What a HIPAA Security Risk Analysis Must Actually Include

If a regulator opened an investigation into your facility tomorrow, one of the first documents they would ask for is your security risk analysis. It is also one of the most frequently cited gaps in HHS Office for Civil Rights enforcement. Many organizations have a policy binder, a firewall and a yearly training video, yet cannot produce a current, documented analysis of where electronic protected health information lives and what could go wrong with it.

This article explains what the HIPAA Security Rule expects, in plain terms.

What the rule requires

The Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. You must then implement security measures to reduce those risks to a reasonable and appropriate level.

Two points often get missed. First, it is not a one-time project. Second, it is not a vulnerability scan alone. A scan is one input; the analysis is a broader business document.

The core elements

1. Scope: where is ePHI?

Start with an inventory. Include:

The EHR and any connected modules

Email, shared drives and cloud storage

Laptops, tablets, phones and removable media

Medical devices that store or transmit resident data

Fax services, scanners and copiers with storage

Backups, both on-site and off-site

Vendors and business associates who touch the data

2. Threats and vulnerabilities

List realistic threats: phishing, ransomware, lost devices, insider snooping, power or internet outages, vendor compromise, natural disasters. Then note the weaknesses that would let them succeed, such as unpatched systems, shared passwords or missing encryption.

3. Current controls

Document what you already do: multi-factor authentication, encryption, access reviews, training, backups, physical locks. Be honest about what is partial or inconsistent.

4. Likelihood and impact

For each risk, rate how likely it is and how damaging it would be. A simple high, medium and low scale is acceptable if it is applied consistently and explained.

5. Risk rating and priority

Combine likelihood and impact into a ranked list. This tells leadership where limited budget should go first.

6. Risk management plan

For each significant risk, record the action, the owner, the target date and the status. This is where analysis becomes action, and regulators look for it.

How often to update

The rule does not set a fixed number of months, but the analysis should be reviewed and updated when conditions change. Reasonable triggers include:

A new EHR, new facility or new major system

A merger or change in ownership

A security incident

New vendors with access to ePHI

Significant changes in staff, locations or remote work

Many organizations also schedule a full review annually so it never goes stale.

Common mistakes

Treating a vendor scan as the analysis. A scan finds technical flaws but ignores policy, people and process.

Copying a template without customizing it. Auditors can tell when your analysis could belong to any organization.

No follow-through. An analysis that lists risks but shows no remediation is a liability.

Ignoring business associates. Your risk includes the vendors who handle your data.

Leaving out paper and physical risk. The Security Rule focuses on electronic information, but your overall privacy program should still address both.

Resources worth using

HHS and the National Institute of Standards and Technology both publish guidance. HHS offers a Security Risk Assessment Tool aimed at smaller providers, and NIST Special Publication 800-30 describes risk assessment methodology. The HHS 405(d) program also offers Health Industry Cybersecurity Practices that can help you identify sensible controls.

Involve the right people

Do not leave the analysis to IT alone. Clinical leaders know how information really moves through a unit, the business office knows which spreadsheets hold resident data and the administrator knows which risks leadership will accept. Hold one or two working sessions, take notes and assign owners. The conversations often surface shadow systems and informal workarounds that no inventory would have found on its own.

Making it manageable

For a single facility, a thorough analysis can often be completed in a few weeks with the right people in the room: administrator, DON, compliance officer, IT lead and key vendors. UnityCare IT helps long-term care and clinic teams document ePHI, assess risks and build a prioritized remediation plan that leadership can actually fund.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034