HIPAA Tip: Areas Overlooked When Conducting a HIPAA Risk Analysis
Complete Guide to Comprehensive HIPAA Security Risk Assessments
Welcome to this week’s HIPAA Tip Tuesday! Conducting a thorough HIPAA risk analysis is one of the most critical requirements for healthcare organizations, yet many practices inadvertently overlook key areas that could expose them to serious security vulnerabilities and compliance violations. In this comprehensive guide, we’ll explore the most commonly missed elements in HIPAA risk analysis and provide actionable steps to ensure your assessment covers all necessary safeguards.
- Physical PHI locations (paper records, stored documents, older files)
- Medical devices with hard drives (X-ray machines, diagnostic equipment, copiers)
- Cloud-based and web applications (SharePoint, Dropbox, Google Drive)
- Communication systems (dictation software, answering services, text messaging)
- Physical access controls (record rooms, server closets, storage areas)
What is a HIPAA Risk Analysis?
A Risk Analysis is defined as the Security Management Process standard in the Security Rule requiring organizations to “implement policies and procedures to prevent, detect, contain, and correct security violations.” (45 C.F.R. § 164.308(a)(1).)
RISK ANALYSIS (Required): Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic Protected Health Information (ePHI) held by the organization.
This requirement isn’t optional—it’s the foundation of your entire HIPAA compliance program. The Office for Civil Rights (OCR) consistently cites inadequate risk analysis as one of the top violations during audits and breach investigations. Yet many healthcare organizations conduct incomplete assessments that leave critical vulnerabilities unaddressed.
The Three Safeguards: A Holistic Approach to Risk Analysis
One of the most significant mistakes organizations make is focusing too narrowly on electronic systems while neglecting the comprehensive scope required by HIPAA. Your risk analysis must evaluate all three types of safeguards:
Administrative Safeguards
These include your policies, procedures, and the actions your workforce takes to protect PHI. Consider:
- Workforce training and awareness programs
- Access authorization and termination procedures
- Incident response plans
- Business associate agreements and vendor management
- Security role assignments and responsibilities
Physical Safeguards
Physical security measures protect facilities and equipment containing PHI. Many organizations focus solely on electronic security while overlooking physical vulnerabilities:
- Facility access controls and badge systems
- Workstation security and positioning
- Device and media disposal procedures
- Physical barriers and locked storage areas
- Visitor management and escort policies
Technical Safeguards
These are the technology-based controls that protect ePHI. While most organizations focus here, they often miss critical systems:
- Access controls and authentication mechanisms
- Encryption for data at rest and in transit
- Audit logging and monitoring systems
- Automatic log-off features
- Data backup and recovery systems
Critical Areas Overlooked in HIPAA Risk Analysis
Based on our experience conducting hundreds of HIPAA Security Risk Assessments annually, here are the areas healthcare organizations most frequently overlook:
1. Non-Electronic PHI (Paper Records and Physical Documents)
Many organizations fixate on Electronic Medical Records (EMR) security while completely overlooking physical PHI. Don’t forget to assess:
- Paper charts and intake forms
- Older medical records in storage facilities or basements
- Printed reports and lab results
- Faxed documents and reception desk paperwork
- Appointment schedules and sign-in sheets
- Billing statements and insurance documentation
Action Item: Walk through your entire facility and document every location where paper PHI exists, including storage rooms, file cabinets, reception areas, and off-site storage facilities.
2. Medical Devices and Diagnostic Equipment
Every device that contains ePHI needs to be assessed for security vulnerabilities, yet medical devices are frequently omitted from risk analyses:
- X-ray machines and imaging equipment with embedded hard drives
- Diagnostic devices that store patient data
- Copiers and multifunction printers (these have hard drives that retain images of everything copied/scanned)
- Older equipment being stored that contains hard drives with patient information
- Portable ultrasound a