If the Office for Civil Rights (OCR) knocks on your door — through a random audit, a breach investigation, or a patient complaint — the first document it will ask for is your security risk analysis. Not your firewall configuration. Not your penetration test report. Your risk analysis.
It is the foundation of the HIPAA Security Rule, and it remains the most consistently botched requirement in healthcare compliance. OCR has said as much: its ongoing enforcement initiative and the current round of compliance audits both focus squarely on the risk analysis and risk management provisions of the Security Rule.
Mid-market healthcare organizations — regional provider groups, specialty clinics, community hospitals, and the health IT vendors that serve them — occupy an uncomfortable middle ground. They hold enough protected health information (PHI) to be attractive targets and to draw regulatory attention, but they rarely have the dedicated compliance staff of a large health system. After years of performing HIPAA security and privacy compliance reviews for organizations in this segment, we see the same failures repeat. Here are the ones that matter most.
Mistake #1: Confusing a gap assessment with a risk analysis
This is the error OCR cites more than any other. Completing a checklist walkthrough of the Security Rule's safeguards — "Do we have access controls? Yes. Do we encrypt laptops? Mostly." — is a gap assessment. It is useful, but it is not a risk analysis.
A true risk analysis under 45 CFR § 164.308(a)(1) requires you to identify where electronic PHI lives, the threats and vulnerabilities that could compromise it, the likelihood and impact of those threats materializing, and the resulting risk levels. The distinction sounds academic until an investigator asks to see your threat identification and likelihood ratings and you hand them a compliance checklist. Resolution agreements are full of organizations that made exactly this substitution.
Mistake #2: Scoping to the EHR and stopping there
A risk analysis is only as good as its asset inventory. Most mid-market organizations can tell you about their electronic health record system. Far fewer have accounted for the ePHI sitting in email archives, cloud file shares, billing platforms, backup repositories, medical devices, departmental spreadsheets, text messages between clinicians, and the systems run by their business associates.
If ePHI exists somewhere your risk analysis never looked, then by definition you have not analyzed the risk to it. Breaches disproportionately originate in exactly those unexamined corners. The inventory step is tedious. It is also the step that determines whether everything downstream is meaningful.
Mistake #3: Treating it as a one-time event
The Security Rule requires the risk analysis to be an ongoing process, not a binder produced once and shelved. Yet we routinely encounter organizations whose most recent analysis predates their cloud migration, their merger, their new telehealth platform, or their last three EHR module deployments.
Your risk analysis should be refreshed when the environment changes materially and reviewed on a regular cadence regardless. An analysis describing an infrastructure that no longer exists is worse than useless in an investigation — it demonstrates that leadership knew the obligation existed and let it lapse.
Mistake #4: Findings that never become a risk management plan
Identifying risk is half the requirement. The other half — 45 CFR § 164.308(a)(1)(ii)(B) — is implementing security measures sufficient to reduce those risks to a reasonable and appropriate level. In practice, this means every significant finding needs an owner, a remediation decision, and a documented timeline.
The pattern OCR penalizes hardest is not ignorance; it is the organization that identified a risk in 2022, documented it, and did nothing. A risk analysis that surfaces problems you have and then leave unaddressed creates a paper trail of willful neglect — which is the most expensive penalty tier in the HIPAA enforcement scheme.
Mistake #5: Treating "addressable" as "optional"
The Security Rule labels certain implementation specifications — encryption being the famous example — as "addressable." Many mid-market firms have quietly read that word as "optional." It is not. Addressable means you must assess whether the safeguard is reasonable and appropriate for your environment, implement it if it is, and document a legitimate rationale plus an equivalent alternative if it is not. "We never got around to it" does not qualify.
The addressable/optional distinction is about to disappear anyway: the Security Rule update proposed in January 2025 would eliminate the addressable designation entirely, making encryption, multi-factor authentication, and other controls flatly mandatory.
Mistake #6: Forgetting the business associates
Your risk posture includes every vendor that creates, receives, maintains, or transmits ePHI on your behalf. Mid-market organizations frequently have signed Business Associate Agreements on file but no idea whether those vendors actually maintain reasonable safeguards.
A BAA transfers certain legal obligations; it does not transfer your risk. Some of the largest healthcare breaches of the past few years originated at business associates, and the covered entities involved still absorbed the operational damage, the patient notification burden, and the reputational cost. Vendor risk belongs in your risk analysis, not adjacent to it.
Mistake #7: Buying a template and calling it done
There is a thriving market in fill-in-the-blank risk analysis templates, and to be fair, a good template beats a blank page. But a generic document listing generic threats against a generic clinic does not describe your organization — and investigators can tell.
The analysis must reflect your actual systems, your actual data flows, and your actual threat exposure. Examples such as ransomware targeting healthcare, credential phishing against your workforce, and insider misuse of records are all potential threats — but the specifics matter. If your risk analysis would read identically for the practice across town, it is not an analysis of your risk.
The line OCR looks for.
A risk analysis that is complete, current, documented, and genuinely used to drive decisions — sized to your organization, but real.
A fair counterpoint: you can also overdo this
Honesty requires acknowledging the other side. Some organizations, often after a scare, swing into compliance over-engineering: hundred-page risk registers nobody reads, quarterly reassessments that consume staff time without changing decisions, and controls adopted because a framework mentioned them rather than because they reduce actual risk.
HIPAA is explicitly scalable — the rule instructs regulators and organizations alike to weigh size, complexity, and capabilities. Compliant does not mean secure, and simple is often more secure in general. The goal for a mid-market firm is a risk analysis that is complete, current, documented, and genuinely used to drive decisions. It does not need to be enormous. It needs to be real.
The regulatory ground is shifting: prepare, but don't panic
A note on the proposed Security Rule overhaul: as of mid-2026, it remains a proposed rule, not final law. The comment period drew thousands of responses, a large coalition of hospital and provider groups has pushed for it to be withdrawn or scaled back, and the federal regulatory agenda now targets 2027 for final action.
Anyone telling you the new requirements are already binding is wrong. But anyone telling you to ignore them is also giving bad advice — because OCR's enforcement priorities have already moved toward the controls the proposal contemplates, and most of them (encryption at rest and in transit, MFA, tested incident response) simply describe what reasonable security looks like in 2026. A sound risk analysis today positions you for whatever version of the rule eventually lands.
Where to start
If any of the seven mistakes above sound familiar, the fix begins with an honest, structured look at where you stand. Digital Elevation's HIPAA Security and Privacy Compliance Review evaluates your administrative, physical, and technical safeguards against the Security Rule and Privacy Rule. It includes your risk analysis methodology and documentation with a thorough document review, stakeholder interviews, and a gap analysis mapped to specific HIPAA citations. Prioritized findings by risk severity and regulatory impact are communicated and documented. The deliverable is written in plain language, sized to your organization, and designed to give you a practical path forward — not a shelf document.
Compliance shouldn't be guesswork.
If you'd like clarity on how your risk analysis would hold up under scrutiny, we should talk.
Start the conversation arrow_forwardW. Scott Montgomery is Director of Security at Digital Elevation.