HIPAA Security Rule Risk Analysis: A Practical Approach
The most cited deficiency in HIPAA enforcement is a missing or inadequate risk analysis. What separates one that holds up from a vulnerability scan with a cover page.
GuardsArm Team
Security Experts
Inadequate risk analysis is among the most frequently cited findings in HIPAA enforcement actions. Not because organisations skip it, but because what they produce is something else wearing its name — usually a vulnerability scan, a control checklist, or a gap assessment against a framework.
What it is not
| Not a risk analysis | Why |
|---|---|
| A vulnerability scan | Identifies technical weaknesses, not risk to ePHI. No threat, likelihood or impact |
| A control checklist | Records what you have, not what could go wrong |
| A gap assessment against NIST or HITRUST | Measures conformance to a framework, not risk to your data |
| A penetration test | Demonstrates exploitability of a subset, at a point in time |
| A BAA inventory | Necessary, and a different exercise |
Each of these is useful and each is an input. None is the analysis.
The six things it must contain
1. Scope. Every system, application, device, location and medium where ePHI is created, received, maintained or transmitted. Enterprise-wide, explicitly — including medical devices, cloud services, backups, paper and third parties.
2. An ePHI inventory. Where it lives, how it flows, who can reach it. This is the step that takes the longest and the one most often abbreviated, and without it the rest is guesswork.
3. Threats and vulnerabilities, paired. A vulnerability alone is not a risk. It becomes one when paired with a threat that could exploit it. Include natural, human and environmental threats — not only cyber.
4. Current controls. What is already in place that affects likelihood or impact.
5. Likelihood and impact. Rated, with the rating criteria written down so the result is reproducible rather than an opinion.
6. Risk level, documented. The output is a rated list of risks, not a narrative.
Pairing threats with vulnerabilities
The structure that makes an analysis defensible:
| Asset | Threat | Vulnerability | Current control | Likelihood | Impact | Risk |
|---|---|---|---|---|---|---|
| EHR database | Malicious insider | Broad clinical read access | Audit logging, targeted alerting | Medium | High | High |
| Imaging archive | External attacker | DICOM accepts unauthenticated associations | Network segmentation | Medium | High | High |
| Laptops | Theft | Portable, leave the building | Full-disk encryption | High | Low | Medium |
| Backups | Ransomware | Reachable with domain credentials | Offsite copy, not immutable | Medium | Very high | Critical |
| Legacy lab system | Exploitation | Unpatched, end of support | Isolated VLAN | Medium | Medium | Medium |
Note the laptop row. High likelihood, low impact — because encryption means a stolen laptop is probably not a reportable breach. That is how a control earns its place in the analysis, and it is why "we have encryption" belongs here rather than as a standalone assertion.
Risk analysis, then risk management
The analysis identifies risk. The risk management plan is a separate required specification and is what enforcement actually looks for: what you decided to do about each risk, who owns it, by when.
Accepting a risk is a legitimate outcome. Accepting it silently is not.
When to redo it
Not merely annually. Trigger a reassessment on:
- A new clinical system, or a significant change to an existing one
- A merger, acquisition or new facility
- A security incident
- A new threat that materially changes likelihood
- A change in the regulatory baseline
Where to start
If your last analysis was a scan report, start with the inventory. Spend the time locating ePHI properly — including the copies in reporting databases, non-production environments and vendor systems. Everything downstream depends on it, and it is the part an assessor will test first.
For the operational side of the same obligation, see vulnerability management.
GuardsArm conducts HIPAA Security Rule risk analyses, including the ePHI inventory work most organisations find hardest. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on “HIPAA Security Rule Risk Analysis: A Practical Approach”
Talk to the GuardsArm team about how these services apply to your environment.


