What You'll Need Before You Start
A healthcare security risk assessment is a documented review of where patient data lives, who can reach it, and what could go wrong. The goal is simple: find the gaps before someone else does.
At Tech Dynamix, we help practices across Northeast Ohio work through this process every year. Most of them start with good intentions and no plan.
Here is what to gather first:
- A current list of every system that touches patient data
- Your HIPAA Privacy and Security policies
- Network diagrams, even rough ones
- Vendor contracts and business associate agreements
- Login records for your EHR, billing, and email systems
- A named person to own the project
The HHS Security Risk Assessment Tool walks small practices through each step. It is free and built for teams without a security officer.
One warning before you begin: a risk assessment is not a one-time form. It is a living document you revisit as systems change.
Step 1: Define the Scope of Your Healthcare Security Risk Assessment
Scope decides what you are protecting and what you are leaving out. Get this wrong and every later step drifts.
Start with these boundaries:
- Which locations? One office, or five across Lake County?
- Which systems? EHR, billing, email, phones, imaging, backup drives.
- Which people? Staff, contractors, remote workers, outside vendors.
- Which data? Records, claims, payment details, scheduling notes.
Write the scope down in one page. Have your practice administrator sign it.
For a small practice, the scope is usually tighter than people expect. A 15-person office may run one EHR, one billing platform, and a shared file server. That is manageable. The risk comes from the tools nobody listed, like a personal phone syncing work email.
Pro Tip: The systems people forget are the ones that cause breaches. Ask each employee to list every device and app they use for work, including personal phones and home laptops.
Step 2: Inventory Systems, Devices, and Data Flows
An inventory lists every asset and traces where data moves. You cannot protect what you have not counted.
Build your inventory in four buckets:
- Hardware: servers, workstations, laptops, tablets, printers, routers
- Software: EHR, billing, scheduling, email, antivirus, backup tools
- Data: patient records, claims, payment data, staff files
- People: who touches each system, and how
Then map the flow. Patient data enters at the front desk, moves to the EHR, goes to billing, and lands in a backup. Each handoff is a place where data can leak.
Most small practices find 20 to 40 assets once they look properly. That number surprises them.
| Asset Type | Common Examples | Who Owns It |
|---|---|---|
| Hardware | Servers, laptops, routers | IT lead or vendor |
| Software | EHR, billing, email | Practice administrator |
| Data | Records, claims, payments | Compliance officer |
| People | Staff, contractors, vendors | Office manager |
Step 3: Identify Threats and Vulnerabilities
A threat is something that can cause harm. A vulnerability is a weakness that lets it happen.
Common threats for small practices:
- Ransomware locking your EHR
- Phishing emails that steal login details
- Lost or stolen laptops and phones
- Staff sharing passwords
- Vendors with weak security
- Power outages and failed backups
Common vulnerabilities:
- No multi-factor authentication
- Unpatched software
- Shared logins with no audit trail
- No written security training
- Backups stored on the same network
Pair each threat with the weakness it exploits. That pairing becomes the basis for scoring in the next step.
Watch Out: Skipping the threat list and jumping straight to fixes is the most common mistake. You end up buying tools that do not address your actual risks.
Step 4: Score Risks and Assign Ownership
Scoring tells you what to fix first. Without it, every problem looks urgent and nothing gets done.
Use a simple scale. Rate each risk on likelihood and impact, each from 1 to 5. Multiply the two numbers. Anything scoring 15 or higher gets fixed this quarter.
| Risk | Likelihood | Impact | Score | Owner |
|---|---|---|---|---|
| Phishing steals EHR login | 5 | 5 | 25 | IT lead |
| Lost laptop with patient data | 4 | 4 | 16 | Office manager |
| Backup fails during outage | 3 | 5 | 15 | IT vendor |
| Shared front desk password | 4 | 3 | 12 | Practice admin |
Every risk needs one named owner. Not a department. A person.
This is where most assessments stall. A list of risks with no owner sits in a folder and never moves. Assign the name, set a date, and check it monthly.
Step 5: Document Findings With a HIPAA Risk Assessment Template
A HIPAA risk assessment template turns your notes into evidence. Auditors and insurers want to see the process, not just the result.
Your documentation should include:
- Scope statement and date
- Full asset inventory
- Threat and vulnerability list
- Risk scores with owners
- Remediation plan with deadlines
- Sign-off from leadership
The HHS guidance on risk analysis is clear that the analysis must be documented and reviewed. A verbal walkthrough does not count.
Store the finished document somewhere you can find it fast. When a payer or auditor asks, you want it in minutes, not days.
Key Takeaway: The assessment document is the deliverable. If it is not written down and dated, it did not happen.
Step 6: Build a Remediation Plan With Healthcare Cybersecurity Best Practices
A remediation plan lists what you will fix, who owns it, and when it is due. Pair it with proven security habits.
Start with these healthcare cybersecurity best practices:
- Turn on multi-factor authentication everywhere
- Patch systems on a set monthly schedule
- Train staff on phishing every quarter
- Test backups by restoring a file
- Limit access to only what each role needs
- Review vendor agreements each year
Set deadlines that match your risk scores. High scores get fixed first. Lower scores can wait a quarter, but they still need a date.
Revisit the plan every 90 days. New devices and new staff create new risks.
For practices across Northeast Ohio, a local IT partner can run the technical pieces while your team handles policy and training. That split keeps the work moving.
A HIPAA Compliance Checklist for Small Practices
A HIPAA compliance checklist for small practices keeps the yearly work on track. Use it as your calendar, not a one-time to-do list.
- Name a security officer
- Complete a written risk assessment
- Inventory every device and system
- Enable multi-factor authentication
- Patch systems monthly
- Train staff on phishing quarterly
- Test backups by restoring files
- Sign business associate agreements with every vendor
- Review access rights twice a year
- Document everything with dates
If you would rather not run this alone, Tech Dynamix handles the technical side for practices across Northeast Ohio. Our team provides layered cybersecurity protection watched around the clock and evidence-ready compliance for HIPAA. The same people learn your systems, so nobody reads your account cold.
Frequently Asked Questions
What are the steps of a healthcare security risk assessment?
A full healthcare security risk assessment runs in six steps: define the scope, inventory your systems and data flows, identify threats and vulnerabilities, score each risk by likelihood and impact, document your findings against a HIPAA template, and build a remediation plan with owners and deadlines. At its core it comes down to four actions: know what you have, know what threatens it, rank the risks, and write down how you will fix them. Skipping any step leaves gaps in your HIPAA documentation, which matters if OCR ever reviews your practice.
Is a security risk assessment required by HIPAA?
Yes. The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information. It is not optional, and it is not a one-time task. You must be able to show your work if the HHS Office for Civil Rights requests documentation.
How often should a healthcare organization perform a security risk assessment?
Most practices should run a full healthcare security risk assessment annually and update it whenever something material changes: new software, new locations, new staff, or a breach. Smaller clinics often treat it as a yearly exercise tied to their HIPAA compliance checklist for small practices. If you add a new EHR module or move to a new office, revisit the assessment before that change goes live.
What tools are available for HIPAA security risk assessments?
You can use a spreadsheet-based HIPAA risk assessment template, the HHS Security Risk Assessment Tool, or a managed IT partner who runs the assessment and documents it for you. The tool matters less than the process: scope, inventory, threat identification, scoring, and a written remediation plan. Many Northeast Ohio practices hand this to a partner so the documentation stays evidence-ready.
Managing HIPAA security alone is a lot to carry, especially when you are also running a practice. Tech Dynamix gives you one partner instead of three, with proactive problem prevention, round-the-clock monitoring, and evidence-ready HIPAA documentation. Schedule a free consultation with our Northeast Ohio team and get a clear plan for your next risk assessment.