The Risk Assessment Your Practice Signs Off On Every Year
Somewhere in your practice there's supposed to be a document. It's dated within the last year, it lists everywhere patient data lives, what could go wrong, and what you've done about it, and it has a name attached to it. HIPAA calls it a security risk analysis, and if an auditor, an insurer, or a Medicare attestation ever asks for yours, "we take security seriously" is not an acceptable substitute for the document.
If you're confident yours exists and is current, you can stop reading. If you hesitated, the objections below are probably why. They're the same ones we hear from every small practice, and each one sounds reasonable right up until you look at it closely.
"Our EHR vendor handles HIPAA."
This is the most common one, and it's the most expensive to believe.
Your EHR vendor secures their software. That's real, and it matters. But your obligation under the HIPAA Security Rule covers everywhere electronic patient information goes, and in a working practice that's a much bigger map than the EHR: the front-desk computers, the email account patients send things to, the laptop that goes home, the Wi-Fi the billing workstation sits on, the staff logins nobody has reviewed since the last hire, the old machine in the back that still turns on.
The vendor is responsible for their product. The practice is responsible for the practice. No business associate agreement transfers that, and when something goes wrong on your side of the line, the vendor's compliance doesn't cover you.
"We did a risk assessment when we set up the EHR."
That assessment was real, and it's done its job. The rule requires the analysis to reflect your practice as it operates now, and a practice drifts more in a few years than it feels like from inside: staff have turned over, a portal got added, someone started texting with patients, machines were replaced, and a telehealth setup appeared in 2020 and never got looked at again.
There's also a yearly signature involved for many practices. Practices reporting through Medicare's quality program attest each year that a security risk analysis was conducted for that period, and that the problems it found were actually addressed. Both parts. That attestation goes in annually, with a dated document expected behind it, so an assessment from the EHR install era isn't just stale. It doesn't back up what someone in your practice is signing.
"We're a small practice. Nobody's auditing us."
Two problems with this one.
First, regulators aren't the ones who usually find you. The event that exposes a missing risk analysis is a breach, a stolen laptop, a hijacked email account, and small practices get hit with those constantly, precisely because attackers assume nobody's watching the small ones. When a breach gets investigated, the first document requested is the risk analysis, and a missing or template-grade analysis is one of the most commonly cited failures in enforcement cases. The fine isn't for being breached. It's for never having looked.
Second, your cyber insurance already audits you. Renewal questionnaires now ask directly about risk assessments, MFA, and backups, and an answer that doesn't survive a claim investigation is a denied claim at the worst possible moment.
"Fine. So what does one actually involve?"
Less than the word "audit" makes it sound, at small-practice scale. A real security risk analysis for a practice your size:
- Maps where patient data actually lives. EHR, email, phones, scanners, billing systems, backups, and the paper-adjacent stuff everyone forgets, like the shared drive of scanned insurance cards.
- Names what could realistically go wrong. Not theoretical hospital scenarios. A stolen laptop, a phished email account, a staff departure where nobody removed access, a ransomware email opened at the front desk.
- Records what's protecting each of those today. Encryption on or off, MFA on or off, backups tested or assumed, and who can access what.
- Documents the gaps and what you're doing about them. Dated, written down, with the follow-up recorded. This last part is the one that counts twice: it's what the annual attestation asks about, and it's what an investigator reads first.
The free checklist versions of this fail the same way template WISPs fail for accountants: a column of boxes marked yes, contradicted by the first laptop anyone actually inspects. A risk analysis that doesn't match your real machines isn't compliance. After a breach, it's an exhibit.
What to check at your practice this week
- Can you put your hands on a dated risk analysis from the past year? If finding it would take more than a few minutes, treat that as a no.
- Could you list, from memory, three places patient data lives outside the EHR? If you can't, neither can your risk analysis.
- Is MFA on for email? Log in and check. Email is where practice breaches actually start.
- Whatever your last assessment flagged, did anyone fix it? An assessment with unaddressed findings is worse than none in one specific way: it's proof you knew.
If those four came back clean, your practice is in better shape than most. If they didn't, the fix is a scoped project, not a life change, and it's dramatically cheaper before the bad day than after.
Assessing where a practice actually stands and putting the documentation in order is work we take on for independent practices. Book a 15-minute review and we'll walk through where yours stands, no strings attached.
Tech 360 Solutions provides managed IT and cybersecurity for small businesses in the Kansas City metro. Built for HIPAA, FTC Safeguards, and other regulated environments.