Why Organizations Must Conduct a HIPAA Risk Assessment

by Catherine Wanjau and Jay Hodes, President – Colington Consulting

Data breaches targeting Electronic Protected Health Information (ePHI) are nothing new. In fact, with more healthcare organizations now storing patients’ medical records electronically, these attacks are at an all-time high. It is crucial that healthcare entities regularly conduct a HIPAA risk assessment to identify any threats or vulnerabilities that may put ePHI in jeopardy. A risk assessment, also known as a risk analysis, is not only useful in detecting data threats; it’s also required by the Code of Federal Regulations (CFR). The HIPAA Security Rule requires that Covered Entities (CEs) and their Business Associates (BAs) “Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by the organization.” The risk assessment process keeps your patients’ records safe and your organization on the right side of the CFR.

Do Small Practices Need to Conduct a HIPAA Risk Assessment?

Data breaches don’t only occur in larger organizations; hackers can target small practices and businesses too. Regardless of the size of the organization, a HIPAA Risk Assessment must be conducted with the proper documentation of any gaps and weaknesses determined by the assessment. It’s essential and required.

The Office of the National Coordinator for Health Information Technology (ONC), in partnership with the HHS Office for Civil Rights (OCR), saw the need to launch a Security Risk Assessment (SRA) Tool to help small and medium-sized healthcare organizations and BAs comply with the HIPAA Security Rule. The tool is meant to guide these entities in identifying security risks in their systems, policies, and processes and display results that they can use to mitigate any identified vulnerabilities. Since launching the original tool about ten years ago, revisions have been made and it is now more of a decision tree process.

However, it’s important to note that the CFRs do not make it mandatory for Covered Entities and Business Associates to use the SRA tool nor does it give specific guidelines on how risk assessment should be carried out. HHS recognizes that different sized businesses have different needs and vulnerabilities, as well as different levels of access to resources. The problem with the tool is it can become time consuming to use, leads to more questions about meeting compliance requirements, and inability to see all the questions until traversing through the process. Regardless of using the tool or outsourcing the assessment to a consultant or vendor, all CEs and BAs must have documented proof that they have conducted an accurate and thorough HIPAA security risk assessment.

Failure to Perform a HIPAA Risk Assessment Can Result in Serious Penalties

If just knowing that conducting a risk analysis is a HIPAA requirement isn’t enough motivation to get you started with the process, then you should keep in mind that the fines for non-compliance can add up to hefty amounts. Some organizations like Excellus Health Plan, Inc., for instance, have had to pay up to $5.1 million to OCR for breaching ePHI. According to this press release, the penalty was attributed to the organization’s “failure to conduct an enterprise-wide risk analysis, and failures to implement risk management, information system activity review, and access controls”, which put the privacy of millions of its patients in danger. So, carrying out a risk assessment does not only allow you to spot potential weaknesses in organizational information systems that contain ePHI; it also enables you to take the right actions as soon as possible to safeguard your ePHI data, which can protect your business from federal penalties and the need to enter into a resolution agreement with OCR.

Need Help With Your HIPAA Compliance Program?

HIPAA violations often stem from small, overlooked gaps in daily operations. Don’t wait for a patient complaint to trigger a federal investigation. Would Your Practice Pass a HIPAA Audit Tomorrow?

At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your practice.