HIPAA

The HIPAA Security Rule Requirement That OCR Cites Most Often

Key Takeaways

  • 45 CFR 164.308(a)(1)(ii)(A) requires an accurate and thorough assessment of potential risks to all electronic protected health information
  • The requirement is organization-wide and covers ePHI wherever it is created, received, maintained or transmitted
  • Risk analysis is a required implementation specification, not an addressable one, so it cannot be satisfied by documenting a reasoned alternative
  • OCR has described risk analysis as an ongoing obligation rather than a one-time exercise
  • The Security Rule applies to business associates directly, not only through contract terms

What the Regulation Requires

The HIPAA Security Rule, at 45 CFR Part 164 Subpart C, sets standards for protecting electronic protected health information. Within the administrative safeguards standard on security management process, at 45 CFR 164.308(a)(1)(ii)(A), the regulation requires a regulated entity to “conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate.”

The paired implementation specification at 164.308(a)(1)(ii)(B) requires risk management: implementing security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. The two operate together. The analysis identifies risk; the management step addresses it.

Required, Not Addressable

The Security Rule divides implementation specifications into two categories. Addressable specifications permit a regulated entity to assess whether the specification is reasonable and appropriate in its environment and, where it is not, to document why and implement an equivalent alternative measure. Required specifications carry no such flexibility.

Risk analysis is a required specification. The flexibility the Security Rule otherwise grants, which allows entities to account for size, complexity, technical infrastructure and cost, applies to how safeguards are implemented rather than to whether the analysis is performed.

Scope: All ePHI, Everywhere It Lives

The regulation refers to electronic protected health information held by the entity, without limiting the assessment to particular systems. OCR guidance has consistently described the requirement as extending to ePHI wherever it is created, received, maintained or transmitted, across all of an organization's information systems, applications and devices.

Enforcement documents have repeatedly identified analyses that covered only part of an environment. Recurring gaps described in those documents include electronic media and portable devices, systems acquired through mergers or acquisitions, environments managed by vendors, and applications outside the core electronic health record.

OCR's Description of an Adequate Analysis

OCR's published guidance on risk analysis describes elements drawn from recognized risk-management practice rather than prescribing a single methodology. The guidance identifies the scope of the analysis, data collection about where ePHI resides, identification of potential threats and vulnerabilities, assessment of current security measures, determination of likelihood and impact, determination of the level of risk, and documentation.

The guidance states that the Security Rule does not prescribe a particular methodology, and that approaches will vary with the size and complexity of the organization. What the guidance does treat as fixed is that the analysis be accurate, thorough and documented.

An Ongoing Obligation

The Security Rule requires that security measures be reviewed and modified as needed to continue providing reasonable and appropriate protection. OCR guidance has described risk analysis as a continuous process rather than a discrete project, and has identified events that warrant review: the adoption of new technology, changes in business operations, a security incident, or the passage of time since the last assessment.

Resolution agreements have described situations where an analysis existed but predated significant changes to the environment it purported to cover.

Business Associates Are Directly Covered

Amendments made under the Health Information Technology for Economic and Clinical Health Act extended direct liability for Security Rule compliance to business associates. A vendor handling ePHI on behalf of a covered entity carries the risk analysis obligation itself, independent of the terms of its business associate agreement. Subcontractors that create, receive, maintain or transmit ePHI on behalf of a business associate are likewise covered.

Documentation Is Part of the Requirement

The Security Rule's documentation standard, at 45 CFR 164.316, requires that policies, procedures and required actions, activities and assessments be maintained in written form, retained for six years from the date of creation or the date last in effect, whichever is later, and reviewed periodically and updated as needed in response to environmental or operational changes.

The practical consequence is that an analysis performed without a durable record does not demonstrate compliance during an investigation. Resolution agreements have described entities that asserted an assessment had occurred but could not produce contemporaneous documentation of its scope, findings or resulting decisions.

Where This Sits Relative to Other Obligations

Risk analysis under the Security Rule is distinct from the Privacy Rule obligations governing use and disclosure, and from the Breach Notification Rule, which sets the process following an impermissible acquisition, access, use or disclosure of unsecured protected health information. An entity can satisfy one and not the others; enforcement documents have addressed all three.

The requirement also sits alongside state law. Several states impose their own security and notification duties on health information, and consumer health data statutes in some states reach information that HIPAA does not cover at all, such as data held by applications and wearables outside a covered entity relationship.

Background

For the underlying law rather than this development: Healthcare privacy law.

Frequently Asked Questions

Is a vulnerability scan or penetration test the same as a HIPAA risk analysis?
OCR guidance distinguishes them. A scan or test evaluates technical vulnerabilities in specific systems. The risk analysis required by 164.308(a)(1)(ii)(A) is broader, covering threats and vulnerabilities to all ePHI across the organization and assessing likelihood and impact. Technical testing can inform the analysis without constituting it.
Does the Security Rule specify how often a risk analysis must be repeated?
The regulation does not set a fixed interval. It requires that security measures be reviewed and modified as needed to continue providing reasonable and appropriate protection, and OCR guidance describes review as warranted by changes in technology, operations or the threat environment, as well as by the passage of time.
Does the Security Rule apply to paper records?
No. The Security Rule applies to electronic protected health information. Protections for protected health information in other forms, including paper and oral communications, come from the Privacy Rule.

Sources

Everything above is reported from these documents. Follow them to verify.

  1. 45 CFR §164.308, Administrative safeguards (HIPAA Security Rule) regulation
  2. HHS Office for Civil Rights, Guidance on Risk Analysis agency guidance
  3. HHS Office for Civil Rights, enforcement and resolution agreements agency release

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.