What a HIPAA Security Risk Analysis Actually Has to Include

If a compliance officer could do only one thing for the Security Rule, it would be a thorough, current risk analysis. The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. The HHS Office for Civil Rights has repeatedly pointed to missing or incomplete risk analyses in its enforcement actions, so it is worth getting right.

Many organizations confuse a risk analysis with a vulnerability scan, a policy binder or a one-time checklist. None of these alone satisfies the requirement. Here is what a defensible analysis includes.

Scope: every place ePHI lives

Start by defining the scope broadly. Electronic PHI is not only in your EMR. Build an inventory that covers:

Servers, workstations, laptops, tablets and phones that create, receive, store or transmit ePHI

Cloud services and software vendors, including email, file sharing, eFax and backup

Medical and connected devices, such as nurse call systems, medication carts and imaging equipment

Removable media and printers or copiers with storage

Paper-to-digital processes, such as scanning stations

Where data travels, including interfaces to pharmacies, labs, hospitals and payers

If you do not know where information is, you cannot protect it. This inventory is usually the most eye-opening part of the process.

Identify threats and vulnerabilities

For each asset or group of assets, consider what could go wrong and what weaknesses make it more likely.

Threats

Ransomware and other malware

Phishing and account takeover

Lost or stolen devices

Insider misuse or curiosity

Hardware failure, power loss, fire and severe weather

Vendor outages or breaches

Vulnerabilities

Unsupported operating systems or unpatched software

Missing multi-factor authentication

Shared accounts

Unencrypted laptops or backups

Flat networks where one infected machine can reach everything

Untested restore processes

Assess current controls

Document what is already in place: encryption, access controls, audit logging, backups, endpoint protection, physical safeguards, training and policies. Be honest. A risk analysis that lists every control as perfect will not survive scrutiny and will not help you.

Rate likelihood and impact

For each risk, estimate how likely it is and how severe the impact would be. A simple scale of low, medium and high is acceptable, as long as you apply it consistently and explain your reasoning. The result is a ranked list of risks, not a pass or fail score.

For example, an unencrypted laptop used by a visiting therapist might rate as high likelihood of loss and high impact, while a locked server room with redundant cooling might rate lower.

Build a risk management plan

The analysis feeds the Security Rule's risk management requirement. For each significant risk, record:

The chosen response, such as fix, reduce, transfer or formally accept

The person responsible

A target completion date

Budget or resources needed

Status updates

Regulators generally want to see that you act on what you find. An analysis sitting in a drawer with no remediation is a common enforcement theme.

Keep it current

The Security Rule expects ongoing evaluation. Update your analysis when:

You adopt a new system, vendor or device type

You open a new location or change how care is delivered

You experience a security incident

Major changes occur in your environment, such as moving to the cloud

At least annually, as a baseline practice

Common mistakes

Treating a one-time scan as the whole analysis

Excluding vendors, medical devices and personal devices

Having no written record of reasoning

Failing to assign owners and dates to findings

Letting the analysis go years without review

Where to get help

The HHS Office for Civil Rights has published guidance on the risk analysis requirement, and the Security Risk Assessment Tool from HHS and ONC is a free starting point for smaller organizations. Many facilities benefit from an outside party who can look at the technical environment objectively.

UnityCare IT performs risk analyses for long-term care and healthcare organizations, translating technical findings into a prioritized plan that administrators and compliance officers can act on. If yours is out of date, we can help you refresh it.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172