HIPAA Risk Analysis Checklist to Complete Before Opening a New Satellite Urgent Care
Opening a new satellite urgent care expands access to care and your regulatory footprint. Before go-live, you must complete a thorough HIPAA risk analysis so electronic protected health information (ePHI) remains confidential, accurate, and available. Use this practical checklist to scope, analyze, document, and remediate risk with confidence.
HIPAA Risk Analysis Requirement
The HIPAA Security Rule requires an “accurate and thorough” assessment of potential risks and vulnerabilities to ePHI. This risk analysis is foundational to risk management and must be completed and documented before the new site begins handling patient data.
As a covered entity or business associate, you are accountable for selecting safeguards proportionate to your risks and for demonstrating due diligence during HIPAA compliance enforcement. Treat risk analysis as a decision-quality study that informs budget, timelines, and the order in which you deploy controls.
- Designate a security official and define governance for the satellite site.
- Set a pre–go-live deadline for completing analysis and initial remediation.
- Plan for ongoing risk management, not a one-time exercise.
Scope of Risk Analysis
Your scope must cover every place ePHI is created, received, maintained, or transmitted across the new site and its dependencies. Include people, processes, technology, and third parties tied to operations.
- Systems: EHR, PACS/imaging, lab devices, e-prescribing, billing, secure messaging, telehealth, VoIP, printers/scanners, and kiosks.
- Infrastructure: Workstations, tablets, mobile phones (BYOD/COPE), servers, medical IoT, network closets, switches, wireless APs, firewalls, and VPNs.
- Data flows: Interfaces (HL7/FHIR), APIs, SFTP, email, fax services, cloud storage, backups, and remote access.
- Facilities: Waiting areas, triage rooms, procedure rooms, radiology, break rooms, and shared building spaces that affect physical security.
- Vendors: Cloud EHR, RCM, billing, transcription, telehealth platforms, imaging service providers—ensure BAAs and security due diligence.
- People and process: Scheduling, intake, clinical documentation, discharge, referrals, and after-hours on-call workflows.
Explicitly define the boundary with headquarters IT and any managed service providers. Inventory all assets and map where ePHI resides and travels to avoid blind spots.
Components of Risk Analysis
1) Establish method and scope
- Select a consistent methodology for likelihood/impact scoring and define risk acceptance criteria.
- Confirm the satellite site’s dependencies, assumptions, and constraints.
2) Inventory assets and ePHI locations
- Create an asset register (hardware, software, data stores, interfaces) and owners.
- Identify all repositories of electronic protected health information, including temporary files and logs.
3) Map data flows
- Diagram intake-to-discharge data movement, including cloud services and third parties.
- Flag points where ePHI leaves the site or crosses security zones.
4) Threat and vulnerability identification
- Examine credible threats (malware, phishing, insider error, theft, outage, disasters) and vulnerabilities (unpatched systems, weak access controls, misconfigurations, process gaps).
- Include clinical workflows that bypass policy under time pressure.
5) Likelihood, impact, and risk scoring
- Rate each risk scenario for likelihood and business/clinical impact (care disruption, data loss, regulatory exposure, reputational harm).
- Prioritize a top-tier list for immediate action before opening day.
6) Control review across security safeguard categories
- Administrative: policies, training, sanctions, vendor oversight, contingency planning, and incident response.
- Physical: facility access, device placement, cable locks, secure disposal, and environmental controls.
- Technical: authentication (MFA), encryption, access control, logging/monitoring, network segmentation, backups, and anti-malware.
7) Define risk mitigation strategies
- Select controls to reduce likelihood and/or impact (e.g., MFA for remote access, encrypt mobile endpoints, segment imaging networks).
- Balance speed, cost, and clinical usability to avoid workarounds.
8) Remediation management
- Create a time-bound plan with owners, milestones, and success criteria.
- Track status in a risk register and escalate barriers to leadership.
9) Risk assessment documentation
- Compile your methodology, scope, asset inventory, data flows, findings, and decisions.
- Record residual risks accepted by leadership and planned review dates.
10) Validation and readiness check
- Test controls (restore a backup, run a phishing simulation, walk the facility for physical gaps).
- Confirm go-live criteria are met and document evidence.
Documentation Requirement
Maintain written risk assessment documentation sufficient to show how you identified, evaluated, and addressed risk. Auditable records protect your organization during HIPAA compliance enforcement and guide continuous improvement.
- Methodology and scope statement, roles, and dates of analysis.
- Asset inventory and ePHI data-flow diagrams.
- Threat/vulnerability analysis, scoring model, and risk register.
- Selected risk mitigation strategies, rationale, and expected risk reduction.
- Remediation management plan with owners, timelines, and evidence of completion.
- Testing results (e.g., restore tests, access recertifications) and incident lessons learned.
- Leadership approvals, residual risk acceptances, and next review date.
Retain required documentation for at least six years from creation or last effective date, and keep versions to demonstrate how decisions evolved.
Ready to assess your HIPAA security risks?
Join thousands of organizations that use Accountable to identify and fix their security gaps.
Take the Free Risk AssessmentPeriodic Review and Updates
Risk analysis is not a one-time task. Reassess risks on a defined cadence and whenever material change occurs so controls keep pace with your operations.
- Time-based: perform at least annually with a midyear mini-review.
- Event-based: new systems or vendors, EHR upgrades, site expansions, process changes, or after security incidents.
- Threat-based: emerging vulnerabilities, regulatory changes, or shifts in attacker tactics.
Update your risk register, remediation plan, and training to reflect new realities, and verify that controls remain effective.
Common Pitfalls
- Scoping only IT assets and ignoring clinical workflows and human factors.
- Failing to inventory devices, interfaces, and shadow IT where ePHI actually lives.
- Relying on generic templates that don’t reflect the satellite urgent care environment.
- Underestimating physical risks in shared buildings and publicly accessible areas.
- Skipping vendor due diligence and BAAs, especially for cloud and imaging services.
- Weak access control (no MFA), flat networks, and unencrypted mobile devices.
- Poor remediation management—no owners, deadlines, or evidence of completion.
- Inadequate logging and monitoring, leaving incidents undetected.
Tailoring to Practice Needs
Urgent care is fast-paced, high-volume, and shift-driven. Tailor your analysis and controls to real workflows so security supports care rather than slowing it down.
Go-live essentials for a satellite urgent care
- Role-based access in the EHR with MFA for remote access and admin actions.
- Encrypted Wi‑Fi with separate guest network; network segmentation for imaging/IoT.
- Hardened endpoints: disk encryption, auto-lock, patching, and anti-malware.
- Secure messaging for clinical coordination; disable SMS for ePHI.
- Vendor readiness: BAAs executed, SOC/third-party reports reviewed, minimum-security baselines verified.
- Backups tested for restore; downtime procedures printed and accessible.
- Facility safeguards: screen privacy, device placement, secure cabling, and locked network closets.
- Intake and discharge workflows validated to prevent data exposure at kiosks and printers.
- Training completed for staff and providers, including phishing and device handling.
- Incident response runbook with on-call escalation and breach assessment steps.
- Media sanitization and disposal process for paper, drives, and devices.
- Continuous logging and alerting for authentication, privileged changes, and ePHI access anomalies.
Right-sizing security around your actual risks—using concrete risk mitigation strategies and disciplined remediation management—positions your new satellite urgent care to open on time, safeguard patients, and sustain compliance.
FAQs.
What are the key steps in performing a HIPAA risk analysis?
Define scope and method, inventory assets and ePHI locations, map data flows, conduct threat and vulnerability identification, score risks by likelihood and impact, review controls across security safeguard categories, choose risk mitigation strategies, build and execute a remediation plan, document everything, and validate readiness before go-live.
How often should the HIPAA risk analysis be updated?
Update at least annually and whenever material changes occur—new systems or vendors, major upgrades, workflow changes, incidents, or emerging threats. Keep your risk register and risk assessment documentation synchronized with these updates.
What common pitfalls should be avoided during HIPAA risk analysis?
Avoid narrow IT-only scoping, poor asset and data-flow visibility, generic templates, weak vendor oversight, insufficient physical controls, lack of MFA and segmentation, inadequate logging, and weak remediation management that leaves high risks unresolved.
Table of Contents
- HIPAA Risk Analysis Requirement
- Scope of Risk Analysis
-
Components of Risk Analysis
- 1) Establish method and scope
- 2) Inventory assets and ePHI locations
- 3) Map data flows
- 4) Threat and vulnerability identification
- 5) Likelihood, impact, and risk scoring
- 6) Control review across security safeguard categories
- 7) Define risk mitigation strategies
- 8) Remediation management
- 9) Risk assessment documentation
- 10) Validation and readiness check
- Documentation Requirement
- Periodic Review and Updates
- Common Pitfalls
- Tailoring to Practice Needs
- FAQs.
Ready to assess your HIPAA security risks?
Join thousands of organizations that use Accountable to identify and fix their security gaps.
Take the Free Risk Assessment