Skip to main content
What Actually Goes Wrong in a HIPAA Risk Analysis?Incident & Breach Response
5 min readFor GRC Leaders

What Actually Goes Wrong in a HIPAA Risk Analysis?

These questions arise from discussions with compliance teams after OCR settlements make headlines. When Ambry Genetics paid $700,000 to settle HIPAA violations following a phishing attack that exposed 225,370 individuals' ePHI, the technical details were clear: compromised email account, three-day window of unauthorized access, and a class action lawsuit costing $12.25 million. What compliance teams really want to know is what OCR found when they audited the risk analysis program, and how to avoid similar findings in their own environments.

What Does OCR Mean by "Accurate and Thorough" Risk Analysis?

OCR doesn't accept checkbox exercises. An accurate risk analysis under the HIPAA Security Rule (§164.308(a)(1)(ii)(A)) requires identifying where ePHI is stored, flows, and is processed across your organization, then documenting specific threats and vulnerabilities for each location and system.

The "thorough" part often trips up teams. You can't limit your analysis to obvious systems like EHRs or billing platforms. Email systems, backup repositories, employee devices, vendor connections, physical storage, and decommissioned hardware all need evaluation. When OCR investigated Ambry Genetics, they found the risk analysis hadn't adequately addressed email security controls despite email being a known attack vector.

Your risk analysis must produce a documented inventory of:

  • All systems and locations containing ePHI
  • Specific threats to confidentiality, integrity, and availability for each
  • Current safeguards protecting against those threats
  • Residual risk after safeguards are applied
  • Decisions about whether residual risks are acceptable or require additional controls

If you can't trace a specific control back to a documented risk, or if a breach reveals a vulnerability your analysis didn't identify, OCR considers the analysis incomplete.

Is a Risk Analysis from Two Years Ago Still Valid?

No. The HIPAA Security Rule requires ongoing risk management (§164.308(a)(1)(ii)(B)), meaning your risk analysis can't be a one-time project. OCR expects updates when:

  • New systems or technologies are deployed
  • ePHI flows change within your organization
  • New threat intelligence emerges
  • A security incident reveals a gap
  • Vendor relationships change

Most organizations treat this as an annual cycle, but you need a documented process for triggering interim updates. If you experience a phishing attack and don't immediately reassess your email security controls and workforce training, you're demonstrating the same pattern OCR found at Ambry Genetics.

The corrective action plan OCR imposed requires not just a comprehensive risk analysis, but also a risk management program to continuously reduce and mitigate identified risks. Static assessments don't satisfy the rule.

Why Are Shared Usernames a Problem?

The HIPAA Security Rule requires unique user identification (§164.312(a)(2)(i)) to track who accessed what ePHI and when. Shared credentials make accountability impossible.

When OCR investigates a breach, one of their first questions is: "Can you tell us exactly which employee's account was compromised and what ePHI that specific account could access?" If you're using shared logins for systems containing ePHI, you can't answer that question. You can't determine breach scope, notify the right patients, or demonstrate you've implemented required access controls.

This isn't about sophisticated identity governance platforms. It's about basic account hygiene: every person who touches ePHI gets their own username, and you log their activity. Service accounts and system-to-system connections need separate controls, but any human access requires individual identification.

How Do You Prevent Phishing Attacks from Becoming HIPAA Violations?

You can't prevent all phishing attempts from reaching your workforce. What you can prevent is successful phishing from turning into a breach of 225,370 records.

OCR's enforcement pattern shows they expect layered controls:

  • Technical safeguards: Multi-factor authentication on all systems containing ePHI, especially email. Email filtering and anti-phishing tools that block known malicious content.
  • Access controls: Principle of Least Privilege applied to ePHI access. If a phishing attack compromises one account, that account shouldn't have access to your entire patient database.
  • Monitoring: Automated alerts for suspicious login patterns, unusual data access, or geographic anomalies. Ambry Genetics detected suspicious activity on January 22, but the unauthorized access had already begun.
  • Workforce training: The HIPAA Security Rule requires security awareness training (§164.308(a)(5)(i)). OCR's corrective action plans consistently mandate phishing simulation programs and documented training on recognizing social engineering.

The gap at Ambry Genetics wasn't that phishing exists. It's that their risk analysis apparently didn't identify email as a high-risk attack vector requiring compensating controls beyond basic training.

What Happens to Access When Someone Leaves or Changes Roles?

OCR found that Ambry Genetics failed to implement procedures for terminating access when workforce members left or no longer needed ePHI access. This is a §164.308(a)(3)(ii)(C) violation and it's shockingly common.

Your access termination process needs to cover:

  • Immediate revocation of all system access on termination date
  • Review and removal of access rights when roles change
  • Regular access reviews to catch orphaned accounts
  • Documented procedures your IT and HR teams actually follow

The "otherwise no longer required" language matters. If someone moves from clinical operations to marketing, their ePHI access should end even though they're still employed. Most organizations discover during breach investigations that terminated employees still had active credentials months after departure.

Is $700,000 the Going Rate for Risk Analysis Failures?

OCR has imposed 10 financial penalties this year, collecting $3,030,250 in fines. Nine of those 10 penalties involved risk analysis failures. The amounts vary based on breach size, organizational revenue, and violation severity, but the pattern is clear: if OCR investigates your breach and finds you didn't conduct a compliant risk analysis, you're facing both a financial penalty and a multi-year corrective action plan.

The bigger cost for Ambry Genetics was the $12.25 million class action settlement. HIPAA penalties are just the regulatory floor. Add litigation costs, breach notification and credit monitoring expenses, incident response, and reputational damage, and a single phishing email can easily cost your organization eight figures.

Where to Go from Here

Start with your current risk analysis documentation. If you can't produce a document showing how you identified email security as a risk, what threats you evaluated, what controls you implemented, and how you're monitoring effectiveness, you have the same gap OCR found at Ambry Genetics.

The HIPAA Security Rule text (45 CFR Part 164, Subpart C) provides the baseline requirements. HHS also publishes guidance on conducting risk assessments at HealthIT.gov. If your last risk analysis predates your current email security architecture, cloud migrations, or remote work policies, it's not accurate or thorough under OCR's standard.

Your risk management program should produce updated documentation at least annually and after any significant change. If you can't show OCR how your controls trace back to documented risks, you're building technical debt that comes due when the next phishing email succeeds.

You Might Also Like