Regulation · Filed · New York · 9 min read
HIPAA Risk Analysis: The Template OCR Actually Accepts
The structure, scope, and evidence expectations for a HIPAA risk analysis that satisfies 45 CFR § 164.308(a)(1)(ii)(A) — with the pitfalls OCR enforcement actions cite.
By Cyber Inspect Editorial Board
The single most cited deficiency
Missing or inadequate risk analysis is the most frequently cited deficiency in OCR enforcement actions. A defensible risk analysis is not a checklist — it is a documented, reproducible methodology aligned to NIST SP 800-30 or ISO 27005.
Structure that satisfies the rule
- Scope: every system, application, and process handling ePHI.
- Data collection: inventory of ePHI stores and flows.
- Threat identification: environmental, human, and technical.
- Vulnerability identification: technical and administrative.
- Likelihood and impact scoring.
- Risk determination and prioritized treatment plan.
- Documentation and periodic review.