Back to articles
Healthcare Operations

The Foundation of Compliance: What Is a HIPAA Security Risk Analysis and Why Is It Failing Your Organization?

Dr. Jose I. Delgado
10 min read
HIPAA Security Baseline

Many healthcare leaders believe their organization has completed a HIPAA Security Risk Analysis because someone reviewed the firewall, installed antivirus software, or completed an online questionnaire.

That is not a comprehensive Security Risk Analysis.

A valid HIPAA Security Risk Analysis, commonly called an SRA, is a documented assessment of how electronic protected health information is created, received, maintained, transmitted, accessed, and protected throughout your organization.

It examines technology. But it must also examine your people, physical environment, daily workflows, vendors, policies, documentation, and decision-making processes.

When those areas are overlooked, the organization may have cybersecurity tools in place while still operating with serious compliance gaps.

That is why the SRA is the foundation of the HIPAA Security Rule.

The SRA Is a Legal Requirement

The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities affecting the confidentiality, integrity, and availability of electronic protected health information, or ePHI.

This is not an optional cybersecurity exercise.

It is a required component of the security management process.

The SRA should help your organization answer several critical questions:

  • Where does ePHI exist?

  • Who can access it?

  • How does it move through the organization?

  • Which systems, devices, facilities, vendors, and employees interact with it?

  • What threats could expose, alter, destroy, or make the information unavailable?

  • Which safeguards are currently in place?

  • Are those safeguards reasonable and effective?

  • What corrective actions are still needed?

  • Who is responsible for completing those actions?

  • How will remediation be documented and monitored?

The Security Rule does not prescribe one mandatory format for every organization. However, the assessment must be accurate, thorough, appropriately documented, and tailored to the organization’s actual operations.

A generic template that does not reflect your organization’s environment is not enough.

Why an SRA Is Not Just an IT Project

Information technology is an important part of the assessment, but technology represents only one portion of your risk.

An effective SRA evaluates administrative, physical, and technical safeguards. The Security Rule uses all three because healthcare information can be compromised through far more than a computer attack.

A comprehensive assessment should consider areas such as:

Workforce Practices

Your employees and contractors interact with sensitive information every day.

The SRA should examine:

  • Employee onboarding and offboarding

  • Access authorization

  • Role-based permissions

  • Security awareness training

  • Password practices

  • Remote work procedures

  • Sanction policies

  • Terminated employee access

  • Use of personal devices

  • Reporting of suspected security incidents

A sophisticated firewall cannot protect information when former employees retain access or current employees share passwords.

Operational Workflows

Your written policies may look compliant while your actual workflows tell a different story.

The assessment should evaluate how information is handled during:

  • Patient registration

  • Scheduling

  • Billing

  • Telehealth appointments

  • Clinical documentation

  • Email communication

  • Prescription management

  • Records requests

  • File transfers

  • Remote access

  • Mobile device use

  • Data disposal

  • Emergency operations

Compliance depends on what your workforce actually does, not only what your policy manual says it should do.

Physical Security

Electronic information can be exposed through physical access to equipment, workstations, server rooms, mobile devices, and facilities.

Your SRA should consider:

  • Workstation placement

  • Screen visibility

  • Facility access

  • Visitor controls

  • Server and network equipment security

  • Device storage

  • Laptop transportation

  • Lost or stolen devices

  • Paper records containing system credentials

  • Disposal or reuse of electronic equipment

Third-Party Vendors

Healthcare organizations increasingly depend on outside companies for hosting, billing, communications, data storage, analytics, telehealth, software support, and other critical services.

Every vendor relationship can introduce risk.

A comprehensive SRA should examine:

  • Which vendors create, receive, maintain, or transmit ePHI

  • Whether appropriate Business Associate Agreements are in place

  • Whether subcontractors are involved

  • How vendor access is authorized and terminated

  • Whether vendors have experienced security incidents

  • Whether contracts include security responsibilities

  • How vendors notify your organization of incidents

  • Whether vendor security practices are reviewed

  • Whether data can be retrieved if the vendor becomes unavailable

The federal SRA tool developed by federal health information technology officials and the HHS Office for Civil Rights includes asset and vendor management because these areas are integral to understanding an organization’s risk.

Why So Many SRAs Fail

Most failed SRAs do not fail because the organization did nothing.

They fail because the organization did something incomplete and believed it was enough.

Common problems include:

The Assessment Only Covers the EHR

Electronic protected health information may exist in email accounts, cloud storage, billing platforms, mobile devices, diagnostic equipment, backup systems, shared drives, text messages, spreadsheets, and vendor systems.

Reviewing only the electronic health record leaves major portions of the environment unassessed.

The Organization Uses a Generic Checklist

A checklist may help begin the process, but it does not automatically demonstrate an accurate and thorough analysis.

The assessment must reflect your organization’s actual systems, locations, workforce, workflows, threats, vulnerabilities, and safeguards.

The SRA Is Assigned Entirely to IT

Your IT provider may understand your network, devices, and technical controls.

It may not know whether terminated employees are removed promptly, whether staff members use personal email, whether vendor agreements are current, or whether employees bypass approved workflows.

The process requires participation from leadership, compliance, operations, human resources, clinical staff, information technology, and other relevant departments.

The Organization Identifies Risks but Does Not Manage Them

An SRA is not complete simply because risks were listed.

The Security Rule also requires organizations to implement security measures sufficient to reduce identified risks and vulnerabilities to a reasonable and appropriate level.

That means the organization needs a documented risk-management plan containing:

  • Identified deficiencies

  • Corrective actions

  • Assigned responsibility

  • Target completion dates

  • Priority levels

  • Progress updates

  • Supporting evidence

  • Leadership oversight

An unresolved risk that remains on the same report year after year may demonstrate that the organization knew about the problem but failed to address it.

The Assessment Is Outdated

HIPAA does not establish one universal rule stating that every regulated entity must conduct a completely new SRA on the same date each year.

However, risk analysis is an ongoing process. It should be reviewed and updated when there are environmental or operational changes that affect ePHI.

Examples include:

  • Opening or closing a location

  • Changing an EHR

  • Adding a new software platform

  • Beginning telehealth services

  • Expanding remote work

  • Changing vendors

  • Experiencing a security incident

  • Merging with another organization

  • Adding connected medical devices

  • Changing network infrastructure

  • Discovering new vulnerabilities

  • Making significant workforce changes

Many organizations use an annual review as their minimum internal compliance cycle. Certain federal programs also require eligible participants to complete and attest to Security Risk Analysis activities during the applicable calendar-year performance period.

An old SRA that no longer reflects your organization’s current operations cannot provide a reliable basis for decision-making.

The Difference Between an SRA and a Vulnerability Scan

A vulnerability scan uses technology to identify potential weaknesses in networks, devices, software, or configurations.

It can be an important part of the process.

It is not the entire SRA.

A scan may identify:

  • Missing software updates

  • Unsupported operating systems

  • Open ports

  • Weak configurations

  • Known vulnerabilities

  • Unprotected devices

A comprehensive SRA places those findings within the larger operational environment.

It determines:

  • Whether ePHI is affected

  • How likely the vulnerability is to be exploited

  • What the potential impact would be

  • Which safeguards already exist

  • Whether the remaining risk is acceptable

  • What corrective action is required

  • Who will complete that action

  • How completion will be verified

Technology identifies certain vulnerabilities. Risk analysis evaluates what those vulnerabilities mean to your organization.

The High Stakes of an Inadequate SRA

The Office for Civil Rights has repeatedly emphasized that risk analysis is foundational to HIPAA Security Rule compliance.

OCR has also established a Risk Analysis Initiative focused on investigations involving failures to perform accurate and thorough assessments. In April 2026, OCR announced four ransomware-related settlements under its enforcement activities, including matters associated with that initiative.

OCR has warned that failing to conduct a risk analysis can foreshadow a future breach because the organization may not know where its information is located or which safeguards are needed.

The consequences of an inadequate SRA may include:

  • Regulatory investigations

  • Corrective action plans

  • Financial settlements or civil monetary penalties

  • Breach-notification expenses

  • Business interruption

  • Ransomware recovery costs

  • Loss of patient confidence

  • Contractual disputes

  • Insurance complications

  • Increased legal exposure

  • Federal-program attestation concerns

The SRA often becomes one of the first documents requested after a breach, complaint, audit, or compliance review.

At that point, the organization is no longer preparing its story.

It is defending it.

When a Compliance Attestation Creates Additional Risk

Some federal healthcare programs require eligible participants to attest that Security Risk Analysis activities were completed during the applicable reporting period.

For example, current Medicare Promoting Interoperability and MIPS requirements include Security Risk Analysis and risk-management attestations for participating organizations or clinicians.

An attestation should never be treated as a routine checkbox.

A federal investigation involving a Kansas hospital alleged that the hospital falsely attested that it had conducted or reviewed required security risk analyses for federal EHR incentive-program reporting periods. The matter resulted in a $250,000 False Claims Act settlement.

This does not mean that every incomplete SRA automatically constitutes fraud.

It does mean that knowingly making an inaccurate compliance attestation can create exposure far beyond an ordinary documentation deficiency.

Leadership should be able to support every attestation with current, complete, and credible evidence.

Seven Signs Your Current SRA May Not Be Defensible

Your organization may need immediate assistance if:

  1. Your SRA is only a few pages long and consists mainly of yes-or-no answers.

  2. The assessment was completed without input from operations, human resources, compliance, or leadership.

  3. The scope does not identify every location where ePHI is created, received, maintained, or transmitted.

  4. Vendors, cloud platforms, mobile devices, remote workers, and connected equipment are missing.

  5. The report lists risks but does not include a documented remediation plan.

  6. The assessment has not been reviewed since major operational or technology changes occurred.

  7. Leadership has attested to compliance but cannot produce documentation supporting the organization’s conclusions.

The presence of any one of these problems does not automatically prove noncompliance.

It does indicate that your SRA deserves a closer review.

What an Effective SRA Should Produce

A professional Security Risk Analysis should leave your organization with more than a completed questionnaire.

It should produce a clear and defensible record of:

  • The assessment’s scope

  • The systems and information evaluated

  • The methods used

  • The individuals involved

  • The threats identified

  • The vulnerabilities identified

  • Existing safeguards

  • Likelihood and impact determinations

  • Assigned risk levels

  • Recommended corrective actions

  • Remediation priorities

  • Responsible parties

  • Target completion dates

  • Supporting evidence

  • Leadership review

  • Ongoing monitoring expectations

The final report should help leadership understand where the organization is exposed, what should be corrected first, and how available resources should be allocated.

Why Outside Review Matters

Internal teams understand the organization’s daily operations.

That familiarity is valuable, but it can also create blind spots.

Organizations frequently accept inherited workflows because “that is how we have always done it.” Employees may not recognize that routine practices create risk. IT providers may focus on technical controls while missing operational or contractual concerns. Leadership may assume that a completed questionnaire represents full compliance.

An independent assessment adds structure, objectivity, and accountability.

Taino Consultants Inc. helps healthcare organizations evaluate the full operational environment surrounding ePHI.

Our approach considers:

  • Technology and cybersecurity

  • Workforce access

  • Human resources practices

  • Physical safeguards

  • Clinical and administrative workflows

  • Vendor relationships

  • Business Associate Agreements

  • Policies and procedures

  • Incident-response readiness

  • Risk-management documentation

  • Leadership oversight

  • Federal-program attestation support

The goal is not to create another document that sits in a folder.

The goal is to provide a practical roadmap your organization can use to reduce risk and demonstrate a reasonable, organized compliance process.

Do Not Wait for an Incident to Test Your Foundation

A breach is one of the worst times to discover that your Security Risk Analysis was incomplete.

By then, regulators, attorneys, insurers, patients, business partners, and leadership may all be asking the same questions:

Where was the information?

What risks had been identified?

What safeguards were in place?

What corrective actions were taken?

Who was responsible?

Where is the documentation?

A comprehensive SRA helps your organization answer those questions before they become part of an investigation.

Your organization may already have strong security measures. It may also have risks that have gone unnoticed because no one has examined the entire environment.

The only responsible way to know is to conduct a thorough assessment.

Schedule Your Security Risk Analysis

Do not rely on assumptions, outdated reports, generic checklists, or incomplete technical reviews.

Taino Consultants Inc. can help you determine whether your current Security Risk Analysis accurately reflects your systems, workforce, vendors, facilities, and daily operations.

Schedule your SRA consultation today.

Our team will help you:

  • Define the appropriate scope

  • Identify operational and technical blind spots

  • Evaluate existing safeguards

  • Prioritize high-risk deficiencies

  • Develop a practical remediation roadmap

  • Strengthen your compliance documentation

  • Prepare for audits, investigations, attestations, and security incidents

Your HIPAA compliance program is only as strong as the risk analysis supporting it.

Build the foundation before someone else tests it.

Schedule your Security Risk Analysis with Taino Consultants Inc. today!

#BusinessAssociates #HealthcareLaw #VendorRiskManagement #HIPAA2026 #ExecutiveLeadership

About Dr. Jose I. Delgado

Dr. Jose I. Delgado is the founder and CEO of Taino Consultants, a veteran-owned, 8(a) graduate healthcare IT consulting firm based in St. Augustine, Florida. With over 30 years of experience in healthcare compliance and government contracting, Dr. Delgado has helped organizations navigate HIPAA, MACRA/MIPS, and federal IT security requirements.

Need help with healthcare compliance?

Taino Consultants provides HIPAA compliance consulting, MACRA/MIPS compliance support, and healthcare IT modernization services for government and private healthcare organizations.

Schedule a consultation