decisionhealth Newsletters, Part B News - 2026 Issue 2 (February)
Will your risk analysis stand up to scrutiny? Map out a plan
Subscribe or sign in to view the full article.
Article Overview
This article explains how healthcare organizations can evaluate and strengthen HIPAA Security Rule risk analysis efforts, with emphasis on OCR scrutiny, business associate oversight, breach preparedness, policy and procedure management, and use of HHS and NIST guidance resources. It is aimed at compliance, privacy, security, HIM, and leadership teams responsible for protecting electronic protected health information and coordinating risk management activities.
Why This Topic Matters
Strong risk analysis and preparedness processes are central to HIPAA Security Rule compliance and to reducing exposure from vendors, system dependencies, and security incidents. The article helps organizations understand the broad areas regulators and guidance materials expect them to address.
Article Sections
-
OCR scrutiny and the Comstar settlement
Introduces the regulatory focus on risk analysis, vendor oversight, and breach preparedness. It frames the article around lessons from a recent OCR settlement and broader HIPAA Security Rule expectations.
-
Know blind spots and safeguards
Discusses common gaps in risk analysis and the importance of assessing third-party exposure and security safeguards across the organization. It also addresses ongoing monitoring of business associate risk.
-
Take lessons from Comstar
Explores how organizations can learn from high-profile incidents and incorporate those lessons into routine preparedness efforts. The section focuses on using incident scenarios to examine exposure and resilience.
-
Treat policies and procedures like an owner’s manual
Covers the role of clear, current, and usable policies and procedures in HIPAA compliance. It also notes the importance of training and role-based implementation.
-
Focus on guidance and education
Reviews the non-prescriptive nature of HIPAA risk analysis language and points to HHS and NIST resources discussed in the article. It outlines the broad components referenced as part of a comprehensive assessment.
-
How to operationalize and modernize risk analysis
Describes how organizations can structure ongoing risk analysis and update it over time. It addresses the use of standardized frameworks and routine reassessment after organizational or security changes.
-
Coordinate contingency planning
Addresses contingency planning, business impact analysis, backups, recovery planning, and preparedness testing. It emphasizes coordination between risk assessment and emergency response readiness.
-
Resources
Lists external reference materials and links mentioned in the article. These resources support further review of OCR and NIST guidance.
What You Will Learn
- How OCR enforcement activity relates to HIPAA Security Rule risk analysis expectations
- Common risk analysis blind spots in healthcare organizations
- How business associate oversight fits into broader cybersecurity governance
- How policies, procedures, and training support risk management
- Which HHS and NIST resources are referenced for guidance
- How organizations can structure ongoing risk analysis and contingency planning
Who Should Read This
- HIPAA compliance professionals
- Health information management leaders
- Privacy officers
- Security officers
- Healthcare executives
- Risk management teams
- Vendor management teams
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com