Resource
HIPAA risk analysis basics
The risk analysis is the foundation of the HIPAA Security Rule. Every other decision is supposed to trace back to it, which is why an analysis completed once and never updated undermines everything built on top of it.
What the analysis has to cover
Six elements. A vendor checklist confirming products are installed is not a risk analysis and will not be accepted as one.
| Element | What it means |
|---|---|
| ScopeImaging and backup systems left out | Every system that creates, receives, stores or transmits patient data |
| Data inventoryNobody has ever mapped it | Where protected health information actually lives |
| Threats and vulnerabilitiesCopied from a template, not specific to you | What could realistically go wrong |
| Current controlsDescribed rather than evidenced | What is already in place |
| Risk determinationSkipped entirely | Likelihood and impact, assessed |
| DocumentationExists as a certificate rather than an analysis | The written record of all of the above |
Why it must be repeated
The rule does not set an interval, but the analysis has to reflect your current environment.
- Any material change to systems, such as a new server, application or location
- A change in how patient data flows, including a new referral or results interface
- After a security incident, regardless of scale
- When a new type of data or service is introduced
- Periodically regardless, and annually is the defensible common practice
Analysis is not the same as a checklist
A checklist asks whether you have encryption. A risk analysis asks where unencrypted patient data could exist, how likely that is, what it would cost, and what you are doing about it.
That distinction is why purchased compliance certificates rarely satisfy the requirement. They demonstrate that products were bought, not that risks specific to your practice were assessed and addressed.
The practical output should be a findings register with an owner and a timeline against each item, feeding into a remediation plan. An analysis that produces a score and no plan has not done the job.
Common questions
Answered before you ask.
Can our IT provider do the risk analysis?
They can perform the technical portion, which is usually the largest part, and produce the evidence for it. The analysis also covers workforce, physical security, policy and business process, so it needs an owner inside the practice. The Security Rule expects a designated security official to exist, and that role cannot be outsourced.
How long does it take?
For a small practice, the technical assessment is typically a matter of days rather than weeks. What extends it is the data mapping, because many practices have never established exactly where patient information lives, particularly in backups, imaging systems and interfaces set up years ago by a vendor.
What happens if we have never done one?
Do one now rather than worrying about the gap. Absence of a risk analysis is a frequently cited finding, and having a current analysis with a documented remediation plan is a materially better position than having nothing, even where the analysis identifies real problems.
Related
Read next.
HIPAA IT compliance
Risk analysis, safeguards, audit controls and business associate agreements.
Healthcare
HIPAA, EHR uptime, device segmentation
Dental practices
Imaging servers, practice management, HIPAA
IT compliance and risk
HIPAA, CMMC, PCI DSS and cyber insurance requirements.
Backup and disaster recovery
Immutable backups with tested restores and a defined recovery window.
Start with the assessment, not the contract.
We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.