The HIPAA Risk Analysis Santa Clarita Practices Skip: Required, Free to Start, and the Finding in Almost Every OCR Settlement
The practice has a binder. Annual training is done and signed, the business associate agreements are filed, the policies were bought from a reputable vendor and they look the part. Then something happens, the notification goes in, and the letter comes back asking for documents. The first one on the list is the risk analysis, and there is a pause in the office while everybody tries to remember whether that was ever done.
This is the most common gap we find, and it is not carelessness. The risk analysis is the least visible item in the Security Rule. Nothing about it shows up at the front desk, no staff member ever asks about it, and a practice can run for years without noticing it is missing. It is also the item the Office for Civil Rights names, over and over, when it explains why a settlement was reached.
Overview
Last week's piece was about a password rule that turned out to be addressable, meaning you may implement an equivalent measure instead and record why. This one is the opposite, and the difference is the whole point. The security management process at 45 CFR 164.308(a)(1) carries four implementation specifications and every one of them is required: risk analysis, risk management, a sanction policy, and information system activity review. There is no alternative to document in place of any of them.
The risk analysis specification asks you to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information held by the organization. Two words in that sentence carry most of the enforcement weight. Accurate means it describes the environment you actually have rather than a generic one. Thorough means it reaches everywhere the information lives, which is almost never just the practice management system.
This is not a theoretical reading. OCR has been running a named Risk Analysis Initiative and working through it action by action, numbering them publicly in its own announcements. What follows are two of those cases, chosen because one of them is not a medical practice at all.
The Challenge
An accounting firm paid $175,000, and the finding was the risk analysis. BST & Co. CPAs is a New York accounting, advisory and consulting firm. In December 2019 ransomware reached part of its network and affected protected health information belonging to a client, and the breach was reported to OCR the following February. The settlement OCR announced records the finding plainly: the firm had failed to conduct an accurate and thorough risk analysis of the risks and vulnerabilities to the electronic protected health information it held. The resolution was $175,000 and a corrective action plan monitored for two years, requiring a real risk analysis, a risk management plan, written policies and annual role specific training. OCR described it as the tenth action under the Risk Analysis Initiative.
The reason that case matters in Valencia and Stevenson Ranch is the word accounting. You become a business associate by doing work that touches protected health information, not by deciding you are in healthcare. OCR's own fact sheet on direct liability states that business associates are directly liable for failure to comply with the requirements of the Security Rule, and for failure to provide breach notification to a covered entity. A firm in Saugus doing billing, filings, consulting or records work for a medical client is inside that sentence, whatever the sign on the door says, and the obligations arrive with the first file.
And the enforcement is current, not historical. On September 17 this year OCR settled with Ambry Genetics for $700,000 over a phishing attack that exposed the health data of 225,000 patients, which sits at the top of the agency's published list of resolution agreements. Ten days ago, in other words, while most practices in the valley were doing something else.
One more, for the practice that assumes the penalty scales with the damage. In March OCR settled with MMG Fusion, a software company and business associate, over a breach affecting roughly 15 million people. The settlement was $10,000, and it was the twelfth Risk Analysis Initiative action. Read that next to the $700,000 and the lesson is not that fines are small. It is that the number reflects what an organization can pay, while the corrective action plan, the monitoring and the years of attention land regardless. The cost of these cases is rarely the check.
What a risk analysis is not, since this is where most practices go wrong. It is not a gap assessment, which compares you to a list of controls and tells you what is missing. It is not a penetration test, which tells you whether one route in is open today. It is not the policy binder, and it is not a certificate, because no federal agency certifies anybody as HIPAA compliant. A real analysis starts from an inventory of where the information actually lives, the laptop that goes home to Canyon Country, the phone with the email on it, the imaging box nobody can patch, the cloud vendor, the backup, and then works through what could go wrong at each one and how badly it would hurt. The inventory is the part people skip, and an analysis built on a partial inventory is inaccurate by construction.
Why It Matters
It is the first document requested when something goes wrong. Not the training log, not the policies. A practice that can produce a current, environment specific risk analysis and the risk management plan that came out of it is having a very different conversation from one that cannot, even when the underlying incident is identical.
Required removes the argument. With an addressable item you can explain your alternative. Here there is nothing to explain, and that is why the finding appears so often: it is the cleanest thing for an investigator to establish. The mechanics of how one incident becomes several parallel processes for a regulated office are the subject of our piece on ransomware in a regulated practice, and the risk analysis is what shapes the opening position in all of them.
It is also the cheapest required item in the rule. The federal government publishes a free tool for exactly this, and the honest position is that a small practice can make a real start without hiring anyone. That makes its absence harder to explain than almost anything else on the list, and it is the same shape as the free IRS template our piece on the written plan most small firms do not have works through.
What Organizations Should Watch For
- A vendor checklist filed as a risk analysis. If the document is a list of yes and no answers with no inventory of where your information lives, it is a gap assessment wearing the wrong label.
- One done years ago and never revisited. A new practice management system, a cloud migration, a remote work arrangement or a new imaging device each change the environment the analysis was describing.
- Scope that stops at the main system. Email, phones, laptops, backups, the scanner, the vendor portal and the machine in the back room all hold or move the information, and a thorough assessment has to reach them.
- No risk management plan behind it. The second specification is equally required. An analysis that identified risks and led to no documented decisions is half the job, filed.
- No information system activity review. The fourth specification asks you to regularly review audit logs, access reports and incident tracking. Almost nobody does, and the logs are usually not even switched on.
- Anyone selling HIPAA certification. There is no such thing from a federal agency, and a vendor offering it has told you how carefully they read.
Recommended Actions
- Ask for the document, not the reassurance. The question is not whether the practice is compliant, it is whether somebody can put a dated risk analysis on the desk this week and say who wrote it.
- Build the inventory first. Every place electronic protected health information is created, received, stored or transmitted, including the ones that are inconvenient to admit. The analysis is only as accurate as this list.
- Start with the free federal tool if you are small. The Security Risk Assessment Tool from ONC and OCR is free, aimed at small and medium providers, and keeps your data on your own computer. Its own disclaimer is worth repeating: using it neither is required by nor guarantees compliance with the law.
- Write the risk management plan as you go. Each risk gets a decision: reduce it, and how, or accept it, and why. That document is the other required half and it is what turns an assessment into a program.
- Turn the logs on and put a date in the calendar to read them. A quarterly half hour with the access reports satisfies a required specification almost nobody meets and catches the quiet things.
- Redo it when the environment changes, not only when the year does. New system, new location, new vendor, new way of working. The anniversary is a floor and not the trigger.
The SecureLynx Perspective
Observe:
Across medical practices, accounting firms and law offices in the Santa Clarita Valley, this is the gap we find most reliably, and the practices that have it are usually the conscientious ones. They bought policies, they run the training, they keep the agreements. The risk analysis is missing because it is the only item in the rule that nobody outside the practice ever asks to see until the day it matters. The first pass is an inventory conversation rather than an audit, and it takes an afternoon.
Adapt:
Then the work is ordinary. Inventory where the information lives, assess each place honestly, write the risk management decisions that follow, and make sure the logging that the fourth specification assumes is actually switched on and read, which is standard access control and monitoring work rather than a project. The analysis and the plan live in the compliance record and are exportable from the client portal with the primary copy yours, so the document exists where somebody can find it under pressure. Where the environment itself is the risk, an unpatchable device or an end of life system, that is the segmentation argument our piece on the machine you cannot replace works through.
Protect:
The limits, stated plainly. We cannot certify anybody as compliant and neither can anyone else, and a practice that hears otherwise should ask the vendor to put it in writing. We are not your attorney, and whether a particular arrangement makes your firm a business associate is a question for counsel rather than for us. And we would rather tell you that the federal tool is free and you can start it yourself than sell you the first step, because a practice that does its own inventory understands its own environment better than any report we could hand over. What we are useful for is the part after that, and the part that has to keep running. Our pricing is published and the agreements are readable before you ever call.
Common questions
Is a HIPAA risk analysis required or addressable?
Required, and so is everything else in the same standard. The security management process at 45 CFR 164.308(a)(1) carries four implementation specifications and all four are required: risk analysis, risk management, a sanction policy, and information system activity review. Required means there is no alternative to document in its place, which is the opposite of an addressable item such as password management, where you may implement an equivalent measure and record your reasoning. The text of the risk analysis specification asks for an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. Two words in that sentence do most of the enforcement work: accurate, and thorough.
Does HIPAA apply to my accounting firm or law firm?
It can, and the trigger is the work rather than the industry. If your firm creates, receives, maintains or transmits protected health information on behalf of a covered entity, you are a business associate, and business associates are directly liable for compliance with the Security Rule and for notifying the covered entity of a breach. That is not a reading, it is how the Office for Civil Rights describes its own enforcement authority. A New York accounting firm learned it in an enforcement action after ransomware reached client health information on its network, paying $175,000 and accepting two years of monitoring. If your practice prepares filings, handles billing, does consulting or holds records for a medical client, the question is not whether HIPAA feels relevant. It is whether protected health information touches your systems.
Is a gap assessment or a vendor checklist the same as a risk analysis?
No, and confusing the two is the single most common way a practice believes it is covered when it is not. A gap assessment compares your practice against a list of controls and tells you which ones you do not have. A risk analysis starts from where electronic protected health information actually lives in your environment, identifies the threats and vulnerabilities to each of those places, and assesses the likelihood and impact of each one so that risks can be prioritized and reduced. A checklist can be a useful input to that work. It is not the work. Nor is a penetration test, a policy binder, or a certificate from a vendor, since no federal agency certifies anyone as HIPAA compliant and any company claiming to has told you something about itself.