1. Discover
Map ePHI, systems, people, locations, vendors, threats, vulnerabilities, and existing safeguards so the practice understands the environment being evaluated.
Healthcare Security & HIPAA
HIPAA risk analysis and risk management are connected stages of the same security-management process. Risk analysis identifies and evaluates risks to electronic protected health information; risk management turns those findings into prioritized safeguards, assigned actions, verified remediation, and documented decisions.
Risk analysis is the process of identifying and evaluating risks and vulnerabilities affecting ePHI. Risk management uses those findings to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. Analysis tells the practice what the risks are; management determines what the practice will do about them and verifies that action occurred.
Map ePHI, systems, people, locations, vendors, threats, vulnerabilities, and existing safeguards so the practice understands the environment being evaluated.
Evaluate likelihood and impact consistently, document current safeguards and material gaps, and prioritize the risks that require management attention.
Select appropriate safeguards, assign accountable owners, create remediation tasks, set target dates, address dependencies, and document decisions that require leadership input.
Confirm safeguards were implemented, retain evidence, reassess residual risk, review overdue actions, and repeat the process when the environment or risk landscape changes.
A documented scope, threat and vulnerability assessment, safeguard review, likelihood and impact methodology, risk ratings, findings, and enough context for management to understand each material risk.
A prioritized treatment plan with owners, safeguards, target dates, status, evidence, escalation paths, and documented decisions about residual risk and deferred work.
Configuration records, access reviews, training records, backup tests, incident exercises, vendor reviews, remediation tickets, policies, approvals, and other artifacts should support the status claimed for each control.
Leadership should know which material risks remain open, who owns them, what is overdue, what changed, and whether implemented safeguards continue to operate as expected.
Stopping after the assessment leaves the practice with findings but no operating response. A useful security program connects every significant finding to an owner, decision, safeguard, target date, evidence requirement, and recurring review.
Last reviewed August 10, 2026. This comparison reflects current HHS guidance on risk analysis and the Security Management Process under the HIPAA Security Rule.
Use these resources to connect risk-analysis findings to practical remediation, operating safeguards, and an objective view of your current readiness.
Start with the HIPAA Security Readiness Assessment if you need a structured view of reported gaps. If you already know what needs attention and require implementation support, review HIPAA Security Operations.