HIPAA Tip: Likelihood x Impact = Risk
When we look at risk in a healthcare environment it is defined as the likelihood of a threat exploiting a vulnerability. Think of a combination of factors that could lead to unauthorized disclosure, modification or destruction of electronic Protected Health Information (ePHI). An example of this is an email phishing attack where a threat actor sends an attachment and a staff member (without thinking) opens the attachment and allows the hacker to load malware into the network and gain sensitive data, even passwords.
When conducting a HIPAA Risk Analysis impact refers to the potential severity of consequences if a threat successfully exploits a vulnerability, affecting the Confidentiality, Integrity and Availability (CIA) of the organization’s ePHI. In other words, if ePHI has been accessed and compromised how will this affect patient care? Can business continue or does this cause the organization to shut down? What are the regulatory penalties and reputational damage?
By taking these two and multiplying their scores, a risk level is calculated. A threat with a high likelihood and high impact would have a critical risk score, whereas a low likelihood and low impact would result in a low score or risk.
Healthcare organizations must assess the vulnerabilities within their centers, offices and hospitals, to ensure these are prioritized and addressed so risk levels can be brought down, protecting against reasonably anticipated threats.
Compliance Is Ongoing
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.