Call Us Today! 877-659-2467

NIST OCR conference highlights

HIPAA Risk Analysis Is More Than a Checklist

The message from the NIST OCR conference was clear: a HIPAA risk analysis is not a checklist. It must be comprehensive, accurate, and specific to your organization. Once a thorough and accurate risk analysis is completed, then the mitigation process must be documented. Again, not simply a checklist.

Where is ePHI?

The risk analysis must identify every location where electronic protected health information (ePHI) is created, received, maintained, or transmitted. This includes EHR systems, email, mobile devices, cloud applications, medical equipment, patient portals, billing platforms, databases, websites, backups, and third-party vendors.

Medical practices must map how ePHI flows into, throughout, and outside their systems. This data-flow mapping helps identify unauthorized access, transmission, storage, and disclosure risks that a simple checklist may overlook.

Risk Management

Identifying vulnerabilities is only the beginning. The practice must maintain a documented risk management plan that:

  • Prioritizes identified risks
  • Lists the corrective actions taken
  • Assigns responsibility
  • Establishes completion dates
  • Demonstrates how each vulnerability was mitigated
  • Documents any remaining risk the organization accepts

What is NOT a Risk Analysis?

Several security assessments can support the process, but they do not replace an SRA:

  • A penetration test is useful, but it is not an SRA.
  • A vulnerability scan is useful, but it is not an SRA.
  • A gap analysis is helpful, but it is not an SRA.
  • Completing the HHS SRA Tool does not create a compliant risk analysis if questions are unanswered or marked “Don’t Know.”

Another common problem is leaving the physical safeguards section incomplete. An SRA must evaluate administrative, physical, and technical safeguards and not just cybersecurity controls.

Integrating AI

Before adding an AI tool to a medical practice, the organization should complete the proper privacy, security, and compliance review. Determine whether the AI vendor will access, store, or transmit ePHI. Understand where the data is stored and whether it is used to train AI models. Update the organization’s risk analysis and data-flow map. Establish user access controls, authentication, encryption, and audit logging. Whether ePHI will be shared with third party vendors. Create policies for appropriate AI use and human review. Once this is outlined, then the organization must:

  • Develop procedures for errors, security incidents, and potential breaches
  • Train employees on privacy risks and prohibited uses
  • Obtain a Business Associate Agreement
  • Address patient consent and state-law requirements when applicable

AI can improve efficiency, but it should not be integrated until the practice understands how patient information will be handled and has documented safeguards in place.

Breach Notification

The breach notification clock starts when the breach is discovered, not when the investigation is completed. An organization should not delay the required notification solely because the final number of affected individuals is unknown. File the initial breach report within the applicable deadline using the best information available, and submit an addendum when the investigation confirms the affected-record count or provides additional details. Be sure to follow state law requirement if they are more stringent.

FTC and HIPAA

The FTC does not enforce HIPAA. That responsibility belongs to HHS’s Office for Civil Rights (OCR). However, the FTC can intervene when a healthcare organization’s conduct involves an unfair or deceptive business practice under the FTC Act. A provider could face FTC scrutiny if it misrepresents how patient information is protected. For example, the practice has a “Seal of HIPAA Compliance” on their website and fails to use reasonable security safeguards. The use of online trackers may be sharing health information with advertising or tracking companies contrary to their privacy promises. Therefore, HIPAA compliance does not automatically protect an organization from FTC enforcement. The FTC’s separate Health Breach Notification Rule (HBNR) generally applies to health apps, personal health-record vendors, and related businesses that are not regulated by HIPAA; in some situations, an organization with both HIPAA-regulated and consumer-facing operations may have obligations under both regulatory frameworks.

Summary

The NIST OCR conference clarified the HIPAA compliance requirements. It is crystal clear that more enforcement in on the way due to the increased data breach activity and the lack of documented compliance efforts. They even specifically mentioned that even small providers are required to implement reasonable and appropriate safeguards. No provider is immune from investigations and enforcement.

Protect Your Organization and Your Patients Before It’s Too Late

At Aris Medical Solutions, our HIPAA Keeper cloud-based platform makes HIPAA compliance simple. It guides your organization through every requirement with a clear, step-by-step process. From risk analyses and policies to employee training and required documentation, you’ll have everything needed to remain compliant, protected, and audit-ready. Best of all, your HIPAA Compliance Officer is never on their own. Every client has access to a Certified HIPAA Security Analyst who provides expert guidance, answers questions, and helps ensure your compliance program is implemented correctly.

Schedule a free HIPAA checkup today at Aris Medical Solutions.

©2026 Aris Medical Solutions – HIPAA Risk Management | HIPAA Compliance Consultants | All Rights Reserved | Terms and Conditions | Privacy Policy
The content and images on this website is owned by Aris Medical Solutions and their owners. Do not copy any content or images without our consent.
Powered by Bandwise LLC