Mandeville, LA · Serving St. Tammany Parish and the Northshore 985-304-3054  ·  [email protected]
Insights

What is a HIPAA security risk assessment, and does a small practice need one?

What the HIPAA Security Rule actually requires of a small medical or dental practice, what a risk analysis covers, and how to get one done without stopping the clinic.

A HIPAA security risk assessment (the regulation calls it a risk analysis) is a documented review of where electronic protected health information lives in your practice, what could go wrong, and what you are doing about it. The HIPAA Security Rule requires every covered entity, regardless of size, to conduct one and to review and update it as the practice changes. Most small practices have never documented one, and it is the first thing an auditor or a breach investigator asks to see.

What the rule actually says

The HIPAA Security Rule, at 45 CFR 164.308(a)(1)(ii)(A), requires covered entities and business associates to "conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information." It applies to a two-provider dental office exactly as it applies to a hospital system.

The rule does not set a fixed calendar interval. It requires the analysis to be reviewed and updated in response to changes in the environment or operations. In practice, most practices and their advisors treat an annual review as the standard, with an update whenever something significant changes: a new EHR, a new location, a move to the cloud, a breach.

What a risk analysis covers

A useful risk analysis for a small practice walks through:

  • Where ePHI lives. The EHR, imaging systems, billing, email, scanners, the front-desk PCs, providers' laptops and phones, backups, and any vendor that stores or processes patient data.
  • How it moves. Email to patients and referring providers, claims to clearinghouses, images to specialists, portals, texting.
  • What could go wrong. Lost or stolen devices, phishing, ransomware, a departed employee who still has access, a flood, a vendor breach, a mis-sent email.
  • How likely and how bad. A rough rating for each risk so the fixes can be prioritized.
  • What is in place today. Encryption, multi-factor authentication, access controls, audit logging, backups, training, business associate agreements.
  • What to do about the gaps, with an owner and a date for each item.

The output is a document the practice owns, plus a remediation plan. It is not a certificate and nobody "passes" it; it is evidence that the practice looked, understood and acted.

What it is not

A risk analysis is not an antivirus scan, a vendor's checklist, or a one-page attestation. The Office for Civil Rights has said repeatedly in enforcement actions that a missing or inadequate risk analysis is among the most common findings, and a document that simply lists safeguards without analyzing the practice's actual risks does not meet the requirement.

Why small practices skip it, and why that is a mistake

The usual reasons: nobody on staff knows how, the IT vendor says the practice is "covered," and nothing bad has happened yet. The trouble is that the risk analysis is the foundation for every other Security Rule requirement. Without it, the practice cannot show why it chose the safeguards it has, and after a breach that gap becomes the story.

The practical risks are also real. A stolen unencrypted laptop with patient data on it is a reportable breach. A phished mailbox with patient communications in it is a reportable breach. A flood that destroys the only copy of records is a breach of the contingency requirements. Each of those is also exactly the kind of risk an analysis would have surfaced and a small fix would have closed.

How to get one done without stopping the clinic

  • Have someone who understands both HIPAA and small-practice IT do the interviews and the walkthrough. It takes a few hours of staff time spread across a week, not days of disruption.
  • Expect the first analysis to find real gaps. Encryption on laptops, MFA on email, a tested backup and a signed BAA from the email provider are the usual first fixes.
  • Put the remediation plan on a calendar and treat it as maintenance, not a project.
  • Keep the document current. Update it when the practice changes and review it at least annually.

Lagniappe IT documents the risk analysis in the format HHS expects, ties each finding to a specific fix in the practice's environment, and schedules the work outside clinic hours. A free 30-minute conversation is a reasonable place to start.

Related questions

Is the HIPAA risk analysis required every year?

The rule requires it to be reviewed and updated in response to changes rather than on a fixed interval, but annual review is the widely accepted standard and what most auditors and cyber insurance carriers expect to see.

Can our EHR vendor's security certification count as our risk analysis?

No. The vendor's certification covers their system. Your risk analysis covers your practice: your devices, your staff, your email, your backups and your vendors, including the EHR.

Does a dental practice have to do this too?

Yes. Dental practices are covered entities under HIPAA, and the Security Rule applies to them in full.

What does a risk analysis cost?

It depends on the number of providers, locations and systems. We scope it as a one-time project after a free assessment call, and the remediation work is usually folded into a flat monthly managed IT agreement.

Ready to stop worrying about your IT?

Start with a free 30-minute assessment. We look at your current setup, your backups, your email security and your biggest risks, then give you written findings you can act on, whether or not you hire us.

Prefer to talk now?

Call 985-304-3054 or email [email protected].

Monday to Friday, 8am to 5pm Central. Security monitoring runs 24x7 through our SOC partner.

1011 North Causeway Blvd., Suite 8, Mandeville, LA 70471

Call Book a free assessment