HIPAA Security Risk Assessment Guide

  1. Home
  2. /
  3. IT & Cybersecurity Resources
  4. /
  5. HIPAA Security Risk Assessment...

Healthcare security readiness

HIPAA Security Risk Assessment Guide

Understand how healthcare organizations can evaluate electronic protected health information, threats, vulnerabilities, safeguards, training, documentation, evidence, and remediation priorities.

  • Plain-language guidance
  • Operational considerations
  • Evidence over product claims

Guide section 1

Identify where electronic protected health information exists

The assessment scope should consider systems, applications, endpoints, cloud services, email, integrations, vendors, backups, users, locations, and workflows that create, receive, maintain, or transmit electronic protected health information.

Guide section 2

Evaluate threats, vulnerabilities, likelihood, and impact

Organizations should evaluate reasonably anticipated threats and vulnerabilities, the safeguards already in place, the likelihood and potential impact of harmful events, and the resulting level of risk. Documentation should reflect the actual environment rather than a generic checklist.

Guide section 3

Meet identity requirements without disrupting clinical workflows

Healthcare employees need to move between exam-room, nursing-station, clinical, and administrative workstations without sharing accounts or creating an access-management burden. Level 4 uses proven, industry-standard identity and device-management technologies to give each workforce member a unique, accountable identity across authorized systems. This simplifies onboarding, role changes, password management, access reviews, and employee termination while producing useful audit evidence.

Guide section 4

Automate HIPAA security awareness training and reporting

Level 4 Security Awareness Training (SAT) can automatically enroll employees when they are hired, assign HIPAA-focused training, schedule annual refresher training and retesting, and produce automated completion and status reports. This helps organizations operate and document a repeatable workforce security-awareness program while retaining responsibility for policies, sanctions, role-specific instruction, and compliance decisions.

Guide section 5

Build a completed, client-specific HIPAA manual

Level 4 reviews its written HIPAA policies and procedures, risk-assessment, treatment-plan, and recurring-review templates against current applicable requirements, then customizes the documentation to the client’s actual workforce, systems, vendors, safeguards, responsibilities, and workflows. Deliverables can include a completed policies and procedures manual, documented risk findings and remediation priorities, and a recurring review schedule. These materials support the client’s compliance program; they are not a HIPAA certification, legal advice, or a guarantee of compliance.

Guide section 6

Maintain an ongoing risk-management process

Assessment findings should lead to assigned remediation, documented risk decisions, safeguards, evidence, review, and updates as technology, vendors, business operations, and threats change. Technical support does not replace legal interpretation or an organization’s compliance responsibility.

Related Level 4 capability

Connect the guidance to an operating control

Authoritative references

Current framework, program, and regulatory guidance

These sources provide the official foundation for the topics summarized on this page. Organizations should confirm current versions and obtain qualified legal, compliance, audit, or assessment guidance for their specific obligations.

Frequently asked questions

HIPAA Security Risk Assessment Guide FAQ

Is a HIPAA security risk assessment required?

Yes for covered entities and business associates subject to the HIPAA Security Rule. 45 CFR 164.308(a)(1)(ii)(A) requires an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information, or ePHI.

What should be included in the scope of a HIPAA risk analysis?

HHS guidance states that the analysis should cover all ePHI the organization creates, receives, maintains, or transmits. Practical scope can include systems, applications, endpoints, cloud services, email, integrations, medical devices, backups, facilities, workforce access, vendors, and data flows.

What is the difference between HIPAA risk analysis and risk management?

Risk analysis identifies and evaluates risks and vulnerabilities affecting ePHI under 45 CFR 164.308(a)(1)(ii)(A). Risk management is the separate required process under 45 CFR 164.308(a)(1)(ii)(B) for implementing reasonable and appropriate measures that reduce identified risks.

What is the difference between required and addressable HIPAA specifications?

A required implementation specification must be implemented. Addressable does not mean optional. The regulated entity must evaluate whether the specification is reasonable and appropriate, implement it when it is, or document why it is not and use an equivalent alternative measure when reasonable and appropriate, consistent with 45 CFR 164.306(d)(3).

Does a vulnerability scan complete a HIPAA risk assessment?

No. Technical scanning can provide useful evidence, but a risk assessment also considers scope, data flows, users, physical and administrative safeguards, threats, likelihood, impact, vendors, procedures, and documented risk decisions.

Which administrative safeguards are commonly reviewed?

The assessment can evaluate risk analysis and management, assigned security responsibility, workforce security, access management, security awareness and training, incident procedures, contingency planning, periodic evaluation, business associate arrangements, sanctions, and review of system activity under 45 CFR 164.308.

Which physical safeguards are commonly reviewed?

Physical review can cover facility access, workstation use and security, equipment and media movement, disposal, media reuse, accountability, and backup before equipment movement under 45 CFR 164.310. The assessment should consider remote work and hosted environments as well as traditional offices.

Which technical safeguards are commonly reviewed?

Technical review can cover access control, unique user identification, emergency access, automatic logoff, encryption, audit controls, integrity, authentication, and transmission security under 45 CFR 164.312. The Rule generally defines required outcomes rather than mandating a particular commercial product.

How can a healthcare office meet HIPAA unique-user requirements?

Level 4 can implement centralized identity and access controls using established industry-standard technology. Each employee receives an individual identity that works across authorized systems and workstations, while access policies, authentication, role changes, termination, and activity records are managed consistently. The result is easier administration, a better employee experience, and stronger compliance evidence.

Why are shared office passwords a serious risk?

Shared passwords make it difficult to determine who accessed, changed, printed, transmitted, or deleted information. They also complicate employee departures, password changes, access reviews, investigations, and accountability. 45 CFR 164.312(a)(2)(i) requires unique user identification for tracking identity, and HHS states that each workforce member using a system that maintains ePHI must have a unique identifier.

Can Level 4 replace shared passwords without disrupting the practice?

Level 4 can assess current accounts, workstations, applications, roles, and workflows; design an appropriate identity standard; migrate users in a controlled sequence; and document the resulting controls. The objective is to improve accountability and administration while preserving the practical ability of clinical and administrative staff to work from authorized machines.

Can Level 4 automate HIPAA security awareness training?

Yes. Level 4 Security Awareness Training can automatically enroll new employees, assign HIPAA-focused training, schedule annual refresher training and retesting, and generate automated completion and status reports. The training program and reporting support the organization’s workforce security process but do not replace its policies, role-specific instruction, sanctions, legal guidance, or compliance responsibility.

Can Level 4 provide a completed HIPAA policies and procedures manual?

Yes. Level 4 can begin with its written templates and customize the manual to the client’s actual organization, workforce, systems, vendors, safeguards, assigned responsibilities, and workflows. The engagement can also connect the manual to documented risk findings, remediation priorities, and a recurring review schedule so the written program reflects operations rather than remaining a generic document.

Does a completed HIPAA manual certify that an organization is compliant?

No. HIPAA does not provide a general certification that replaces an organization’s responsibility to comply. A completed manual documents policies and procedures, but the organization must implement, follow, review, and update them; operate the associated safeguards; retain appropriate evidence; and obtain qualified legal or compliance guidance when needed. Level 4 supports that compliance work without representing it as certification or a guaranteed outcome.

What recurring HIPAA activities can Level 4 help document?

Depending on scope, Level 4 can help document recurring reviews for backups and recovery, system activity and logs, access and account changes, patching, endpoint protection, encryption, workforce training, physical safeguards, vendors and business associate agreements, risk management, incidents, media handling, and policies and procedures. The schedule should be tailored to the client’s risks and operating requirements.

Are encryption and automatic logoff mandatory under HIPAA?

Encryption and automatic logoff are addressable implementation specifications, not blanket product mandates. Each must be evaluated through the organization’s risk analysis. The resulting implementation, reasonable alternative, or documented determination must follow the addressable-specification process.

What does HIPAA require for backup and disaster recovery?

The contingency-plan standard at 45 CFR 164.308(a)(7) includes required data-backup, disaster-recovery, and emergency-mode operation plans. Testing and revision procedures and applications-and-data criticality analysis are addressable. HHS also recommends periodic restore testing to validate recoverability.

What logging and activity review should an assessment examine?

45 CFR 164.308(a)(1)(ii)(D) requires procedures to regularly review system activity such as audit logs, access reports, and security incident tracking. Section 164.312(b) also requires mechanisms that record and examine activity in systems containing or using ePHI.

When are business associate agreements relevant?

When a covered entity permits a business associate to create, receive, maintain, or transmit ePHI on its behalf, the Security Rule generally requires satisfactory assurances documented through a written contract or other qualifying arrangement under 45 CFR 164.308(b) and 164.314. Applicability and exceptions should be reviewed with qualified counsel.

How often should a HIPAA risk analysis be updated?

The Security Rule does not prescribe one universal interval. HHS describes risk analysis as an ongoing process. Organizations should update it as needed when technology, operations, locations, vendors, threats, ownership, key personnel, or security incidents change, and should perform periodic technical and nontechnical evaluations.

Does a ransomware incident automatically require breach notification?

The determination is fact specific. A regulated entity should coordinate containment and recovery with qualified privacy, legal, compliance, insurance, and forensic resources; evaluate whether PHI was acquired, accessed, used, or disclosed impermissibly; and document the applicable breach-risk assessment and notification decisions.

Can Level 4 provide HIPAA certification?

Level 4 does not present readiness support as a guaranteed compliance outcome or universal HIPAA certification. It can support technology assessment, safeguards, evidence, remediation, and ongoing security operations while the organization retains responsibility for its obligations.

Apply the guidance

Assess the current environment and define the next step

Level 4 can help translate the topic into scoped responsibilities, evidence, remediation, and an accountable operating plan.

Discuss HIPAA security readiness
Scroll to Top