The Conventional Wisdom
The compliance community often treats risk analysis as a sacred practice. Recent settlements by the Office for Civil Rights (OCR) with four entities, totaling $1,165,000 after ransomware breaches affecting over 427,000 individuals, suggest that comprehensive risk analysis is seen as the first line of defense against ransomware. Industry advisors claim that thorough documentation of your electronic protected health information (ePHI) flows, complete asset mapping, and frequent vulnerability scans will prevent future attacks.
This narrative is gaining traction with the proposed HIPAA Security Rule amendments, expected by May 2026. These amendments would make asset inventories, ePHI mapping, and vulnerability management mandatory, rather than optional. The underlying message is clear: better risk analysis leads to better security outcomes.
Why We Disagree
Risk analysis alone doesn't stop ransomware. Technical controls do.
The recent settlements all cited inadequate risk analysis under 45 C.F.R. § 164.308(a)(1)(ii)(A). However, these organizations likely weren't breached due to incomplete risk analysis documentation. They were breached because their technical controls failed.
OCR uses risk analysis as a compliance measure for security posture because it's easier to audit documentation than to evaluate the effectiveness of your network segmentation. When OCR investigates a breach, they can't reconstruct your pre-incident control effectiveness, but they can review your documentation of potential vulnerabilities and planned remediation. This isn't the same as having effective controls in place.
OCR's corrective action plans require asset inventories, ePHI flow mapping, vulnerability scans, penetration testing results, and documented control reviews. These are audit artifacts. For example, the Consociate plan requires "a complete inventory, vulnerability scans, and penetration testing" as part of risk analysis. However, vulnerability scans don't patch systems, and penetration test reports don't implement multi-factor authentication. Documentation doesn't encrypt data at rest.
The proposed Security Rule amendments highlight this gap. They would mandate encryption of ePHI, multi-factor authentication, network segmentation, audit logs, and specific vulnerability management practices. These are technical controls, not outputs of risk analysis. If comprehensive risk analysis actually prevented breaches, OCR wouldn't need to prescribe these controls.
The Evidence
The settlements describe control and process failures, not documentation failures. Two entities faced citations for impermissible disclosures of ePHI, and one failed to notify affected individuals within the required timeframe.
The proposed amendments estimate over $9 billion in first-year implementation costs for regulated entities, with about $6 billion in recurring annual costs for subsequent years. This isn't the cost of better documentation; it's the cost of implementing necessary controls like encryption, multi-factor authentication (MFA), and network segmentation.
OCR's enforcement approach treats risk analysis as "pre-breach accountability," examining whether organizations identified their ePHI, understood their technical environment, evaluated foreseeable vulnerabilities, and connected those findings to remediation. However, the settlements don't show that organizations with better risk analysis documentation avoided breaches. They show that OCR can more easily establish non-compliance when risk analysis is inadequate.
The proposed rule's removal of the "addressable" versus "required" distinction for implementation specifications is significant. Currently, organizations can document why an addressable specification isn't reasonable and appropriate. The proposed change makes specifications mandatory with limited exceptions, acknowledging that the flexibility in risk-based compliance hasn't led to adequate security outcomes.
What to Do Instead
Focus on implementing controls, not just documentation.
Your risk analysis should identify control gaps, but implementing those controls is what reduces your breach exposure. If your risk analysis shows that ePHI isn't encrypted at rest, the priority should be encrypting the data, not perfecting your risk management plan. If you've documented a lack of multi-factor authentication on systems containing ePHI, deploy MFA immediately.
Use the proposed Security Rule amendments as your implementation roadmap now, regardless of the May 2026 timeline. The amendments codify what OCR already expects: encryption of ePHI in transit and at rest, multi-factor authentication, network segmentation, vulnerability scanning tied to authoritative sources, penetration testing, patch management with defined timelines, and audit logging. These are the baseline requirements.
Tie your risk analysis to control implementation status, not just risk identification. Your asset inventory should feed directly into encryption deployment tracking. Your ePHI flow mapping should drive network segmentation decisions. Your vulnerability scan results should populate your patch management queue with accountable owners and remediation deadlines.
Build your corrective action plan before OCR writes it for you. The settlements show what OCR considers defensible: current asset inventories, ePHI data flows, vulnerability information, control effectiveness assessments, accountable owners, remediation timelines, and change management processes. Your risk analysis should produce these outputs and drive quarterly control reviews.
Prepare for the 240-day compliance window if the rule is finalized as proposed. Organizations that have already implemented encryption, MFA, network segmentation, and continuous monitoring will need to document and validate. Those starting from scratch face the full $9 billion implementation cost curve.
When the Conventional Wisdom Is Right
Risk analysis is valuable when it drives resource allocation toward your highest-exposure gaps. If your analysis identifies that a specific system processes ePHI without encryption, lacks MFA, and hasn't been patched in six months, that's useful. If that analysis results in budget approval, vendor selection, and implementation by a named owner with a deadline, it prevented the next breach.
Risk analysis is also your audit trail for demonstrating reasonable and appropriate security measures under the current rule. When OCR investigates, they'll review your risk analysis, risk management plan, and implementation evidence. Organizations that can show they identified vulnerabilities, prioritized remediation based on risk, and implemented controls within reasonable timeframes will fare better than those with no documentation.
The proposed amendments will make annual Security Rule compliance audits mandatory. Your risk analysis will be the foundation for that audit. If you can demonstrate that your risk analysis identified control gaps, your risk management plan addressed them, and your implementation evidence shows deployment, you've built your audit defense.
But don't confuse the audit defense with the actual defense. Your risk analysis documentation might satisfy OCR. Your implemented controls will stop the ransomware.





