Let’s look at the historical approach from OCR when it comes to HIPAA Security Rule enforcement. Since 2005, the Office for Civil Rights (OCR) has relied on the carrot approach rather than the stick. The existing Security Rule defines risk analysis as the first required implementation of the first required standard. But the existing language provides no guidance about what a risk analysis is. It simply requires regulated organizations to “Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information…”.
Give the OCR some credit for trying. The Office issued many free and widely publicized guidance tools. Regulated entities seemed often not to listen. Organizations performed a gap analysis, or a compliance assessment, rather than a risk analysis. Organizations relied on vendors that boasted about their ability to conduct risk analysis, and then did something else different. Risk management plans that resulted from risk analysis were saved in a folder on the laptop or in OneDrive and never looked at again.
Which brings us to the current NPRM (Notice of Proposed Rule Making), where the OCR metaphorically throws away the carrot, uses the stick to goad the horse to the water, and makes the horse drink. This NPRM defines the eight (8) components that make up a risk analysis:
- Technology asset inventory and network map review
- Threat identification
- Vulnerability identification
- Security control assessment and review
- Likelihood of the threat exploiting vulnerabilities given implemented security controls
- Impact of the threat exploiting vulnerabilities given implemented security controls
- Risk level determination
- Assessment of risks posed by third-party vendors
The Agency goes even further, providing fairly detailed descriptions of what’s necessary to meet each of the 8 component items. Now the kicker comes should the rule become law. How do regulated entities prepare to ensure compliance?
3 Steps Regulated Entities Should Take to Improve Risk Assessment Processes
First, be sure that you understand the very real differences between risk analysis, compliance assessment and gap analysis. Risk analysis looks at everything in an organization that’s touches or is touched by ePHI. This includes people, processes, facilities and technologies. There’s a scoring methodology that determines a level of risk based on likelihood and impact. There’re probably risk rankings – perhaps critical, high, moderate and low. A compliance assessment is an audit. It’s a snapshot of the state of HIPAA compliance in the organization as of the date that the assessment is done. The OCR Audit Protocol is a tool that can be used to complete a compliance assessment. A gap analysis usually includes a partial assessment of an organization and is often used to provide a high-level overview of what safeguards are in place (or missing).
Second, look at your organization’s most recent “risk analysis.” Would the OCR think it was a risk analysis, or would they view it as a compliance assessment? Does it address your entire environment and all your ePHI enterprise-wide?
Third, if there’s not an up-to-date inventory of all your technology assets, start developing one now. Your asset inventory should identify what the asset is, what version it is, who’s accountable for it and where it’s located. Asset tracking, inventory control, and equipment management are crucial for maintaining an organized and efficient tech inventory. Implementing tracking software and barcode scanning can streamline the process and provide accurate and real-time information about your tech assets, and in some cases is surprisingly inexpensive.
Keep in mind there’s no such thing as a HIPAA Compliance Certification, so if a firm’s touting that as a possible outcome, consider it a warning sign.
If you’re realizing that the most recent compliance exercise won’t meet the OCR’s definition of a Security Risk Analysis, get one on the books now with a trusted consultancy. Keep in mind there’s no such thing as a HIPAA Compliance Certification, so if a firm’s touting that as a possible outcome, consider it a warning sign.
And if you’re one of the many organizations taking a deep dive into the certification process – SOC, HITRUST, etc. – for any of those to fly, you’ll need a recent, solid risk analysis.
Julia Huddleston works closely with organizations – business associates and covered entities, conducting security risk analyses, helping establish necessary compliance processes, and readying them for industry certification processes. She and Kevin Haralson bring deep healthcare industry experience to every client engagement. To schedule your free discovery call, contact Apgar and Associates today: 503-384-2538.