Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: HHS OCR Risk Analysis Initiative

During the OCR/NIST Safeguarding Health Information HIPAA Security Conference held in October 2024, OCR Director Melanie Fontes Rainer stated one of the main focuses for OCR will be on the Risk Analysis Initiative. This initiative will be to encourage healthcare organizations to conduct a Risk Analysis that presents an accurate and thorough identification of the threats and vulnerabilities associated with all ePHI the organization has. Additionally, the Risk Analysis needs to be completed annually and reviewed on an ongoing basis for remediation.

Mentioned during the Conference was some of the latest breaches that have been submitted to OCR along with outcomes. In almost every breach and settlement with OCR, the organizations did not have a comprehensive Risk Analysis completed, or worse, never conducted a Risk Analysis. “Failure to conduct a HIPAA Security Rule Risk Analysis leaves health care entities vulnerable to cyberattacks, such as ransomware. Knowing where your ePHI is held and the security measures in place to protect that information is essential for compliance with HIPAA,” said OCR Director Melanie Fontes Rainer. “OCR created the Risk Analysis Initiative to increase the number of completed investigations and highlight the need for more attention and better compliance with this Security Rule requirement.”

The Risk Analysis is a HIPAA Security Rule requirement to “force” healthcare organizations to look very closely at their environment – network, staff, physical securities, policies and procedures – to ensure patient data (PHI, ePHI) is as secure as possible.

Whether you hire a company to conduct the annual Risk Analysis or choose to begin the process with the ONC/OCR Security Risk Assessment Tool complete right away and address vulnerabilities and risks to PHI within the organization.


Author: Dawn Meglino

HIPAA Compliance Specialist, CHPSE, CCSA, CCAP