A founder's guide to the HIPAA Security Risk Analysis required by §164.308(a)(1)(ii)(A): what it is, what it isn't, and the deficiencies we see in the field. Approximately 7 minutes.
Roughly half the medical and dental practices we audit cannot show us their HIPAA Security Risk Analysis. Most have something — a "HIPAA assessment," a "security questionnaire" their IT provider filled out, a 2018 PDF from a vendor that no longer exists. None of those are what the rule asks for.
The Risk Analysis is the most-cited deficiency in OCR HIPAA enforcement actions. It is also the most fixable. The rule is short, the requirements are knowable, and the cost of getting it right is materially less than the cost of getting it wrong. This is a working walkthrough.
The text of 45 CFR §164.308(a)(1)(ii)(A) requires covered entities and business associates to:
Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate.
Four words in that sentence do most of the work. "Accurate" means the analysis must reflect what is actually in your environment, not a template. "Thorough" means all ePHI, everywhere — including the laptop that left the office, the printer with the hard drive, the SaaS vendor your billing team uses. "Risks and vulnerabilities" are not the same thing. A vulnerability is a weakness. A risk is the impact of that weakness being exploited, weighted by likelihood. The analysis must address both.
We see these three deficient artifacts repeatedly:
The vulnerability scan report. An automated tool produced a 60-page PDF listing CVEs across the network. Useful. Not a Risk Analysis. The scan identifies technical vulnerabilities on systems it could see; it does not evaluate workflow, business associates, physical access, or risks the scanner cannot detect.
The compliance checklist. A 200-item questionnaire with yes/no answers and a percentage score at the bottom. Often produced annually as a renewal exercise. Useful as a self-attestation aid. Not a Risk Analysis, because a checklist does not analyze. It records.
The IT provider's "we got you" letter. A signed letter from the MSP stating that the practice is HIPAA compliant. This is not a regulatory document. It is a marketing artifact. OCR does not credit it.
The OCR and NIST have published guidance on what a defensible Risk Analysis looks like. The structure converges on six elements:
The most subtle issue we see: the IT provider performs the Risk Analysis on the environment they themselves built and operate. In nearly every audit we run, the IT provider is also a Business Associate under HIPAA. The Risk Analysis is supposed to evaluate them, among other risks. They cannot independently audit themselves.
OCR has not formally required independent assessment, but every settlement we have read involving a Risk Analysis deficiency has identified self-assessment as a contributing factor. The standard of care has shifted. If your IT provider performs your Risk Analysis, your defensibility under audit is materially weaker than if a separate firm performs it.
A real Risk Analysis for a mid-sized practice — five to fifty users, one to three locations — takes three to six weeks and produces a 40 to 80 page document plus a risk management plan. A boutique firm with healthcare experience can deliver this for materially less than the cost of one settlement with HHS, and meaningfully less than a Big Four-style engagement that produces a similar deliverable.
What we recommend is not heroic. Schedule the analysis annually. Use an independent firm. Make sure the document covers all ePHI everywhere it lives. Document the management plan. Implement the high-priority mitigations. Review on schedule. The HIPAA Security Rule was written to be doable by an organization that takes it seriously. Most don't. The ones that do don't appear in OCR settlement filings.
If you're due for an analysis — or have not had one in two years — Caveo Security runs HIPAA-specific compliance work through our Compliance & Audit practice.
Scope a HIPAA Security Risk Analysis. Typical engagement: 4–6 weeks, fixed-fee, delivered by a senior partner.
Talk to a partner →