What a HIPAA Security Risk Analysis Is and Is Not

If you could do only one thing for HIPAA Security Rule compliance, it would be a thorough risk analysis. It is also the requirement that regulators most often find missing after a breach. Many organizations believe they have one because they bought a checklist, ran a vulnerability scan or filled out a questionnaire for their insurer. Those are useful, but none of them is, by itself, a risk analysis.

What the rule requires

The Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. It then requires you to implement security measures to reduce those risks to a reasonable and appropriate level. The Office for Civil Rights has published guidance on the expectations, and the NIST SP 800-30 publication is commonly used as a method.

What a risk analysis must include

A complete inventory of where ePHI lives

You cannot protect what you have not listed. Include:

The EHR or EMR and any connected systems.

File servers, cloud storage, email and shared drives.

Laptops, desktops, tablets, phones and removable media.

Medical and monitoring devices that store or transmit patient data.

Fax services, scanners and copiers with hard drives.

Backups and archives, onsite and offsite.

Vendors who hold or access your data.

Threats and vulnerabilities

For each system, ask what could go wrong and what weaknesses exist. Threats include ransomware, lost devices, misdirected faxes, insider snooping, power loss, fire and vendor failure. Vulnerabilities include unpatched software, shared passwords, missing encryption and lack of staff training.

Current controls

Document what you already do: encryption, multi-factor authentication, backups, access controls, physical locks, policies.

Likelihood and impact

Rate each risk by how likely it is and how damaging it would be. A simple scale of low, medium and high is acceptable if applied consistently and explained.

A risk level and a plan

The analysis feeds a risk management plan: which risks you will fix, who is responsible and by when. A list of findings with no plan does not satisfy the rule.

What a risk analysis is not

A vulnerability scan. A scan finds technical weaknesses on some systems. It does not address policies, people or physical safeguards.

A penetration test. Valuable, but a point-in-time test of defenses, not a full analysis.

A compliance checklist. A checklist asks whether controls exist; an analysis asks how well they address your actual risks.

A questionnaire for the insurer. Useful as input only.

A one-time project. It must be reviewed and updated as your environment changes.

How often to update it

The rule calls for ongoing evaluation. A common practice is to perform a full review at least annually and to update it whenever something significant changes: a new EHR, a new building, a merger, a cloud migration, or a security incident. Keep prior versions to show progress over time.

Common failures

Leaving out systems that clinical staff adopted without IT involvement.

Ignoring business associates and vendors.

Writing a risk analysis and never acting on it.

Skipping documentation. If it is not written, an investigator will treat it as not done.

Relying on a template that lists generic risks and does not reflect your building.

A practical approach for a small organization

Assign an owner, usually the privacy or security officer.

Build the inventory with help from IT and department heads.

Walk through each system and record threats, controls and gaps.

Rank the risks and write a plan with owners and dates.

Review progress quarterly and redo the analysis annually.

Where UnityCare IT can help

UnityCare IT performs HIPAA security risk analyses for long-term care, senior living and clinic operators, with plain-language results administrators can act on. If you have an older analysis sitting in a binder, we can help you update it and turn it into a practical plan.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172