Skip to content

Resource

HIPAA risk analysis basics

The risk analysis is the foundation of the HIPAA Security Rule. Every other decision is supposed to trace back to it, which is why an analysis completed once and never updated undermines everything built on top of it.

What the analysis has to cover

Six elements. A vendor checklist confirming products are installed is not a risk analysis and will not be accepted as one.

Elements of a HIPAA risk analysis
ElementWhat it means
ScopeImaging and backup systems left outEvery system that creates, receives, stores or transmits patient data
Data inventoryNobody has ever mapped itWhere protected health information actually lives
Threats and vulnerabilitiesCopied from a template, not specific to youWhat could realistically go wrong
Current controlsDescribed rather than evidencedWhat is already in place
Risk determinationSkipped entirelyLikelihood and impact, assessed
DocumentationExists as a certificate rather than an analysisThe written record of all of the above

Why it must be repeated

The rule does not set an interval, but the analysis has to reflect your current environment.

  • Any material change to systems, such as a new server, application or location
  • A change in how patient data flows, including a new referral or results interface
  • After a security incident, regardless of scale
  • When a new type of data or service is introduced
  • Periodically regardless, and annually is the defensible common practice

Analysis is not the same as a checklist

A checklist asks whether you have encryption. A risk analysis asks where unencrypted patient data could exist, how likely that is, what it would cost, and what you are doing about it.

That distinction is why purchased compliance certificates rarely satisfy the requirement. They demonstrate that products were bought, not that risks specific to your practice were assessed and addressed.

The practical output should be a findings register with an owner and a timeline against each item, feeding into a remediation plan. An analysis that produces a score and no plan has not done the job.

Common questions

Answered before you ask.

Can our IT provider do the risk analysis?

They can perform the technical portion, which is usually the largest part, and produce the evidence for it. The analysis also covers workforce, physical security, policy and business process, so it needs an owner inside the practice. The Security Rule expects a designated security official to exist, and that role cannot be outsourced.

How long does it take?

For a small practice, the technical assessment is typically a matter of days rather than weeks. What extends it is the data mapping, because many practices have never established exactly where patient information lives, particularly in backups, imaging systems and interfaces set up years ago by a vendor.

What happens if we have never done one?

Do one now rather than worrying about the gap. Absence of a risk analysis is a frequently cited finding, and having a current analysis with a documented remediation plan is a materially better position than having nothing, even where the analysis identifies real problems.

Start with the assessment, not the contract.

We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.

CallFree assessment