HIPAA Tip: Risk Management Plan
Essential Steps for HIPAA Security Rule Compliance
Welcome to this week’s HIPAA Tip Tuesday! A risk management plan is a required component of HIPAA Security Rule compliance, yet many organizations struggle with where to start. Dawn Meglino breaks down the official Security Rule requirements and provides three practical steps for developing and maintaining an effective risk management plan.
- Required by HIPAA Security Rule § 164.308(a)(1)(ii)(B)
- Must reduce risks to “reasonable and appropriate” level
- Step 1: Develop plan, evaluate and prioritize risks
- Step 2: Implement technical and non-technical security measures
- Step 3: Continuously evaluate, monitor, and update measures
What is a Risk Management Plan?
A Risk Management Plan is defined in the HIPAA Security Rule as: The required implementation specification at § 164.308(a)(1)(ii)(B), for Risk Management, requires a Covered Entity to “[i]mplement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with § 164.306(a) [(the General Requirements of the Security Rule)].”
Example Risk Management Steps
Step 1: Develop and Implement a Risk Management Plan
Develop and Implement a Risk Management Plan. Evaluate and prioritize the areas and levels of risks within the organization. Should certain risks be addressed immediately or in the future? Which security measures need to be implemented right away?
Step 2: Implement Security Measures
Implement Security Measures. Technical and non-technical security measures must be addressed. Projects to implement security measures need to have an identified scope, timeline and budget.
Step 3: Evaluate and Maintain Security Measures
Evaluate and Maintain Security Measures. Continue to evaluate and monitor the risk mitigation measures implemented. Risk management is an ongoing process that must be reviewed and updated constantly and always when there are changes to the business environment – whether physical or technical (network) changes.
Additional Resources
Security Series Paper 6 – Basics of Risk Analysis and Risk Management
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.