decisionhealth Newsletters, Part B News - 2014 Issue 4 (April)
To avoid penalties, go beyond HHS’ HIPAA security risk analysis tool
Subscribe or sign in to view the full article.
Article Overview
This article explains the purpose of HHS’s HIPAA security risk analysis tool and why experts say it should not be treated as a complete compliance solution. It is aimed at healthcare practices, compliance staff, and technology vendors who need a better understanding of HIPAA security requirements, organizational risk assessment, and follow-up documentation and safeguards. The article also discusses related guidance from HHS, OCR, ONC, NIST, and regional extension centers, along with general considerations for business associate relationships and internal policy review.
Why This Topic Matters
HIPAA security risk analysis is a foundational compliance requirement, and gaps in how practices assess and document security risks can create exposure under HIPAA and meaningful use expectations. Understanding the article helps readers evaluate whether the HHS tool is sufficient for their organization and where additional compliance work may be needed.
Article Sections
-
What HHS released and who it is for
Introduces the risk analysis tool and the types of organizations it is intended to help. Summarizes the broader compliance context for practices and covered entities.
-
What the tool misses
Reviews concerns raised by experts about the tool’s depth, context, and ability to reflect real-world security assessment needs. Discusses issues related to organizational policies, safeguards, and related compliance materials.
-
If you analyze, also realize
Explains the need to follow a risk analysis with additional compliance follow-through. Covers general remediation, internal review, and coordination with outside advisers or consultants.
What You Will Learn
- How the HHS HIPAA security risk analysis tool fits into broader compliance efforts
- Why a risk analysis may need follow-up work after the initial assessment
- What kinds of organizational topics are relevant to HIPAA security reviews
- How external resources and consultants may support compliance planning
Who Should Read This
- Physician practices
- Practice managers
- HIPAA compliance staff
- Health IT vendors
- Healthcare consultants
- Business associates
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com