Adding HIPAA risks to the Risk Management module

A handful of custom risks can be added to the risk assessment to meet HIPAA requirements

Written By Micah

If you adhere to HIPAA, we suggest adding a few risks to round out your risk assessment. These risks are very specific to a HIPAA environment and align with HIPAA regulations.

We also suggest controls from our library that best map to the risk; however, your organization may have documented custom controls that can also be applied to mitigate the risk.

The following are strongly suggested:

Risk Name & Category

Risk Description

Suggested Controls to Mitigate Risk

Media Sanitation [HIPAA]

(Physical)

Inadequate sanitation of media can result in the disclosure of passwords or login information, a data breach, unauthorized access to data, and unauthorized modification of user permissions.

Data Retention/Deletion, Temporary Files, Media Disposal, Media Disposal Procedures, Personal Information: Procedure to Destroy (and change the control description to be ePHI focused)

Compliant Business Associates Agreements [HIPAA]

(Legal)

Entering into data sharing agreements with an inaccurate (or no) business associates agreement opens the organization to fines, penalties, unauthorized sharing of sensitive information, and disruption of access to ePHI due to contract disputes.

Business Associates Agreements

Risk Awareness [HIPAA]

(Policy)

Lack of a robust risk management and awareness program and failure to identify new threats can lead to a failure to remediate known risks, can result in regulatory fines, penalties, a data breach, disruption of business and IT processes, unauthorized access to data, and exposure of data to bad actors.

Risk Assessment

Contracts

(Legal)

Inadequate contractual agreements can lead to an inability to hold third parties accountable to basic security standards and requirements which can compound reputational damage and financial repercussions from a data breach.

Contracts

Incident Management

(Technical)

Inadequate or no procedures to address security incidents can lead to the loss of confidential or sensitive data. Incidents may not be addressed timely, resulting in reputational damage or legal actions.

Incidents External, Incident Response: Employee Responsibility, Incident Response: Process, Incident Response: Responsibility, Incident Response: Testing

Corporate Monitoring

(People)

If board or management involvement is lacking, this may lead to poor corporate oversight and decision-making.

Internal Audit, Information Security Objectives, Board Oversight, OR Management Oversight

IT Security Governance

(Policy)

A lack of IT governance leads to a weakened control environment.

Policy Review, Internal Controls, Information Security Oversight, Information Security Policy

Network Security

(Technical)

Inappropriate access to backend systems can result in a data breach or security incident. For example, when systems allow users to bypass established network connection procedures, it can result in an insecure connection.

Firewall Rules, Wireless Networks, Vulnerability Scan, Intrusion Detection

The following are optional:

Risk Name & Category

Risk Description

Suggested Controls to Mitigate Risk

ePHI Data Flow [HIPAA]

(Legal)

Without cataloging and maintaining documentation on how and where ePHI is stored, received, maintained, or transmitted, can result in the misapplication of required HIPAA security safeguards.

Data Flow diagram, Asset Inventory (from a data asset perspective)

HIPAA Assessment [HIPAA]

(People)

Lack of awareness of current data security measures results in inadequate administrative, technical and physical safeguards being applied to protect ePHI.

Internal Audit, Independent Review

Integrity of ePHI [HIPAA]

(Access)

Lack of appropriate physical and logical access controls opens systems and data to inappropriate changes to ePHI and may compromise the integrity of the ePHI.

Logical Access, Physical Access Policy, Physical Access Review, User Access Review

Patient Access to ePHI [HIPAA]

(Privacy)

Poorly defined processes and lack of training on the timescale for providing access to ePHI results in fines.

Apply a control from the control library or create a custom control to address this risk.