A HIPAA security risk assessment assesses threats to the privacy and security of PHI, the likelihood of a threat occurring, and the potential impact of each threat so it is possible to determine whether existing policies, procedures, and security mechanisms are adequate to reduce risks and vulnerabilities to a reasonable and appropriate level. The requirements for covered entities and business associates to conduct a HIPAA security risk assessment appear twice in the Administrative Simplification provisions of the Health Insurance Portability and Accountability Act.
However, it may be necessary for organizations to conduct risk assessments beyond these requirements. The first requirement to conduct a HIPAA security risk assessment appears in the HIPAA Security Rule ( 45 CFR § 164. 308 – Security Management Process).
This standard requires covered entities and business associates to conduct an “accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI”. The second requirement appears in the HIPAA Breach Notification Rule ( 45 CFR § 164. 402 ).
This standard only applies when there has been an impermissible acquisition, access, use, or disclosure of unsecured PHI (in any format), and a HIPAA risk assessment is necessary to determine whether the event is notifiable to HHS and the affected individual(s). However, beyond the HIPAA security risk assessment requirements of the HIPAA Security and Breach Notification Rules, risks exist to the confidentiality, integrity, and availability of PHI when it is not in electronic format – for example, when unauthorized disclosures are made verbally or when a printed medical report is left unattended in an area of public access.
Because of these risks, it may be necessary to conduct a HIPAA privacy risk assessment which not only takes into account risks to the confidentiality, integrity, and availability of non-electronic PHI, but which also covers individuals’ access rights (to their PHI), Business Associate Agreements, and other Organizational Requirements of HIPAA. HIPAA Security Risk Assessment The objective of a HIPAA security risk assessment is outlined in the General Rules (CFR 45 § 164.
- that precede the Administrative, Physical, and Technical Safeguards of the HIPAA Security Rule. These are to: Ensure the confidentiality, integrity, and availability of all electronic PHI the covered entity or business associate creates, receives, maintains, or transmits. Protect against any reasonably anticipated threats or hazards to the security or integrity of such information.
Protect against any reasonably anticipated uses or disclosures of such information that are not permitted or required under subpart E of this part (the HIPAA Privacy Rule). Ensure compliance with this subpart (the HIPAA Security Rule) by its workforce. Note: This is achieved via security awareness training and the enforcement of a sanctions policy.
With regards to the Administrative, Physical, and Technical Safeguards of the HIPAA Security Rule, the General Rules allow a “flexibility of approach” in how the standards are implemented. Despite the flexibility of approach clause, it is important that all standards are implemented unless an implementation specification is not “reasonable and appropriate” and an equivalent alternate measure is implemented in its place.
The full list of Administrative, Physical, and Technical implementation specifications is: Standards Sections Implementation Specifications (R)=Required, (A)=Addressable Implementation Commentary Security Management Process 164. 308(a)(1) Risk Analysis (R), Risk Management (R), Sanction Policy (R), Information System Activity Review (R) Organizations should perform a comprehensive risk analysis to identify potential vulnerabilities to ePHI.
Develop and document a risk management strategy that prioritizes remediation activities. Enforce a sanction policy for employees who fail to comply with security policies, and implement tools for reviewing system activity regularly to detect any unauthorized access. Assigned Security Responsibility 164.
308(a)(2) (R) Assign a senior-level individual (such as a CISO or Privacy Officer) to be responsible for ensuring the implementation and oversight of security policies and procedures across the organization. This individual should have authority and resources to enforce HIPAA compliance. Workforce Security 164.
308(a)(3) Authorization and/or Supervision (A), Workforce Clearance Procedure (A), Termination Procedures (A) Establish and document procedures for supervising workforce members who access ePHI. Screen employees before granting access, and ensure prompt deactivation of accounts and access upon termination or role change to prevent unauthorized access. Information Access Management 164.
308(a)(4) Isolating Health Care Clearinghouse Function (R), Access Authorization (A), Access Establishment and Modification (A) Create controls to isolate systems that manage ePHI, especially if a healthcare clearinghouse is part of a larger organization. Define procedures for granting, modifying, and removing user access based on job roles. Access should be reviewed periodically and updated accordingly.
Security Awareness and Training 164. 308(a)(5) Security Reminders (A), Protection from Malicious Software (A), Log-in Monitoring (A), Password Management (A) Develop a formal training program that includes regular security updates, awareness of phishing and malware threats, instructions for recognizing suspicious activities, and best practices for password management.
Training should be documented and mandatory for all employees. Security Incident Procedures 164. 308(a)(6) Response and Reporting (R) Develop and maintain a written incident response plan that defines how to detect, report, and respond to security incidents.
Train staff on recognizing incidents, and test the plan through simulated exercises to improve readiness.
Originally published at hipaajournal.com