Medicare Compliance & Reimbursement - 2022 Issue 4
Reader Questions: Keep Compliant With HIPAA Risk Analysis
Subscribe or sign in to view the full article.
Article Overview
This reader question addresses HIPAA Security Rule compliance planning for covered entities and business associates. It explains the difference between a narrower gap analysis and a more comprehensive risk analysis, drawing on guidance from the HHS Office for Civil Rights (OCR). The article is aimed at privacy, compliance, and security teams that need a general understanding of how risk assessment approaches fit into HIPAA planning and documentation.
Why This Topic Matters
Organizations subject to HIPAA need a clear understanding of the type of assessment they are using and how that assessment supports Security Rule compliance. This article helps readers evaluate whether a limited gap review is sufficient for their purposes or whether a broader risk analysis is more appropriate.
Article Sections
-
Question
Introduces a reader question about substituting one type of HIPAA compliance review for another. The focus is on whether a simpler assessment approach can replace a more comprehensive one.
-
Answer
Provides a general response about HIPAA compliance planning and references OCR guidance on assessment scope and methodology. It also outlines broad activities commonly included in a risk analysis process.
What You Will Learn
- How gap analysis and risk analysis differ at a high level in HIPAA planning
- Why OCR guidance is relevant to Security Rule compliance assessments
- What broad steps are commonly associated with a risk analysis process
- How organizations may think about scope, documentation, and ongoing review in compliance planning
Who Should Read This
- HIPAA compliance officers
- Privacy and security officers
- Healthcare administrators
- Business associates
- Covered entities
- Healthcare compliance teams
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com