HIPAA Tip: Conducting Your Own Risk Analysis
The Value of Professional HIPAA Security Risk Analysis
I would be the first to recommend when your organization is preparing its annual budget, the cost for the annual HIPAA Security Risk Analysis (SRA) by a certified HIPAA compliance specialist is factored in. Their knowledge and expertise will ensure that all HIPAA Security Rules are covered, to include administrative areas (policies and procedures), physical (server rooms secure, key code locks), and technical (is the firewall firmware up to date?), but especially identifying the location of ALL ePHI, who has access, and how the data is secured.
- Recommendation: Budget for annual SRA by certified HIPAA specialist
- Professional SRA covers: Administrative, physical, and technical security
- Key focus: Identifying ALL ePHI locations, access controls, and data security
- Free tools available: HHS OCR/ONC Security Risk Assessment Tool
- NIST resources: SP 800-30 (Risk Assessments) and SP 800-66 (HIPAA Security Rule)
- No monetary cost to enhance security and employee understanding
Free Resources for Self-Conducted Risk Analysis
However, there are many resources at your disposal to enhance your organization’s security and increase your employees’ understanding of its importance, all at no monetary cost to the business. The following links are a very good starting point for keeping your organization more secure and compliant.
HHS Security Risk Assessment Tool
NIST Risk Assessment Guide
NIST HIPAA Security Rule Implementation Guide
NIST SP 800-66 Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide
Ongoing HIPAA Compliance Support
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.