Healthcare SBC
Compliance8 min read

The HIPAA Security Risk Analysis Most Practices Get Wrong

A security risk analysis is required, specific and frequently misunderstood. Here's what it actually has to contain, and what a checklist from your IT vendor doesn't satisfy.

H

Healthcare SBC Security Team

Security & Compliance ·

The HIPAA Security Rule requires an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information.

It's also the most commonly cited deficiency in enforcement actions: usually because a practice mistook a vendor's security checklist for a risk analysis.

What a real risk analysis contains

  • A complete inventory of where ePHI is created, received, maintained and transmitted, including cloud services, mobile devices, email and backups
  • Identification of reasonably anticipated threats and vulnerabilities to each
  • Assessment of current security measures already in place
  • A determination of likelihood and impact for each identified risk
  • An assigned risk level supporting prioritized remediation
  • Documentation of the analysis, the findings and the decisions made

Why checklists fall short

A checklist confirms whether specific controls exist. A risk analysis evaluates whether your specific environment, data flows and threats are adequately addressed, which requires knowing where your ePHI actually lives.

Most practices are surprised by their own inventory. ePHI routinely sits in places nobody catalogued: personal phones, a scanning workstation, an old backup drive, a departed employee's cloud folder, a fax service.

How often it must be updated

The rule requires periodic review and update. In practice this means at least annually, and additionally whenever there's a material change: a new EHR, a new location, a merger, a significant new technology, or a security incident.

It is also a required measure under Promoting Interoperability, so an outdated analysis affects program attestation as well as HIPAA compliance.

The remediation obligation

Identifying risk is only half the requirement. The Security Rule requires implementing measures sufficient to reduce risks to a reasonable and appropriate level, and documenting what you did.

A thorough risk analysis with no evidence of remediation is arguably worse than none at all. It documents that you knew about a vulnerability and left it in place.

FAQ

Frequently asked questions questions

How often is a HIPAA security risk analysis required?
The Security Rule requires periodic review and update. The practical standard is at least annually, plus whenever there is a significant change such as a new EHR, a new location, a merger, major new technology, or a security incident.
Does a vendor security checklist satisfy the requirement?
No. A checklist verifies whether specific controls exist but does not constitute a risk analysis. The requirement is an environment-specific assessment identifying where ePHI resides, what threats and vulnerabilities apply, and the likelihood and impact of each: with documented remediation decisions.