What a defensible HIPAA Security Risk Analysis actually looks like
The HIPAA Security Rule requires covered entities and business associates to conduct an 'accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability' of ePHI. OCR has cited the absence - or inadequacy - of this analysis in nearly every major resolution agreement of the past decade, with settlements ranging from $25,000 to $16M.
Our SRA methodology follows NIST SP 800-30 and the HHS OCR Guidance: full ePHI inventory across systems, devices, and third parties; threat and vulnerability identification; likelihood and impact rating; current-control evaluation; residual-risk determination; and a documented Risk Management Plan tracked to closure. The deliverable is what OCR asks for - not a vendor checklist with a logo.
- ePHI inventory across all systems and BAs
- NIST 800-30 threat / vulnerability / likelihood / impact model
- Risk Management Plan with named owners and due dates
- Annual update with change-driven mid-year refreshes
- Audit-ready evidence file for OCR // HHS

