Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Conducting Your Own Risk Analysis

The Value of Professional HIPAA Security Risk Analysis

I would be the first to recommend when your organization is preparing its annual budget, the cost for the annual HIPAA Security Risk Analysis (SRA) by a certified HIPAA compliance specialist is factored in. Their knowledge and expertise will ensure that all HIPAA Security Rules are covered, to include administrative areas (policies and procedures), physical (server rooms secure, key code locks), and technical (is the firewall firmware up to date?), but especially identifying the location of ALL ePHI, who has access, and how the data is secured.

TL;DR – Conducting Your Own HIPAA Risk Analysis:

  • Recommendation: Budget for annual SRA by certified HIPAA specialist
  • Professional SRA covers: Administrative, physical, and technical security
  • Key focus: Identifying ALL ePHI locations, access controls, and data security
  • Free tools available: HHS OCR/ONC Security Risk Assessment Tool
  • NIST resources: SP 800-30 (Risk Assessments) and SP 800-66 (HIPAA Security Rule)
  • No monetary cost to enhance security and employee understanding

Free Resources for Self-Conducted Risk Analysis

However, there are many resources at your disposal to enhance your organization’s security and increase your employees’ understanding of its importance, all at no monetary cost to the business. The following links are a very good starting point for keeping your organization more secure and compliant.

HHS Security Risk Assessment Tool

HHS Office for Civil Rights (OCR) and Office of the National Coordinator (ONC) Security Risk Assessment Tool

NIST Risk Assessment Guide

National Institute of Standards and Technology (NIST) SP 800-30 Guide for Conducting Risk Assessments

NIST HIPAA Security Rule Implementation Guide

NIST SP 800-66 Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide

Ongoing HIPAA Compliance Support

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.