Skip to main content
Rethinking HIPAA Risk Assessments: A Technical ChallengeIncident & Breach Response
5 min readFor Data Privacy Officers

Rethinking HIPAA Risk Assessments: A Technical Challenge

The challenge

Your organization conducts HIPAA security risk assessments annually, focusing on electronic Protected Health Information (ePHI) as required by 45 CFR § 164.308. You've documented risks to confidentiality, integrity, and availability, assessed vulnerabilities, and filed the report.

Then a breach occurs involving printed medical reports left unattended in a public waiting area. Another incident involves a staff member verbally disclosing patient information in an elevator. Neither event triggers your existing risk assessment framework because neither involves ePHI. Yet both require breach notification determinations under 45 CFR § 164.402.

The issue isn't that your security risk assessment was poorly executed. It's that you've been solving only half the equation. The HIPAA Security Rule mandates assessment of ePHI risks, but PHI exists in multiple formats, and the Breach Notification Rule applies to "unsecured PHI (in any format)." Your risk assessment program hasn't caught up to this reality.

The environment and constraints

The regulatory framework creates a structural gap. The HIPAA Security Rule requires "accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI." It doesn't mandate assessment of non-electronic PHI risks.

Meanwhile, you're operating under the flexibility of approach clause in 45 CFR § 164.306, which allows variation in how standards are implemented. This flexibility is useful for tailoring technical safeguards to your environment, but it also creates ambiguity about scope. Can you implement only what's explicitly required and still maintain comprehensive protection?

Your constraints are practical:

  • You're already stretched thin managing the Administrative, Physical, and Technical Safeguards across 20 required and addressable implementation specifications.
  • Business Associate Agreements with vendors cover security obligations but don't always address privacy risks outside the electronic realm.
  • Your incident response plan (required under 164.308(a)(6)) focuses on system breaches, not physical document handling or verbal disclosures.
  • When an impermissible disclosure occurs, you face the breach risk assessment requirement: demonstrate low probability of compromise or notify HHS and affected individuals.

The real constraint is conceptual. Your team has been trained to think about HIPAA compliance as a security problem, not a comprehensive privacy protection program.

Expanding your approach

Organizations facing this challenge have expanded their risk assessment methodology to cover the "privacy surface area" beyond ePHI. This isn't about adding a separate privacy assessment as a parallel workstream. It's about integrating privacy risk factors into your existing risk management process.

Start by mapping PHI flows in all formats. Your security risk assessment already traces ePHI through systems. Extend this to printed records, verbal communications, and physical documents. Where do discharge summaries get printed? How are patient names called in waiting rooms? What happens to faxed referrals?

Then apply the four breach risk assessment factors from 45 CFR § 164.402 proactively, before an incident occurs:

  • Nature and extent: What types of identifiers appear in non-electronic formats? (Full names on appointment cards, diagnoses on paper charts, Social Security numbers on insurance forms)
  • Unauthorized persons: Who has physical access to areas where PHI might be visible or audible? (Cleaning staff, visitors, delivery personnel)
  • Actual acquisition: What physical controls prevent viewing? (Privacy screens, closed-door policies, document shredding)
  • Risk mitigation: What compensating controls exist? (Staff training on verbal disclosure policies, visitor sign-in procedures, secure document disposal)

Update your Business Associate Agreements to explicitly address non-electronic PHI handling. The required written contract standard in 164.308(b)(1) mandates that business associates comply with the HIPAA Security Rule and report security incidents. Extend this to require reporting of privacy incidents involving any PHI format.

Integrate privacy considerations into your existing implementation specifications. Under Workforce Security (164.308(a)(3)), add authorization requirements for staff who handle printed records. Under Facility Access Controls (164.310(a)(1)), include procedures for securing areas where paper files are stored. Under Security Awareness and Training (164.308(a)(5)), add modules on verbal disclosure risks and physical document handling.

Results and metrics

Organizations that have implemented comprehensive privacy risk assessments report fewer breach notifications requiring HHS reporting. This matters because frequent breach notifications can trigger compliance reviews by HHS' Office for Civil Rights.

The more significant outcome is operational. When your risk assessment covers all PHI formats, your incident response plan (164.308(a)(6)) becomes more effective. You're not scrambling to determine whether an incident is notifiable because you've already assessed the likelihood of compromise for common scenarios.

Your evaluation standard (164.308(a)(8)) becomes more meaningful. Instead of auditing only technical controls, you're assessing whether your entire privacy protection program is working. This creates better data for your annual security risk assessment under the Security Management Process (164.308(a)(1)).

Lessons learned

The primary lesson is timing. Don't wait for a non-electronic incident to expose gaps in your risk assessment program. The flexibility of approach clause allows you to implement standards in ways that fit your environment, but it doesn't exempt you from addressing all reasonably anticipated risks.

Organizations that got this right from the start integrated privacy risk assessment into their initial HIPAA compliance program. Those that didn't faced retrofit costs: updating policies, retraining staff, and revising Business Associate Agreements after discovering gaps during incident response.

The second lesson is documentation. When you conduct a breach risk assessment under 45 CFR § 164.402 to demonstrate low probability of compromise, you need evidence that you've considered all four factors. If you haven't proactively assessed non-electronic PHI risks, you're building that evidence in crisis mode.

Third, don't treat Business Associate Agreements as boilerplate. The requirement in 164.308(b)(1) to ensure business associates report security incidents should extend to privacy incidents. If your medical transcription vendor has a verbal disclosure incident, you need to know about it to conduct your own breach risk assessment.

Takeaways for your team

Review your current security risk assessment scope. Does it explicitly address non-electronic PHI? If not, you're compliant with the letter of 45 CFR § 164.308 but exposed to breach notification requirements under 45 CFR § 164.402 that you haven't proactively assessed.

Map your PHI lifecycle across all formats. Electronic systems are easier to inventory than physical document flows and verbal communication patterns. Invest the time to understand where non-electronic PHI exists in your environment.

Update your incident response plan to address privacy incidents beyond system breaches. Train your workforce on recognizing and reporting incidents involving printed records and verbal disclosures, not just cyberattacks.

Revise your Business Associate Agreements to explicitly cover privacy incident reporting. Don't assume that security incident reporting obligations automatically extend to non-electronic PHI handling.

Use the breach risk assessment factors proactively. The four factors in the Breach Notification Rule aren't just for post-incident evaluation. They're a framework for identifying privacy risks before they become notifiable breaches.

The HIPAA Security Rule requires assessment of ePHI risks. But comprehensive privacy protection requires assessing risks to PHI in all formats. Your organization can't afford to discover this gap during an incident response.

You Might Also Like