Executive summary. A risk analysis follows ePHI through the systems that actually hold it, and records what the organization decided to do about each risk it found.
Definition
The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
Start with ePHI flows
Inventory the systems, interfaces, endpoints, people, and vendors that create, receive, maintain, or transmit ePHI. A diagram helps only when it matches the real flows, including exports, support processes, backups, and integrations.
Then identify credible threats and vulnerabilities for each flow, and make every treatment decision explicit and owned. Eliminating all risk is not the objective.
Record the reasoning, not only the score
Document the method, the evidence, the likelihood and impact rationale, the owner, the treatment decision, and the review date. A number on its own cannot show why a control was chosen or deferred.
Revisit the analysis when technology, vendors, locations, or workflows change materially. An assessment that drifts away from operational reality stops being accurate.
Frequently asked questions
Does HIPAA prescribe one risk-analysis template?
No. OCR describes a flexible and scalable approach. The analysis still has to be accurate, thorough, and appropriate to the organization’s circumstances.
Referenced standards and further reading
- HHS OCR: Guidance on Risk Analysis ↗U.S. Department of Health and Human Services
Related articles
The minimum necessary standard in operational design →
Business associate relationships: map the work, not the logo →