If a regulator opened an investigation into your facility tomorrow, one of the first documents they would ask for is your security risk analysis. It is also one of the most frequently cited gaps in HHS Office for Civil Rights enforcement. Many organizations have a policy binder, a firewall and a yearly training video, yet cannot produce a current, documented analysis of where electronic protected health information lives and what could go wrong with it.
This article explains what the HIPAA Security Rule expects, in plain terms.
The Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. You must then implement security measures to reduce those risks to a reasonable and appropriate level.
Two points often get missed. First, it is not a one-time project. Second, it is not a vulnerability scan alone. A scan is one input; the analysis is a broader business document.
Start with an inventory. Include:
The EHR and any connected modules
Email, shared drives and cloud storage
Laptops, tablets, phones and removable media
Medical devices that store or transmit resident data
Fax services, scanners and copiers with storage
Backups, both on-site and off-site
Vendors and business associates who touch the data
List realistic threats: phishing, ransomware, lost devices, insider snooping, power or internet outages, vendor compromise, natural disasters. Then note the weaknesses that would let them succeed, such as unpatched systems, shared passwords or missing encryption.
Document what you already do: multi-factor authentication, encryption, access reviews, training, backups, physical locks. Be honest about what is partial or inconsistent.
For each risk, rate how likely it is and how damaging it would be. A simple high, medium and low scale is acceptable if it is applied consistently and explained.
Combine likelihood and impact into a ranked list. This tells leadership where limited budget should go first.
For each significant risk, record the action, the owner, the target date and the status. This is where analysis becomes action, and regulators look for it.
The rule does not set a fixed number of months, but the analysis should be reviewed and updated when conditions change. Reasonable triggers include:
A new EHR, new facility or new major system
A merger or change in ownership
A security incident
New vendors with access to ePHI
Significant changes in staff, locations or remote work
Many organizations also schedule a full review annually so it never goes stale.
Treating a vendor scan as the analysis. A scan finds technical flaws but ignores policy, people and process.
Copying a template without customizing it. Auditors can tell when your analysis could belong to any organization.
No follow-through. An analysis that lists risks but shows no remediation is a liability.
Ignoring business associates. Your risk includes the vendors who handle your data.
Leaving out paper and physical risk. The Security Rule focuses on electronic information, but your overall privacy program should still address both.
HHS and the National Institute of Standards and Technology both publish guidance. HHS offers a Security Risk Assessment Tool aimed at smaller providers, and NIST Special Publication 800-30 describes risk assessment methodology. The HHS 405(d) program also offers Health Industry Cybersecurity Practices that can help you identify sensible controls.
Do not leave the analysis to IT alone. Clinical leaders know how information really moves through a unit, the business office knows which spreadsheets hold resident data and the administrator knows which risks leadership will accept. Hold one or two working sessions, take notes and assign owners. The conversations often surface shadow systems and informal workarounds that no inventory would have found on its own.
For a single facility, a thorough analysis can often be completed in a few weeks with the right people in the room: administrator, DON, compliance officer, IT lead and key vendors. UnityCare IT helps long-term care and clinic teams document ePHI, assess risks and build a prioritized remediation plan that leadership can actually fund.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034