Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Likelihood x Impact = Risk

When we look at risk in a healthcare environment it is defined as the likelihood of a threat exploiting a vulnerability. Think of a combination of factors that could lead to unauthorized disclosure, modification or destruction of electronic Protected Health Information (ePHI). An example of this is an email phishing attack where a threat actor sends an attachment and a staff member (without thinking) opens the attachment and allows the hacker to load malware into the network and gain sensitive data, even passwords.

When conducting a HIPAA Risk Analysis impact refers to the potential severity of consequences if a threat successfully exploits a vulnerability, affecting the Confidentiality, Integrity and Availability (CIA) of the organization’s ePHI. In other words, if ePHI has been accessed and compromised how will this affect patient care? Can business continue or does this cause the organization to shut down? What are the regulatory penalties and reputational damage?

By taking these two and multiplying their scores, a risk level is calculated. A threat with a high likelihood and high impact would have a critical risk score, whereas a low likelihood and low impact would result in a low score or risk.

Healthcare organizations must assess the vulnerabilities within their centers, offices and hospitals, to ensure these are prioritized and addressed so risk levels can be brought down, protecting against reasonably anticipated threats.

Compliance Is Ongoing

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.