The Security Rule Risk Analysis
The single most cited failure in OCR enforcement is the risk analysis at 45 CFR 164.308(a)(1)(ii)(A): an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of all electronic protected health information the entity holds. OCR runs a dedicated Risk Analysis Initiative, and its ransomware settlements almost always name a missing or inadequate risk analysis as the root failure.
An acceptable risk analysis is enterprise-wide and specific. It starts from an inventory of where ePHI is created, received, maintained and transmitted, identifies the threats and vulnerabilities for each of those systems, rates likelihood and impact, and produces a documented list of risks with owners. A questionnaire that answers yes or no to the Security Rule's standards is not a risk analysis, and OCR says so in its resolution agreements.
Risk management, the next paragraph of the rule, is where the analysis becomes action: security measures sufficient to reduce risks to a reasonable and appropriate level, tracked to completion. Both are required, and both must be repeated when the environment changes materially and reviewed periodically.
Key points
Scope: all ePHI
Every system, device, application and vendor that touches ePHI is in scope, including medical devices, cloud services, email and workstations. Scope gaps are the most common finding.
NIST SP 800-66 Rev. 2
NIST's implementation guide for the Security Rule, updated in 2024. It walks the risk assessment process from NIST SP 800-30 through each Security Rule standard and is the reference OCR points entities to.
Threat and vulnerability pairs
A risk is a threat exploiting a vulnerability with a consequence to ePHI. Ransomware exploiting unpatched remote access, an insider with excessive access, a lost unencrypted device: each is rated for likelihood and impact.
Documentation
The analysis, the risk register, the decisions and the dates. OCR asks for the document; an analysis that was performed but not written down is treated as not performed.
Frequency
The rule says periodically; OCR's guidance and settlements expect at least annually and after significant changes such as a new EHR, a merger, or a cloud migration.
Relationship to the Security Rule proposal
The 2025 proposed rule would make the technology asset inventory and network map explicit prerequisites of the risk analysis, and require the analysis be written and updated at least every 12 months.
Common mistakes
Gap assessment versus risk analysis
A gap assessment compares your controls to a checklist. A risk analysis identifies what could go wrong to your ePHI and how likely and severe it is. OCR accepts only the second.
Risk analysis versus risk management
Finding the risks is half the requirement. Entities are cited for analyses that found high risks that then sat untreated for years.
Enterprise versus system
A vendor's assessment of one product, or an IT team's review of one data center, does not cover the enterprise. The analysis must span every place ePHI lives.
Sources
; ;
See it in the live data.
Track NIST drafts and Federal Register rules