Healthcare2 min read

A Risk Analysis You Do Once Is Not a Risk Analysis

Most practices have a security risk analysis in a folder. Very few have one that reflects the environment today, and that difference is what an auditor is actually looking for.

Somewhere in your compliance folder there is a document titled something like "Security Risk Analysis," dated two or three years ago, produced by a consultant, containing a table of findings.

Ask three questions about it. Which findings were remediated? Who owned each one? When was it last revisited?

If the answers are uncertain, you do not have a risk analysis. You have a snapshot of an environment that no longer exists.

Why the one-off version fails on its own terms

The security rule expects the analysis to be accurate and thorough with respect to your current environment, and to be updated as circumstances change. A practice that has since added two locations, changed EHR modules, adopted a telehealth platform and hired forty people has changed its circumstances substantially.

Beyond the regulatory position, there is a practical one. A document nobody revisits cannot influence decisions. Its findings do not appear in budget conversations, do not shape procurement, and do not get remediated, because remediation requires somebody to own an item and be asked about it.

What a live register looks like

The change is smaller than people expect. The content is largely the same. What differs is the structure.

Every risk has a named owner. A person, not a department. Departments do not attend meetings.

Every risk has a review date. When it comes due, it surfaces, and somebody either updates it or explains why it has not moved.

Accepted risks expire. This is the one that matters most and is most often missing. A risk accepted by leadership two years ago, on the basis of the environment at the time, should come back for re-acceptance rather than remaining accepted for ever. Circumstances change; so should the decision.

Treatment is recorded, not just intent. What was done, when, and what the residual position is afterwards.

Changes to the environment trigger review. A new system, a new location, a new vendor with access. Each is a reason to revisit rather than a thing to remember at annual review.

Where practices most often find gaps

When we run this properly, the findings cluster in the same places.

Vendor access, granted at installation and never reviewed, frequently outliving the relationship. Departing staff whose access persisted across the systems that were not part of the offboarding checklist. Backups nobody has tested restoring, particularly for the systems outside the EHR. Devices holding records that were never inventoried. And business associate agreements that exist but were never checked against what the vendor actually does now.

None of these are exotic. All of them are the kind of thing a one-off analysis records once and never revisits.

The audit position, plainly

If a regulator or a payer asks, the difference between a folder and a register is the difference between "we performed an analysis" and "here is our current risk position, here is who owns each item, here is what has been remediated in the last year, and here is the evidence."

The second is a substantially better conversation, and the work to get there is mostly organisational rather than technical.