Somewhere in Denton County there is a two-person dental practice, a small counseling group, or a medical billing company that has never completed a security risk assessment. Not because anyone decided to skip it. It never got assigned to a specific human being, and the calendar kept moving. The practice manager assumes the IT company handles it. The IT company assumes the practice manager handles it. When someone finally asks for the document, nobody can produce one.

Here is the encouraging part. A risk assessment is not a mysterious audit performed by strangers in expensive suits. It is a structured way of asking a few honest questions about your own business, and the federal government publishes a free tool that walks a small office through them. Before we go further, an important note: this article is general information, not legal or compliance advice. Obligations vary by organization, and a qualified attorney or compliance advisor has to confirm what actually applies to you.

What a Risk Assessment Actually Is

The U.S. Department of Health and Human Services publishes guidance on risk analysis under the HIPAA Security Rule. That guidance describes risk analysis as an assessment of “potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information.” In plain business English: figure out where the health data lives, what could go wrong with it, how likely each problem is, how bad it would be, and what you intend to do about it.

HHS breaks the work into components that read less like a technical specification and more like a checklist a careful person would build anyway.

  • Scope. HHS says the analysis covers all electronic protected health information the organization “creates, receives, maintains, or transmits,” across every kind of electronic media. Laptops, phones, cloud applications, and the flash drive in a desk drawer all count.
  • Data collection. Find where that information really sits. The guidance points to reviewing past and existing projects, performing interviews, and reviewing documentation.
  • Threats and vulnerabilities. Identify and document reasonably anticipated threats, plus the weaknesses those threats could take advantage of.
  • Current security measures. Look honestly at what you already have running and whether it is doing the job.
  • Likelihood and impact. Estimate the probability of each risk and the magnitude of the damage if it happens. HHS notes this can be done with words, with numbers, or with a mix.
  • Risk level and corrective action. Assign a level to each risk and document the corrective actions you plan to take.

Read that list again. Most of it is thinking clearly and writing it down. Offices skip it because it is unglamorous and nobody owns it.

The Free Tool Most Small Practices Have Never Opened

There is a government-published Security Risk Assessment Tool, usually called the SRA Tool. According to HealthIT.gov, it was developed by the Office of the National Coordinator for Health IT in collaboration with the HHS Office for Civil Rights to help healthcare providers conduct a security risk assessment. The same page is refreshingly blunt about fit, describing it as intended for “medium and small providers” and noting that “use of this tool may not be appropriate for larger organizations.”

It comes in two forms: a downloadable desktop application for Windows, and a spreadsheet workbook that runs on any computer capable of handling .xlsx files. Owners always ask where the answers go. HealthIT.gov states that “All information entered into the tool is stored locally on the user’s computer” and that “HHS does not collect, view, store, or transmit any information entered into the SRA Tool.” It produces reports you can save and print, and a user guide is published alongside it.

We will be honest. It is tedious. Plan on several sittings rather than one heroic afternoon. But tedious and free beats perfect and never started.

Why the Paper Trail Matters as Much as the Findings

HHS guidance says the risk analysis has to be documented, and it also says the rule “does not require a specific format.” Small offices hear the second half of that sentence and quietly conclude that a conversation counts. It does not. Nobody reviewing your business later can read a hallway discussion from two years ago. They can read a dated file.

The guidance also frames this as ongoing work rather than a one-time project, describing risk analysis as something updated as needed, with the right frequency varying from one organization to the next. It specifically raises reviewing your analysis after a security incident, after a change in ownership, and when you are planning to bring in new technology. Plenty of practices settle into a yearly rhythm because a year is easy to remember. Whether that fits you is a question for your advisor.

The Gaps We Find in Small Offices

Different practices, remarkably similar findings. These surface again and again in small offices around Denton, Lewisville, and Flower Mound.

  • Nobody knows where the data lives. Scanned intake forms in a shared folder, patient details in email attachments, a spreadsheet on the front desk computer, and a cloud portal someone signed up for years ago. That last category is shadow IT, and it is almost always bigger than owners expect.
  • Shared logins. One “frontdesk” account used by three people across two shifts. It feels efficient right up until you need to know who opened a record.
  • Personal phones with no rules. Staff checking work email on devices with no screen lock and no way to be wiped if lost.
  • Vendors nobody has inventoried. Transcription services, billing companies, answering services, cloud tools. Whether a written agreement is required with any given vendor is a legal question, but you cannot ask it until the list exists.
  • Backups nobody has tested. A backup that has never been restored is a theory, not a safeguard.
  • Former staff who still have access. The offboarding checklist covered the building key and forgot the software.

Turning Findings Into a Dated Action List

The most common failure is not a bad assessment. It is a finished assessment that goes into a drawer. Findings without follow-through are just a well-organized list of things you already knew were wrong.

  1. Give every finding a name. A person, not a department. “IT” does not fix anything. Sarah does.
  2. Give every finding a month. Not “soon.” A month on a calendar you actually look at.
  3. Rank by damage, not by ease. It is tempting to knock out the simple items first. Do the one that would hurt most instead.
  4. Write down what you decided not to do. Accepting a risk on purpose, with a reason recorded, is a defensible business decision. Accepting it by accident is not.
  5. Schedule the next review before you close the file. The highest-value minute in the entire exercise.

The Bottom Line

The assessment is not the hard part. Deciding that it belongs to a specific person, in a specific month, is. A practice that works through the free federal tool, documents the results, and builds a dated action list is in far better shape than one waiting for the perfect consultant engagement that never gets scheduled. Security work compounds, and so does the case for treating it as a normal business function instead of an emergency.

One more time, because it matters: everything above is general information, not legal or compliance advice. A qualified attorney or compliance professional must confirm what applies to your organization, how often you need to revisit it, and what your documentation needs to contain.

If you are a small practice or a business associate in Denton County and want help finding where your data actually lives, closing the gaps a self-assessment turns up, or building the action list that follows, we are glad to help. We work with small teams that need practical answers, not a lecture. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).