What Good Looks Like: A HIPAA Risk Analysis That Survives an HHS Audit

What Good Looks Like: A HIPAA Risk Analysis That Survives an HHS Audit
TL;DR
  • The HIPAA Risk Analysis is the most-cited finding in HHS Resolution Agreements over the past several years. The same gap appears repeatedly: the organization either has no Risk Analysis, has one that is years out of date, has one that does not cover ePHI in all its locations, or has one that exists as a checklist rather than an actual analysis.

  • A defensible Risk Analysis has a recognizable shape: documented scope covering ePHI in all its locations, methodology that identifies reasonably foreseeable threats and vulnerabilities, qualitative assessment of likelihood and impact, documentation of safeguards and residual risk, and integration with the organization's broader risk management.

  • The CEO question is not whether the organization has a Risk Analysis on file. It is whether the document produces the evidence HHS asks for first, demonstrates that the organization has actually analyzed risk rather than completed a template, and integrates with the organization's program operation.

Why the CEO Needs to Engage With the Risk Analysis, Not Just File It

A healthcare CEO walking into the executive review is rarely asked to read the organization's HIPAA Risk Analysis in detail. The compliance lead manages the document, the IT team contributes to its development, and the document goes into the program package. The CEO sees the executive summary at most.

The Risk Analysis is the document HHS asks for first during enforcement. The most-cited finding across recent Resolution Agreements is failure to conduct or update the analysis. CEOs who delegate this entirely to compliance produce organizations whose most important compliance document may not survive scrutiny.

CEOs who engage with the Risk Analysis substantively shape the document the organization defends. CEOs who do not, accept whatever the document produces, with the consequences landing on the organization when HHS reviews it.

 

What the HIPAA Security Rule Actually Requires From a Risk Analysis

The HIPAA Security Rule requires covered entities to "conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information." HHS guidance on the Risk Analysis names specific elements the analysis must include.

  1. The analysis must scope ePHI in all its locations: systems, devices, applications, vendor environments, paper records that contain or interact with electronic records, and any other location where ePHI exists. Scope decisions should be documented with rationale.

  2. The analysis must identify reasonably foreseeable threats: human threats (intentional and unintentional), technical threats (malware, system failure, unauthorized access), and environmental threats (fire, flood, power loss). The threat list should reflect the organization's specific environment, not a generic template.

  3. The analysis must identify vulnerabilities: technical, administrative, and physical weaknesses that threats could exploit. The vulnerability identification should be specific to the organization's actual systems, processes, and physical environment.

  4. The analysis must assess the likelihood that each threat would exploit each vulnerability and the impact if it did. The assessment can be qualitative (typically high/medium/low ratings) but should be defensible, with rationale documented.

  5. The analysis must document existing safeguards (administrative, technical, physical) and their effectiveness against the identified threats and vulnerabilities. Safeguards that exist but are not operating effectively should be noted.

  6. The analysis must document residual risk after safeguards are applied, with the organization's risk acceptance decisions explicit.

  7. The analysis must integrate with the organization's broader risk management, with material findings reaching the appropriate governance level.

A document covering all seven elements is what good looks like. A document missing any element produces gaps the framework cites.

 

The Five Risk Analysis Gaps That Show Up in HHS Findings

Across healthcare organizations preparing HIPAA risk analyses, five recurring gaps appear most often.

The first is incomplete scope. The Risk Analysis covers EHR systems but does not cover newer additions: cloud productivity platforms, telehealth systems, AI tools integrated with clinical workflow, vendor environments, mobile devices used by clinical staff. Each scope gap is a finding waiting to happen.

The second is generic threat language. The threats listed read like a template ("malware, unauthorized access, system failure") without specificity to the organization's actual environment. HHS investigators recognize template language and treat it as evidence the analysis was not actually conducted.

The third is missing vulnerability identification. The threats are listed but the vulnerabilities that would let them succeed are not. An analysis that lists "ransomware" without identifying the specific vulnerabilities (unpatched systems, weak access controls, missing endpoint security) does not satisfy the requirement.

The fourth is implausible likelihood-and-impact ratings. The analysis rates everything as "low likelihood, low impact" without rationale, or rates everything as "high" without distinction. Either pattern signals the assessment was not actually conducted; ratings should reflect the organization's specific posture and produce a meaningful distribution across categories.

The fifth is documentation drift. The analysis was current when written but has not been updated as the organization's environment changed. New systems, new vendors, new threats, new regulatory expectations have all appeared since the document was last touched. The drift is invisible in the document itself but visible to an investigator who notices the document references a system the organization no longer operates.

A Risk Analysis without these five gaps is rare. Most organizations have one or more, and the organizations that close the gaps before HHS surfaces them avoid the most-cited finding category.

 

Eight Questions a CEO Should Be Able to Answer About the Risk Analysis

A healthcare CEO reviewing the Risk Analysis substantively should ask specific questions.

  1. Does the scope cover ePHI in every location it actually exists, including newer systems and vendor environments? If the CEO can name a system the analysis does not address, the scope is incomplete.

  2. Are the threats described in language specific to the organization, or in template language that could apply to any healthcare organization? Specific language signals genuine analysis; template language signals a checklist exercise.

  3. Are the vulnerabilities tied to specific systems, processes, or physical conditions? Generic vulnerability lists do not satisfy the requirement.

  4. Do the likelihood and impact ratings produce a meaningful distribution? If everything rates the same, the assessment was not actually conducted.

  5. Are existing safeguards documented with their effectiveness against specific threats? Safeguards listed without effectiveness assessment do not demonstrate the analysis.

  6. Is residual risk explicit, with risk acceptance decisions documented? Acceptance language ("the organization accepts this residual risk because...") is what an investigator looks for.

  7. Is the document current? Recency means updated within the past year, with interim updates triggered by material environmental changes. A document over two years old is not current regardless of its quality when written.

  8. Does the document integrate with the organization's broader risk management? Material findings should reach the executive team and the board, with documented governance review.

A document that satisfies all eight questions is defensible. A document that fails any of them produces a gap.

 

Why "The Compliance Team Handles It" Produces the Most-Cited Finding

A healthcare CEO will hear, somewhere in the program discussion, this argument: the organization has a Risk Analysis on file, the compliance team handles it, and additional executive engagement on the document duplicates work that is already being done.

That is a false choice, and HHS Resolution Agreements have made the cost of believing in it visible. The Risk Analysis is the most-cited finding category. Organizations that delegate the document entirely produce documents whose quality varies widely; some are excellent, others have one or more of the five common gaps. Organizations that engage executively with the document, with the CEO substantively reviewing what the analysis says, produce documents that more consistently survive scrutiny.

The right framing is not whether the CEO needs to author the analysis. It is whether the CEO understands what the document says, can answer questions about it during executive interactions, and demonstrates the engagement HHS investigators look for as evidence of governance.

 

The Quality Review That Makes the Risk Analysis Defensible

A healthcare CEO should walk through a Risk Analysis quality review against the eight CEO questions. The exercise produces a one-page CEO summary of the analysis's current state, identifies any gaps relative to what HHS investigators look for, and produces a remediation plan if gaps exist.

CEOs who use this review describe the next regulatory interaction as recognizably calmer. The Risk Analysis is the document HHS asks for first; organizations whose CEOs have engaged with the document produce evidence the investigation reads favorably.

That is the difference between a Risk Analysis the organization filed and a Risk Analysis the organization defends.

 

The Risk Analysis Is the CEO's Evidence — Treat It That Way

A healthcare CEO who treats the HIPAA Risk Analysis as a compliance document the team handles is treating the most-cited finding category as someone else's responsibility. The document is the organization's evidence. The evidence either demonstrates the organization analyzed risk substantively or produces the gap HHS investigators most often cite.

If your organization has not produced a CEO-level review of the Risk Analysis against the eight quality questions in the last twelve months, that is the conversation worth having with your Tech-Operations partner before the next regulatory cycle.

Five Nines Technology Group is the Tech-Operations partner serving hospitals, clinic systems, and healthcare practices across the region. We focus on helping CEOs translate the HIPAA Risk Analysis into the kind of evidence HHS investigators read favorably.

Frequently asked questions

How often should the Risk Analysis be updated?

At least annually, with interim updates triggered by material environmental changes (new systems, new vendors, mergers, significant incidents, regulatory updates). Documents over two years old without updates are typically not current regardless of original quality.

Can the organization use a template Risk Analysis as a starting point?

Templates are useful for structure but not for substance. The actual threats, vulnerabilities, ratings, and safeguards should be specific to the organization's environment. Templates that produce documents reading like the template itself fail the framework's requirements.

Should the Risk Analysis be performed by internal staff or external partners?

Both models work. Internal staff bring deep understanding of the organization's operation; external partners bring specialty expertise and independence. Many organizations combine both, with internal staff providing context and external partners providing structure and depth.

What is the typical cost of a defensible Risk Analysis?

Variable by organization size and scope. Small clinics typically run in a low-five-figure range for initial analysis with annual updates costing less. Larger hospital systems run substantially higher. The cost is small relative to the consequences of a missing or inadequate analysis.

Should the board review the Risk Analysis?

The board should see substantive summaries with material findings, the organization's risk acceptance decisions, and remediation actions for gaps. Boards that see only check-the-box summaries provide weaker evidence of governance.

How does the Risk Analysis interact with the organization's vendor risk program?

The Risk Analysis should reference vendor environments where ePHI is handled, integrating with the vendor risk program for the specific assessment of vendor-side risks. The two programs are paired; gaps in either undermine both.

What does HHS examine first during enforcement?

The Risk Analysis is typically the first document requested. The completeness, recency, and substance of the document significantly shapes the investigation's trajectory. Organizations without a current Risk Analysis face more aggressive investigation.

Related Blog Posts

Telehealth Security: The BAA Chain Most Clinics Miss, and the CFO Vendor-Risk Gap

Telehealth Security: The BAA Chain Most Clinics Miss, and the CFO Vendor-Risk Gap

Why the Telehealth BAA Chain Is a CFO Responsibility A clinic CFO walking into telehealth budget discussions typically sees the primary platform line.

Read More
Where Cloud Productivity Stacks Create HIPAA Exposure, and the Executive Accountability Gap

Where Cloud Productivity Stacks Create HIPAA Exposure, and the Executive Accountability Gap

Why "The Platform Is Compliant" Answers the Wrong Question A clinic CEO asks the IT lead whether the cloud productivity platform is HIPAA-compliant....

Read More
What Good Looks Like: A Hospital Board's Annual Cyber Risk Briefing

What Good Looks Like: A Hospital Board's Annual Cyber Risk Briefing

Why the CEO Should Design the Board Cyber Briefing, Not Accept What IT Prepares A hospital CEO walking into the next annual board cyber briefing is...

Read More