In our work with healthcare organizations, we’ve seen how a well-executed HIPAA Security Risk Assessment can prevent costly problems. We don’t just know the rule—we’ve applied it in the field, and what follows is what we’ve learned. This post explains what the assessment entails, why it’s required, and when to update it. I’ll even share some of the scary things we’ve encountered in the trenches.
Table of contents
Why You Should Care About Your Security Risk Assessment
Here’s a quick two-question pop quiz:
You may not know the answer to Question #1. (It’s since 2003 for Covered Entities when the HIPAA Security Rule was first issued. And since 2010 for Business Associates when the HITECH Act was passed by Congress). But you should know the answer to Question #2. And if it’s “Never”, or “I don’t remember,” then this article is for you.
Even if you do remember when you last went through the security risk assessment process, now there’s a third question:
Why is a HIPAA Security Risk Assessment Required?
As we noted above, a HIPAA Security Risk Analysis (often called a security risk assessment) has been required since the HIPAA Security Rule was first issued. The requirement for this type of analysis comes from the Administrative Safeguards of the HIPAA Security Rule. One of the required four implementation specifications of the Security Management standard is to complete a security risk assessment. Unfortunately, this required implementation specification was for a long time one of the more frequently ignored provisions of the Security Rule.
A second source of requirements for a security risk assessment is the provisions of the Medicare Program’s Merit-based Incentive Program (MIPS). The 2025 Performance Requirements for Promoting Interoperability require participating Medicare providers to utilize Certified EHR Technology and to attest they are in compliance with the Security Risk Analysis measure of the MIPS performance measures.
Ready to take a closer look at your HIPAA compliance?
CONSIDERING A HIPPA RISK ASSESSMENT?
Ensure your HIPAA compliance starts with a Risk Assessment done right.
What are the elements of a HIPAA Security Risk Assessment?
As the term implies, the purpose of a security risk assessment is to assess the potential risks of loss or unauthorized disclosure of electronic protected health information (eHPI). An accurate and thorough assessment will help your organization identify potential threats to, and vulnerabilities of, health information technology, other information systems and their associated security risks.
The major elements of a risk analysis include:
How often is a HIPAA Security Risk Assessment Required?
The HIPAA Security Rule doesn’t specify how often a security risk analysis must undergo periodic review. But in our experience, many organizations delay updates for years—even after major system or security changes. That kind of gap can expose them to unnecessary risk.
This risk management activity should be periodically reviewed for all applications containing ePHI. Updates are especially important when new applications are added, security measures are changed, or information technology is updated or replaced. In each case, organizations should also document the changes. Covered Entities and Business Associates must then update their related policies and procedures to reflect any changes required by the HIPAA Security Rule.
HIPAA Security Risk Assessment Lessons Learned
The description above is a bare-bones review of the several elements most CEs or BAs must address to achieve compliance with this requirement of the HIPAA Security Rule. In our work over the years providing many organizations with a HIPAA Gap Analysis, we have seen plenty of risky situations for healthcare providers that must be addressed in a security risk analysis.
A few examples of those risky situations we’ve witnessed include:
And the HIPAA Wall of Shame is replete with examples of lost laptops, failed firewalls and equipment or software applications left out of a HIPAA risk assessment. When the Office for Civil Rights (OCR) of the Health and Human Services Department (HHS) comes to audit your compliance with the Privacy and/or Security Rule, they don’t limit themselves to just the issue that prompted an audit. They look at every aspect of your HIPAA compliance, and then they calculate your fine.
And don’t forget that attesting to something you haven’t done, e.g., to having performed a Security Risk Assessment as part of your attestations related to MIPS incentive payments, could be considered a false claim by Medicare. That can involve criminal penalties!
In the long run and the short run, spending money on security measures is cheaper than paying fines!
