Cybersecurity & Compliance

HIPAA Risk Assessments: What Gets Checked and How Often

MSP Worx · 4 min read

The risk analysis is the foundation of HIPAA Security Rule compliance. It is a required implementation specification under 45 CFR 164.308(a)(1)(ii)(A), and it is the single most frequently cited failure in enforcement actions brought by the HHS Office for Civil Rights.

That pattern is worth understanding. Practices that suffered a breach have repeatedly found the penalty related less to the breach itself than to never having conducted an adequate risk analysis — because the absence of one demonstrates the practice was not managing security at all, rather than managing it and being unlucky.

What it is, and what it is not

A risk analysis identifies where electronic protected health information exists across your organisation, what threatens it, how likely each threat is, what the impact would be, and what you are doing about it.

Several things are commonly mistaken for it and are not sufficient:

  • A vulnerability scan. That is a technical test of specific systems, not an assessment of risk to information.
  • A checklist supplied by a vendor. Useful as a prompt, but a checklist is not an analysis of your environment.
  • A security assessment sold as part of a sales process. Frequently scoped to demonstrate a need to buy something.
  • A one-time exercise. The rule expects it to be maintained.

The distinguishing feature of a real analysis is that it is specific to your organisation — your systems, your workflows, your vendors, your actual risks — and that its conclusions drive documented decisions.

What has to be covered

HHS guidance, drawing on NIST methodology, sets out the elements a compliant analysis must include.

Scope — everywhere ePHI exists

This is where most analyses fail, because the inventory is incomplete. ePHI is rarely confined to the EHR. It also lives in:

  • Email, including attachments and archives
  • Laptops, tablets and phones, including personally owned devices used for work
  • Backup systems and any offsite copies
  • Imaging equipment and modalities with local storage
  • Copiers and multifunction printers, which retain scanned images on internal drives
  • Cloud services — practice management, billing, transcription, patient communication platforms
  • Removable media, and paper produced from electronic systems

Threats and vulnerabilities

Natural, human and environmental. Human threats include both malicious action and the far more common category of error — misdirected email, mis-sorted records, lost devices.

Current security measures

What is actually in place, assessed honestly rather than aspirationally.

Likelihood and impact

For each identified risk, how probable and how damaging. This is what allows prioritisation, which is the practical output — a list of every conceivable risk with no ranking is not actionable.

Risk level and remediation plan

A determined risk level for each item, and documented decisions about what will be done, by whom, by when — including decisions to accept a risk, which is legitimate when documented and reasoned.

Documentation

All of the above, written down and retained. Under HIPAA, documentation must be kept for six years.

How often

The rule requires periodic review and update without specifying an interval, which causes genuine confusion. The practical standard that has emerged:

  • Review at least annually, as a baseline expectation
  • Update whenever the environment changes materially — a new EHR, a move to cloud services, a new location, a significant new vendor, a change in the services you provide
  • Update after any security incident, including near-misses
  • Update when new threats emerge that are relevant to your environment

An analysis dated four years ago describing systems you no longer run is, for practical purposes, an absent analysis. Regulators have treated it that way.

Doing it yourself or engaging someone

Small practices can conduct their own. HHS and the Office of the National Coordinator publish a free Security Risk Assessment Tool designed specifically for smaller organisations, and it is a legitimate way to meet the requirement if used properly.

The realistic constraint is not capability but candour and completeness. Self-assessment tends to under-scope, because the person completing it documents the systems they know about, and the risky systems are usually the ones nobody remembers.

Engaging externally is worth it when your environment is complex, when you have had an incident, when a business associate or payer requires independent assessment, or when previous attempts have not been completed. What matters either way is that the output is specific, prioritised and acted upon.

The follow-through that actually matters

A risk analysis that identifies problems and is then filed is arguably worse than none, because it documents that you knew.

The rule pairs the analysis with a risk management requirement — implementing measures sufficient to reduce risks to a reasonable and appropriate level. In practice this means the analysis should produce a remediation plan with owners and dates, and progress against that plan should be reviewed and recorded.

When OCR examines a practice, they look for the analysis, the plan that followed it, and evidence the plan was executed. A practice that identified a risk, planned to address it, and can show the work is in a strong position even if something went wrong. A practice with an analysis and no follow-through has documented its own negligence.

Want a straight answer for your business?

Talk to an advisor about your environment. No pitch, no obligation.