Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: HIPAA Smarter

Becoming HIPAA Smarter: Essential Steps for Compliance

To become “HIPAA smarter” organizations need to understand HIPAA rules, implement appropriate safeguards, and continuously monitor and adapt to ensure compliance. This includes developing policies, training employees, managing Business Associate Agreements (BAAs), conducting regular audits and completing an annual Risk Analysis.

TL;DR – HIPAA Smarter Essentials:

  • Conduct annual Risk Analysis to identify PHI vulnerabilities and threats
  • Risk Analysis is a HIPAA requirement, not optional
  • Most healthcare breaches involve failure to conduct thorough Risk Analysis
  • Free tool: HHS Security Risk Assessment Tool for small/medium practices
  • Free tool: NIST HIPAA Security Rule Toolkit with comprehensive guidance
  • Key steps: policies, training, BAAs, audits, continuous monitoring

Why Risk Analysis is Critical for Healthcare Organizations

The purpose of a Risk Analysis is to Identify vulnerabilities and potential threats to all PHI within the organization and implement measures to mitigate those risks. In addition to being a HIPAA requirement, organizations WANT to conduct a Risk Analysis to keep their patient health information secure and protect the business from the consequences of data breaches. Almost every day we read in the news of a breach to a healthcare organization and one of the violations is almost always the lack of conducting a thorough Risk Analysis.

Free HIPAA Risk Assessment Tools

HHS Security Risk Assessment Tool

The Office of the National Coordinator for Health Information Technology (ONC) and the HHS Office for Civil Rights (OCR) have jointly launched a HIPAA Security Risk Assessment Tool. The tool’s features make it useful in assisting small- and medium-sized health care practices and business associates as they perform a risk assessment.

HHS Security Risk Assessment Tool

NIST HIPAA Security Rule Toolkit

The NIST HIPAA Security Toolkit Application is a self-assessment survey intended to help organizations better understand the requirements of the HIPAA Security Rule (HSR), implement those requirements, and assess those implementations in their operational environment. A comprehensive user guide and instructions for using the application are available along with the HSR application.

Ongoing HIPAA Compliance Support

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.