How to Perform a HIPAA Risk Assessment for a Cardiology Practice Emailing Holter Strips to Referring Offices

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

How to Perform a HIPAA Risk Assessment for a Cardiology Practice Emailing Holter Strips to Referring Offices

Kevin Henry

Risk Management

July 11, 2026

8 minutes read
Share this article
How to Perform a HIPAA Risk Assessment for a Cardiology Practice Emailing Holter Strips to Referring Offices

HIPAA Risk Assessment Requirements

Scope and objectives

Your assessment must cover how Holter strips are captured, labeled, stored, and transmitted to referring offices. Define scope across people, processes, and technology, with the goal of achieving HIPAA Security Rule compliance while enabling timely care coordination.

Core steps

  • Define the use case: emailing Holter strips and related ePHI to external providers.
  • Map data flows end to end, including creation, processing, transmission, receipt, storage, and disposal.
  • Identify threats and weaknesses through a structured vulnerability assessment.
  • Evaluate risk using clear risk rating methodologies (likelihood × impact).
  • Select and implement safeguards; document residual risk and acceptance where appropriate.
  • Monitor controls, retrain staff, and update the assessment when anything material changes.

Roles and responsibilities

Assign an executive sponsor, a security/privacy lead, and system owners for email, EHR, and Holter analysis tools. Make staff accountable for address verification, attachment handling, and incident reporting.

Holter-specific data considerations

Holter strips often contain names, dates of birth, medical record numbers, and timestamps. Limit datasets to the minimum necessary, redact extraneous pages, and verify that exported PDFs or images don’t embed hidden metadata that exposes additional ePHI.

Outcome

The deliverable is a documented risk analysis tailored to emailing Holter strips, plus an action plan that demonstrates ongoing HIPAA Security Rule compliance. In practice, you are learning how to perform a HIPAA risk assessment for a cardiology practice emailing Holter strips to referring offices and turning it into repeatable operations.

Inventory of ePHI Systems and Devices

Build a complete asset inventory

List every system that creates, receives, maintains, or transmits Holter-related ePHI. Capture owner, location, data type, retention, backup, access model, and whether controls meet ePHI encryption standards at rest and in transit.

Typical assets in scope

  • Holter monitors and docking stations used to import recordings.
  • Analysis software and workstations that generate strips and reports.
  • EHR or cardiology PACS modules storing interpretations and PDFs.
  • Email platforms (e.g., Microsoft 365, Google Workspace) and any secure portal.
  • Mobile devices used for email; MDM-enrolled phones and tablets.
  • File servers, scan-to-email copiers, cloud storage, and backups.
  • Security tools: identity provider, MFA, antimalware, and DLP.

Data flow and handoffs

For each asset, record inbound/outbound connections, automated rules (e.g., auto-forwarding), and handoffs to vendors. Note where temporary copies may persist—print spoolers, downloads folders, and scan caches are common blind spots.

Email Transmission Security Measures

Secure email protocols and configuration

Enforce secure email protocols end to end. Require TLS for all external delivery and block downgrade to plaintext; publish sender authentication (SPF, DKIM, DMARC) to reduce spoofing risk. Log message trace events to prove encrypted transit when emailing referring offices.

Message content protection

  • Default to automatic encryption based on rules that detect ePHI terms (patient name patterns, MRNs, report headers).
  • Use S/MIME or a secure portal for end-to-end protection when the recipient’s domain cannot guarantee TLS.
  • Encrypt attachments at the file level (e.g., password-protected PDF/ZIP using strong algorithms) and share passwords via a separate channel.

Identity and address verification

Implement approved-domain allowlists for referring offices, type-ahead address suppression, and “send delay” to catch misaddressed messages. Require a second reviewer when sending to a new recipient domain or when messages exceed a sensitivity threshold.

Endpoint and application safeguards

  • Enable MFA for all email access and block legacy protocols that bypass modern auth.
  • Use MDM to enforce device encryption, screen lock, remote wipe, and copy/paste restrictions for mobile mail apps.
  • Disable downloading of ePHI to unmanaged devices; prefer web-only viewing or portal access.

Operational practices

Standardize file naming (no full names in filenames), include patient identifiers only inside encrypted content, and confirm recipient identity by callback for new or high-risk referrals. Retain delivery receipts and encryption status as part of audit and remediation documentation.

Business Associate Agreement Management

Identify Business Associates

List any third party that creates, receives, maintains, or transmits ePHI for you: email and archive providers, secure messaging/portal vendors, cloud storage, scan-to-email service providers, and Holter analysis vendors operating offsite.

Business Associate Agreements: essentials

  • Define permitted uses/disclosures, required safeguards, breach reporting timelines, and subcontractor flow-down obligations.
  • Specify encryption expectations, logging, retention, return/destruction of ePHI, and right to audit or receive security attestations.
  • Ensure coverage for backup systems and archives that store emailed Holter strips.

Referring offices

You generally do not need Business Associate Agreements with other covered entities when sharing ePHI for treatment. Still, verify the recipient’s capability to receive securely and document the rationale for the chosen transmission method.

Lifecycle management

Maintain a central BAA repository with status, owner, renewal dates, contacts, and scope. Tie BAA reviews to vendor risk assessments and update them whenever services or data flows change.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Risk Identification and Evaluation

Vulnerability assessment approach

Identify technical, administrative, and physical weaknesses across the workflow. Review configs, conduct email encryption tests, inspect DLP rules, and interview staff about real-world exceptions (urgent referrals, after-hours sends, or home devices).

Risk rating methodologies

Use a simple, consistent scale for likelihood and impact (e.g., 1–5). Multiply or map to a matrix to produce risk ratings (Low/Moderate/High/Critical). Document assumptions, existing controls, and the residual risk after proposed mitigations.

Common risk scenarios for Holter emails

  • Misaddressed recipient exposes a named patient’s Holter strip (High impact; mitigate with allowlists, send delay, and dual review).
  • External domain lacks enforced TLS (Variable likelihood; mitigate with portal or S/MIME and automated routing rules).
  • Auto-forwarding to personal mailboxes (High impact; block forwarding and alert on violations).
  • Unmanaged mobile device syncs ePHI (High impact; require MDM and conditional access).
  • Local scan station retains unencrypted copies (Moderate impact; purge caches, encrypt disks, and log deletions).
  • Phishing leads to mailbox takeover (High impact; MFA, phishing-resistant authentication, and anomaly detection).

Validation and testing

Run test messages to key referring domains to confirm negotiated TLS and receipt workflows. Simulate misaddressing events, measure DLP trigger accuracy, and verify that revocation/wipe works on a lost device.

Documentation and Remediation Procedures

What to document

  • Risk analysis report with scope, data flows, assets, threats, vulnerabilities, and risk ratings.
  • Control catalog mapping safeguards to each risk and system.
  • Risk register tracking decisions, owners, milestones, and due dates.
  • Audit and remediation documentation: policies, training logs, test results, screenshots, and change records.

Prioritization and tracking

Address high-impact, easy-to-fix items first (e.g., disable auto-forwarding, enforce TLS, enable MFA). For complex fixes, define interim compensating controls and deadlines. Review progress in standing security meetings.

Policy, training, and awareness

Update policies for email use, device handling, data minimization, and incident reporting. Train staff on secure workflows for Holter strips, including address verification and when to escalate to a secure portal.

Incident response

Create a playbook for misdirected messages or compromised mailboxes: contain, assess risk, decide on breach notification, and implement corrective actions. Preserve logs and artifacts to support post-incident analysis.

Frequency and Compliance Monitoring

Assessment cadence

Perform a baseline assessment, refresh it at least annually, and reassess whenever you introduce new vendors, change email platforms, add domains, or alter Holter workflows. Document each trigger and update.

Ongoing monitoring and metrics

  • Monthly: test enforced TLS to top referring domains and review DLP events.
  • Quarterly: sample sent messages for address accuracy and encryption status; verify MDM compliance.
  • Semiannually: review BAAs and vendor security attestations; retest incident response with tabletop exercises.
  • Annually: full risk analysis update and control effectiveness review.

Internal audits and reporting

Maintain dashboards for encryption coverage, DLP false positives/negatives, training completion, and open remediation items. Report trends to leadership and document decisions to accept, reduce, or transfer residual risk.

Conclusion

By inventorying systems, enforcing secure email protocols, managing Business Associate Agreements, and applying structured risk rating methodologies, you create a defensible, repeatable program. Keep documentation current, monitor controls continuously, and refine safeguards as your cardiology practice and referral network evolve.

FAQs

What steps are involved in a HIPAA risk assessment for emailing Holter strips?

Define scope, map data flows, inventory assets, and conduct a vulnerability assessment focused on email. Rate risks using a clear methodology, select controls (encryption, MFA, DLP, MDM), document residual risk, implement remediation actions, and establish continuous monitoring and periodic reassessment.

How do you secure email transmission of ePHI in cardiology?

Enforce TLS for all outbound mail, require MFA for access, and use DLP to auto-encrypt messages containing ePHI. When a recipient’s domain cannot assure secure transit, switch to S/MIME or a secure portal. Encrypt attachments at the file level, verify addresses with allowlists and send delays, and log delivery and encryption status for audits.

What are the requirements for Business Associate Agreements in this context?

You need Business Associate Agreements with vendors that create, receive, maintain, or transmit Holter-related ePHI on your behalf—email and archive providers, secure messaging portals, cloud storage, scan-to-email services, and any offsite analysis firms. BAAs should address safeguards, breach reporting, subcontractors, encryption, retention, and data return or destruction. Referring offices that are covered entities typically do not require BAAs for treatment-related exchanges.

How often should a cardiology practice perform a risk assessment?

Complete a baseline assessment and update it at least annually or whenever material changes occur—such as onboarding a new email provider, adding a referral portal, changing domains, or modifying Holter workflows. Complement the annual review with monthly and quarterly control monitoring to keep risk within tolerance.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles