The HIPAA Security Rule Requirement That OCR Cites Most Often
Key Takeaways
- 45 CFR 164.308(a)(1)(ii)(A) requires an accurate and thorough assessment of potential risks to all electronic protected health information
- The requirement is organization-wide and covers ePHI wherever it is created, received, maintained or transmitted
- Risk analysis is a required implementation specification, not an addressable one, so it cannot be satisfied by documenting a reasoned alternative
- OCR has described risk analysis as an ongoing obligation rather than a one-time exercise
- The Security Rule applies to business associates directly, not only through contract terms
What the Regulation Requires
The HIPAA Security Rule, at 45 CFR Part 164 Subpart C, sets standards for protecting electronic protected health information. Within the administrative safeguards standard on security management process, at 45 CFR 164.308(a)(1)(ii)(A), the regulation requires a regulated entity to “conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate.”
The paired implementation specification at 164.308(a)(1)(ii)(B) requires risk management: implementing security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. The two operate together. The analysis identifies risk; the management step addresses it.
Required, Not Addressable
The Security Rule divides implementation specifications into two categories. Addressable specifications permit a regulated entity to assess whether the specification is reasonable and appropriate in its environment and, where it is not, to document why and implement an equivalent alternative measure. Required specifications carry no such flexibility.
Risk analysis is a required specification. The flexibility the Security Rule otherwise grants, which allows entities to account for size, complexity, technical infrastructure and cost, applies to how safeguards are implemented rather than to whether the analysis is performed.
Scope: All ePHI, Everywhere It Lives
The regulation refers to electronic protected health information held by the entity, without limiting the assessment to particular systems. OCR guidance has consistently described the requirement as extending to ePHI wherever it is created, received, maintained or transmitted, across all of an organization's information systems, applications and devices.
Enforcement documents have repeatedly identified analyses that covered only part of an environment. Recurring gaps described in those documents include electronic media and portable devices, systems acquired through mergers or acquisitions, environments managed by vendors, and applications outside the core electronic health record.
OCR's Description of an Adequate Analysis
OCR's published guidance on risk analysis describes elements drawn from recognized risk-management practice rather than prescribing a single methodology. The guidance identifies the scope of the analysis, data collection about where ePHI resides, identification of potential threats and vulnerabilities, assessment of current security measures, determination of likelihood and impact, determination of the level of risk, and documentation.
The guidance states that the Security Rule does not prescribe a particular methodology, and that approaches will vary with the size and complexity of the organization. What the guidance does treat as fixed is that the analysis be accurate, thorough and documented.
An Ongoing Obligation
The Security Rule requires that security measures be reviewed and modified as needed to continue providing reasonable and appropriate protection. OCR guidance has described risk analysis as a continuous process rather than a discrete project, and has identified events that warrant review: the adoption of new technology, changes in business operations, a security incident, or the passage of time since the last assessment.
Resolution agreements have described situations where an analysis existed but predated significant changes to the environment it purported to cover.
Business Associates Are Directly Covered
Amendments made under the Health Information Technology for Economic and Clinical Health Act extended direct liability for Security Rule compliance to business associates. A vendor handling ePHI on behalf of a covered entity carries the risk analysis obligation itself, independent of the terms of its business associate agreement. Subcontractors that create, receive, maintain or transmit ePHI on behalf of a business associate are likewise covered.
Documentation Is Part of the Requirement
The Security Rule's documentation standard, at 45 CFR 164.316, requires that policies, procedures and required actions, activities and assessments be maintained in written form, retained for six years from the date of creation or the date last in effect, whichever is later, and reviewed periodically and updated as needed in response to environmental or operational changes.
The practical consequence is that an analysis performed without a durable record does not demonstrate compliance during an investigation. Resolution agreements have described entities that asserted an assessment had occurred but could not produce contemporaneous documentation of its scope, findings or resulting decisions.
Where This Sits Relative to Other Obligations
Risk analysis under the Security Rule is distinct from the Privacy Rule obligations governing use and disclosure, and from the Breach Notification Rule, which sets the process following an impermissible acquisition, access, use or disclosure of unsecured protected health information. An entity can satisfy one and not the others; enforcement documents have addressed all three.
The requirement also sits alongside state law. Several states impose their own security and notification duties on health information, and consumer health data statutes in some states reach information that HIPAA does not cover at all, such as data held by applications and wearables outside a covered entity relationship.
Background
For the underlying law rather than this development: Healthcare privacy law.
Frequently Asked Questions
Is a vulnerability scan or penetration test the same as a HIPAA risk analysis?
Does the Security Rule specify how often a risk analysis must be repeated?
Does the Security Rule apply to paper records?
Sources
Everything above is reported from these documents. Follow them to verify.
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.