Back to blog
US & Americas

The HIPAA security risk analysis: the requirement most often failed

It is explicitly mandated, it underpins every other decision in the Security Rule, and enforcement actions repeatedly cite its absence or inadequacy. What a defensible analysis has to contain.
GRC Copilot Team
The HIPAA security risk analysis: the requirement most often failed

The security risk analysis is the most frequently cited failure in HIPAA enforcement, and the reason is structural: every other decision in the Security Rule is supposed to follow from it. Without one, no safeguard decision can be justified - so an inadequate analysis undermines the entire programme.

What it must actually cover

An accurate and thorough assessment of risks to the confidentiality, integrity and availability of electronic protected health information. In practice that means:

  1. Identify all ePHI - where it is created, received, maintained and transmitted. Not just the electronic health record: backups, imaging systems, email, mobile devices, cloud services, vendor systems, and the spreadsheets somebody exported.
  2. Identify threats and vulnerabilities to each.
  3. Assess current security measures.
  4. Determine likelihood and impact, producing a risk level.
  5. Document everything, including the reasoning.
The first step is where most analyses fail. An inventory limited to the main clinical system misses the majority of ePHI locations, and an analysis over an incomplete scope cannot be accurate or thorough by definition.

Why so many are inadequate

  • A vendor questionnaire treated as an analysis. A checklist of controls is a gap assessment, not a risk analysis - it never establishes likelihood or impact.
  • Scope limited to IT systems rather than everywhere ePHI actually lives.
  • Done once and never updated, despite the requirement being ongoing.
  • No link to decisions - the analysis exists and nothing changed because of it.
  • Business associates excluded, though the data sits with them.

Required and addressable

The Security Rule marks some implementation specifications required and others addressable. Addressable does not mean optional. It means you must assess whether it is reasonable and appropriate, implement it if so, and if not, document why and implement an equivalent alternative measure where reasonable.

Treating addressable as optional and leaving no record is a common finding. The documented reasoning is the compliance artefact - not the decision itself.

Assess against the Security Rule with evidence attached

GRC Copilot scores you against HIPAA safeguards, records the risk decisions behind each, and keeps the evidence auditors and regulators ask for.

Turning it into a risk management plan

The analysis identifies risk; the Security Rule separately requires you to manage it - reducing risks to a reasonable and appropriate level. So the output must be a prioritised remediation plan with owners and dates, and evidence that it progressed.

An analysis with no corresponding plan is half the requirement, and it is the half enforcement notices tend to quote.

Keeping it current

Update it on a defined cycle and whenever something material changes: a new system holding ePHI, a new business associate, a merger, a significant infrastructure change, or after a security incident. Annual review is the common baseline, but change-driven updates are what make it credible.

Business associates

Business associates have their own obligation to conduct a risk analysis - it is not discharged by the covered entity's. If you are a business associate, you need your own, covering the ePHI you hold. Vendors frequently discover this obligation during a customer audit rather than before it.

Frequently asked questions

Is a gap assessment enough?

No. A control checklist does not establish likelihood and impact, which is what makes it a risk analysis.

How often must it be updated?

Annually as a baseline and on material change. The requirement is ongoing rather than periodic.

Does addressable mean optional?

No. It means assess, implement if reasonable and appropriate, or document why not and use an alternative.

Do business associates need their own?

Yes. The obligation applies to them directly for the ePHI they handle.

Key takeaways

  • Every Security Rule decision is supposed to follow from this analysis.
  • Incomplete ePHI inventory is the most common root cause of inadequacy.
  • Addressable means documented reasoning, not optional.
  • An analysis without a risk management plan is half the requirement.
#hipaa #security-risk-analysis #sra #phi #addressable #covered-entity