missing multi-factor authentication
Shared accounts
Unencrypted laptops or backups
Flat networks where one infected machine can reach everything
Untested restore processes
Document what is already in place: encryption, access controls, audit logging, backups, endpoint protection, physical safeguards, training and policies. Be honest. A risk analysis that lists every control as perfect will not survive scrutiny and will not help you.
For each risk, estimate how likely it is and how severe the impact would be. A simple scale of low, medium and high is acceptable, as long as you apply it consistently and explain your reasoning. The result is a ranked list of risks, not a pass or fail score.
For example, an unencrypted laptop used by a visiting therapist might rate as high likelihood of loss and high impact, while a locked server room with redundant cooling might rate lower.
The analysis feeds the Security Rule's risk management requirement. For each significant risk, record:
The chosen response, such as fix, reduce, transfer or formally accept
The person responsible
A target completion date
Budget or resources needed
Status updates
Regulators generally want to see that you act on what you find. An analysis sitting in a drawer with no remediation is a common enforcement theme.
The Security Rule expects ongoing evaluation. Update your analysis when:
You adopt a new system, vendor or device type
You open a new location or change how care is delivered
You experience a security incident
Major changes occur in your environment, such as moving to the cloud
At least annually, as a baseline practice
Treating a one-time scan as the whole analysis
Excluding vendors, medical devices and personal devices
Having no written record of reasoning
Failing to assign owners and dates to findings
Letting the analysis go years without review
The HHS Office for Civil Rights has published guidance on the risk analysis requirement, and the Security Risk Assessment Tool from HHS and ONC is a free starting point for smaller organizations. Many facilities benefit from an outside party who can look at the technical environment objectively.
UnityCare IT performs risk analyses for long-term care and healthcare organizations, translating technical findings into a prioritized plan that administrators and compliance officers can act on. If yours is out of date, we can help you refresh it.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172