IT First Response

Guides

What a HIPAA security risk analysis is, and what OCR asks for first

By Mario Del MazoAugust 2, 20266 minute read

Somewhere in your practice's paperwork, an attestation says a security risk analysis exists. Many small practices have never actually performed one, or did a checklist years ago that nobody has looked at since. That gap matters because the risk analysis is the foundation the whole Security Rule is built on, and it is the first document the Office for Civil Rights requests when a complaint or a breach puts a practice in front of an investigator. This guide explains what the analysis actually is, what it covers, and what a good one looks like at small-practice scale. It is the IT side of the subject, not legal advice; your obligations are a question for qualified healthcare counsel.

What is a HIPAA security risk analysis?

The Security Rule requires every covered practice, regardless of size, to conduct a thorough, documented assessment of the risks to all of its electronic protected health information: where patient data lives, how it moves, who can reach it, and what protects it. That requirement does not scale away for a two-provider office; it is the same citation for you as for a hospital system. The same analysis is also what Medicare's incentive programs have practices attest to, which is why many offices have signed for its existence without quite possessing it. And one thing it is not: a certification. There is no such thing as being HIPAA certified, and anyone selling a certificate is selling paper.

What it actually covers

The rule groups its safeguards into three families, and in a small practice they translate into concrete questions. Administrative: who is responsible for security, who has access to what, whether staff are trained, what the plan is when a system fails, and whether every vendor that touches patient data has signed a business associate agreement. Physical: whether a screen with a chart on it is visible from the waiting room, what happens to old drives and copiers when they leave the building, and who can walk into the room where the server sits. Technical: unique logins rather than shared ones, multi-factor sign-in, encryption on the devices that could be stolen, and audit logs that record who opened which record. A real analysis walks all of it, scores what it finds, and writes the findings in language the practice owner can act on.

The trap in the word addressable

Some safeguards in the rule are labeled required and some addressable, and the second word has lulled a lot of practices. Addressable does not mean optional. It means the practice must either implement the safeguard or document, in writing, why it is not reasonable in its environment and what equivalent protection stands in its place. Skipping an addressable item without that written reasoning is a gap, and it is one of the most common findings in a small-practice assessment, because somewhere along the way somebody read addressable as skippable and moved on.

What OCR asks for first

When an investigation starts, the opening requests are predictable: the current risk analysis, and the risk management plan that addresses what it found. That second document matters as much as the first, because finding risk is step one and reducing it to a reasonable level is the actual obligation. A risk analysis with no follow-up plan documents that the practice knew and did nothing, which is worse than paperwork trouble. Behind those two come the supporting records: training logs, signed business associate agreements, evidence that somebody reviews system activity, and the breach notification procedure. Every one of those is producible in minutes by a practice that has been keeping them, and by no one else.

What a good one looks like for a small practice

Sized to the practice, scored control by control against the rule's actual citations, written in plain language, and ending in a prioritized plan with dates, which becomes the risk management plan OCR asks about. Performed by an outside party, it must be done under a signed business associate agreement, because the assessor is handling information about your patient data systems; that is how I deliver it. And it should be refreshed annually or when the practice changes, because an analysis describes a moment, and practices do not hold still. What it never includes is a certificate, a seal, or a promise of compliance, because none of those exist to give. How an engagement starts is on the healthcare page, and a first conversation costs nothing and decides nothing.

FAQ

Is there such a thing as HIPAA certified?

No. There is no government HIPAA certification, for a practice or for a vendor, and completing an assessment does not by itself make anyone compliant. A seal or badge that says HIPAA Certified is a marketing product. What actually exists is documented compliance work: a current risk analysis, a plan that addresses it, and records that show both.

How often does the risk analysis need to be redone?

The rule requires it to be kept current rather than naming a date, and in practice that means reviewing it annually and after any significant change: a new EHR, a move, new equipment, or a security incident. An analysis from several years ago describes a practice that no longer exists, which is how it reads to an investigator too.

Our EHR vendor says they are HIPAA compliant. Does that cover us?

No. The vendor's obligations cover their platform. Yours cover your practice: the devices in your office, your staff and their training, your access decisions, your backups, your other vendors and their agreements, and your procedures when something goes wrong. A compliant EHR inside a practice with no risk analysis is still a practice with no risk analysis.

Who should perform it, and what does it cost?

HHS publishes a free self-assessment tool, and a practice with the time and expertise can work through it internally. Most small practices have neither, which is where an outside provider comes in; I perform the assessment under a signed Business Associate Agreement, and the deliverable is built to support the risk analysis the rule requires. Work for businesses not on a plan is billed at $125 per hour, and larger projects are quoted up front so you approve the number before the work starts. What the rule obligates your practice to do remains a question for qualified healthcare counsel.

Attested to a risk analysis you are not sure exists? You are far from the only practice in that position, and the fix is a process, not a panic. The healthcare page explains how I work with small practices, delivered under a Business Associate Agreement, priced before work starts.

About the author

Mario Del Mazo is the owner of IT First Response, a managed IT and security practice in Fort Myers serving Lee County, Florida. His background is corporate IT for a healthcare organization operating under HIPAA and HITRUST standards. He publishes his prices, and every client environment is documented so nothing has to be explained twice. More about Mario.