HIPAA
How to perform and document a HIPAA security risk analysis
The risk analysis is the foundation of the Security Rule — and the most common gap in enforcement. Here's a defensible method, step by step.
Why this document matters most
The Security Rule requires an "accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information." In enforcement actions, a missing or superficial risk analysis appears again and again as a core finding. It is also the practical anchor of your program: it decides what you fix first.
A defensible method
- Scope and inventory. List every system, device, application, and vendor where ePHI is created, received, maintained, or transmitted. Include the unglamorous places: email, backups, logs, spreadsheets, texting, and the billing company.
- Map data flows. For each system, how does ePHI arrive, where does it rest, where does it go next?
- Identify threats and vulnerabilities. For each asset: what could go wrong (ransomware, misdirected disclosure, lost device, insider misuse, vendor breach) and what weakness makes it possible?
- Assess likelihood and impact. A simple high/medium/low scale applied consistently beats a sophisticated scale applied once and abandoned.
- Document current controls. What already mitigates each risk, and how well?
- Determine and rank residual risk. This ranking is your remediation plan's spine.
- Decide treatment and document it. Remediate, mitigate, transfer, or accept — with reasoning and an owner for each decision. Risk acceptance without documentation is just risk.
Documentation standards
Date it, name its author and method, and keep versions. Update it when the environment changes materially and review it at least annually. An assessor should be able to trace any remediation task back to the risk that justified it.
Common failure modes
- A vendor questionnaire or insurance form standing in for analysis.
- Scope limited to the EHR while PHI lives in twelve other places.
- A beautiful document from three years ago with no review since.
- Risks identified but no treatment decision ever recorded.
Sources
HIPAA does not provide or recognize an official private certification. ClearCompliance provides readiness, implementation, and assessment services; clients remain responsible for their legal obligations. SOC 2 reports are issued by independent qualified CPA firms. ClearCompliance is not a law firm and does not provide legal advice. This article is educational and is not legal advice.