Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Why Complete a HIPAA Security Risk Analysis

Healthcare organizations and their Business Associates must conduct a Security Risk Analysis (SRA) as required by the HIPAA Security Rule, to evaluate potential risks and vulnerabilities to the Confidentiality, Integrity and Availability (CIA) of electronic Protected Health Information (ePHI). As threats and vulnerabilities are identified the likelihood and impact to the organization and its ePHI must be assessed. Without conducting the SRA there is no way of determining the risks to patients’ information and the network or systems’ security measures that are in place to protect the data.

Vulnerability is defined in NIST SP 800-30 as “[a] flaw or weakness in system security procedures, design, implementation, or internal controls that could be exercised (accidentally triggered or intentionally exploited) and result in a security breach or a violation of the system’s security policy.”

Threat as an adapted definition from NIST SP 800-30 is “the potential for a person or thing to exercise (accidentally trigger or intentionally exploit) a specific vulnerability.”

Risk is more clearly defined once threat and vulnerability are identified. An adapted definition from NIST SP 800-30 is “the net mission impact considering (1) the probability that a particular [threat] will exercise (accidentally trigger or intentionally exploit) a particular [vulnerability] and (2) the resulting impact if this should occur. …Risks arise from legal liability or mission loss due to:

  1. Unauthorized (malicious or accidental) disclosure, modification, or destruction of information
  2. Unintentional errors and omissions
  3. IT disruptions due to natural or man-made disasters
  4. Failure to exercise due care and diligence in the implementation and operation of the IT system(s).”

Now is the time to conduct the annual HIPAA SRA for your organization. Contact your HIPAA professional for assistance.

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


Author:

Dawn Meglino

HIPAA Compliance Specialist, CHPSE, CCSA, CCAP