How to Conduct a HIPAA Risk Analysis After Opening a Second Practice Location
Opening a second site changes how Protected Health Information (PHI) moves, where it resides, and who can access it. A focused HIPAA risk analysis for the new location helps you find gaps early, prioritize fixes, and prove due diligence through solid Compliance Documentation. This guide shows you exactly what to evaluate and how to act.
HIPAA Risk Analysis Purpose
The purpose of a HIPAA risk analysis is to identify reasonably anticipated threats to PHI, evaluate their likelihood and impact, and select Risk Mitigation Strategies to reduce them to an acceptable level. A second location introduces new people, processes, vendors, and technologies that must be assessed on their own merits.
Your analysis should produce a defensible record of what PHI you handle, where it flows, the controls in place, and the residual risk that remains. It also ensures alignment between clinical operations and security so that safeguards protect care delivery rather than slow it down.
Scope and outcomes
- Scope: facilities, devices, networks, apps, cloud services, and vendors that create, receive, maintain, or transmit PHI at the new site.
- Outcomes: a prioritized risk register, selected controls, an implementation plan with owners and dates, and auditable Compliance Documentation.
Steps for Second Location Risk Analysis
- Define assets and data flows: Inventory workstations, mobile devices, scanners, imaging systems, EHR modules, and paper records. Map PHI from intake to billing, storage, and disposal.
- Profile the environment: Note building layout, neighboring tenants, local crime/weather patterns, utilities, and vendor access that can influence exposure.
- Identify threats and vulnerabilities: Consider theft, tailgating, misdelivery of records, misconfigurations, lost devices, phishing, misrouted faxes, and third-party failures.
- Analyze risk: Rate likelihood and impact (low/medium/high). Capture assumptions and evidence so ratings are reproducible.
- Assess existing controls: Review Physical Access Controls, authentication, Encryption Standards, logging, backups, training, and contracts for coverage and effectiveness.
- Select Risk Mitigation Strategies: Avoid, reduce, transfer (e.g., cyber insurance), or accept risk with rationale and approvals.
- Plan and resource fixes: Assign owners, timelines, budgets, and success metrics. Sequence quick wins before longer infrastructure changes.
- Test and validate: Run walk-throughs and tabletop exercises for Incident Response Procedures, access provisioning, and downtime workflows.
- Approve and communicate: Obtain leadership sign-off, brief the workforce, and integrate actions into daily operations and change management.
- Monitor and revisit: Track progress at 30/60/90 days; re-score risks after major changes or new findings.
Physical Security Assessment
Physical controls are your first barrier to PHI exposure. Evaluate how patients, visitors, vendors, and staff move through space and how devices and records are secured when unattended.
Facility controls and access
- Physical Access Controls: badge systems, unique IDs, door alarms, visitor logs, and escort policies for non-staff.
- Reception privacy: screen and speech privacy at check-in; queue design to prevent overhearing PHI.
- Server/network closets: locked, access-logged, with limited keys and periodic audit of permissions.
Workstations and devices
- Screen positioning, automatic timeouts, privacy filters, and secure docking for laptops and tablets.
- Asset tagging and inventories; locked storage for loaner or shared devices.
Media handling and disposal
- Secure bins for paper; policies for label printers, receipts, and misprints.
- Sanitized device returns and certified destruction for drives and copiers.
Environmental and emergency safeguards
- Fire suppression, water leak detection, and climate control for equipment rooms.
- Power redundancy or UPS for critical systems and documented evacuation/continuity routes.
Technical Safeguards Evaluation
Technical safeguards protect PHI in systems and networks. Validate that configurations match your standards and are consistent with the first location without copying mistakes.
Ready to assess your HIPAA security risks?
Join thousands of organizations that use Accountable to identify and fix their security gaps.
Take the Free Risk AssessmentAccess control and authentication
- Unique user IDs, least-privilege roles, and multi-factor authentication for EHR, VPN, email, and admin consoles.
- Automated provisioning/deprovisioning tied to HR events; emergency access break-glass with audit.
Encryption standards and key management
- Encryption Standards for data in transit (TLS 1.2+), at rest on endpoints and servers, and for mobile/portable media.
- Documented key rotation, escrow, and recovery procedures.
Network and application security
- Segmentation that isolates clinical devices; zero-trust or least-privilege network policies.
- Endpoint protection, mobile device management, patching SLAs, and secure configuration baselines.
- Email and messaging controls: phishing defenses, DMARC alignment, and secure messaging for PHI.
Monitoring, auditing, and alerts
- Centralized audit logs for EHR access, admin changes, and authentication events with alerting on anomalies.
- Periodic access reviews and reconciliation against role expectations.
Backup, recovery, and resilience
- Encrypted, tested backups; recovery time and point objectives aligned to clinical needs.
- Downtime procedures with printed forms and clear re-entry steps post-restoration.
Administrative Safeguards Review
Administrative controls steer how people handle PHI. Ensure policies, Workforce Training Requirements, and vendor oversight are complete and applied at the second site.
Governance and accountability
- Designate a security official for the site; maintain a risk register and meeting cadence for status tracking.
- Policy coverage for acceptable use, minimum necessary, sanctions, and change management.
Workforce training requirements
- Role-based onboarding before system access; annual refreshers with phishing simulations and privacy scenarios.
- Documented comprehension (attestations, quizzes) and a clear sanction process.
Vendor and BAA management
- Business Associate Agreements reflecting services at the new location; security reviews for new or changed vendors.
- Evidence of safeguards for couriers, cleaning services, and equipment maintenance providers.
Incident response procedures and contingency planning
- Incident Response Procedures with triage steps, breach assessment, notification triggers, and communication templates.
- Contingency plans for system outages, staff shortages, and disasters; conduct tabletop exercises at the new site.
Documentation and Reporting
Complete, organized records prove you performed due diligence and guide audits and improvement. Build a single source of truth for Compliance Documentation covering the new site.
- Risk analysis report: scope, asset inventory, data flows, methodologies, findings, ratings, and selected mitigations.
- Implementation plan: owners, timelines, budgets, and acceptance criteria.
- Evidence repository: screenshots, logs, training rosters, contracts/BAAs, and test results.
- Approvals and exceptions: leadership sign-offs and documented risk acceptance with expiration dates.
- Dashboards: status of actions, open risks, and KPIs (training completion, patch SLAs, audit review cadence).
Periodic Risk Analysis
A second location is not “set and forget.” Reassess at least annually and whenever significant changes occur—new software, renovated space, device refreshes, leadership changes, or incidents. Use metrics to trigger reviews, such as spikes in access alerts or vendor changes.
Unify both locations under one risk management program while preserving site-specific nuances. Share lessons learned, standardize baselines, and track remediation centrally to keep effort efficient and consistent.
Conclusion
By scoping assets and data flows, testing safeguards, strengthening training and vendor oversight, and maintaining rigorous documentation, you can conduct a HIPAA risk analysis that scales to your second practice location. Prioritize quick wins, schedule deeper fixes, and revisit risks as operations evolve.
FAQs.
What are the key risks to PHI in a new practice location?
Common risks include tailgating and weak Physical Access Controls, misconfigured EHR or Wi‑Fi, unencrypted laptops or portable media, improper paper handling, phishing against new staff, and third-party gaps (e.g., cleaning crews or service vendors) that touch PHI.
How often should HIPAA risk analyses be updated?
Update at least annually and whenever material changes occur—adding services, switching vendors, deploying new technology, remodeling space, or after an incident. Perform targeted reviews at 30/60/90 days post‑opening to validate assumptions.
What documentation is required after completing a risk analysis?
Maintain the written risk analysis, risk register, selected Risk Mitigation Strategies, implementation plan with owners and dates, testing results, Workforce Training Requirements records, BAAs, and leadership approvals—collectively your Compliance Documentation.
How do technical safeguards differ from administrative safeguards?
Technical safeguards are system-based controls—access management, Encryption Standards, logging, and network security. Administrative safeguards are people and process controls—policies, training, vendor oversight, sanctions, and Incident Response Procedures that govern how technology is used.
Ready to assess your HIPAA security risks?
Join thousands of organizations that use Accountable to identify and fix their security gaps.
Take the Free Risk Assessment