Miami, FL

302-205-0504
All articles

What is a risk analysis, and does my practice need one?

Short answer: it is four questions, answered and written down. If HIPAA applies to you, it is the single document a regulator is most likely to ask for, and many small practices do not have one.

I am Scott Derby, I am an attorney. If your practice has a HIPAA breach, or a client files a complaint, a regulator opens an investigation. When that happens, one document matters more than any other. Your written risk analysis. Many small practices do not have one. Others have a document they believe is one, and find out during the investigation that it is not.

That is not just my opinion. Since late 2024, the Office for Civil Rights, which is the agency that enforces HIPAA, has been focused on one thing above all else: whether a practice has a risk analysis.

How does the Office for Civil Rights end up looking at your practice? It almost always starts the same way. Someone reports a breach, or a client files a complaint. That is what gets you noticed. And once you are noticed, the risk analysis is one of the first documents they ask for.

So what is a risk analysis? Underneath the regulatory language, it is four questions.

One. Where do you keep your clients’ information? Make a list of every single place. Your laptop. Your phone. Your email. Your scheduling software. The notes app you use between sessions. The backup drive you set up once in 2019 and have not thought about since.

Two. At each of those places, how could a person who should not see that information end up seeing it? Or how could you lose it for good? The laptop gets stolen out of your car. The phone gets left in a restaurant. Someone guesses your email password. A file goes to the wrong client by mistake.

Three. For each of those problems, how likely is it really? A laptop that never leaves a locked office is one thing. A laptop that rides around in your car all week is another.

Four. If one of those things actually happened, how badly would your clients be hurt? One appointment time getting out is not the same as ten years of session notes getting out.

Answer those four questions. Then write the answers down.

Writing it down is the part people skip. Do not skip it. If a regulator asks to see your risk analysis, you have to hand them something. On your computer or by hand on a piece of paper, it does not matter. It just has to exist.

Two more things. A risk analysis is not the same as fixing what you find. That next step is risk management, and the rule requires you to reduce the risks you identify to a reasonable and appropriate level.

And you may hear that HIPAA requires an annual risk analysis. It does not. The Security Rule sets no schedule at all, and the government’s own guidance says so. The annual requirement people are thinking of comes from Medicare’s Promoting Interoperability and MIPS programs, in a different part of the code, and it binds you only if you take part in those programs. What the Security Rule does require is that you revisit as things change. In its own words, the process should be ongoing.

If you do nothing else this quarter, write down every place your clients’ electronic information lives. Most practices find something they had forgotten about. That list is not the whole risk analysis, but it is where every real one starts.

This is general information about federal HIPAA. It is accurate as of writing and it can change. Your state very likely has its own privacy rules that sit on top of HIPAA and can be stricter, so treat this as a starting point rather than the final word, and check what applies where you practice. This is education, not legal advice for your specific situation.