Top 5 Common Findings from HIPAA Security Risk Analyses
Recurring Gaps, Root Causes, and Practical Steps Forward
-
August 04, 2026
-
When performing Health Insurance Portability and Accountability Act (“HIPAA”) security risk analyses and HIPAA compliance assessments for covered entities and business associates (“BAs”), we often find consistent control areas where organizations fall short. These issues span technical, operational, and governance domains, and can lead to compliance gaps and/or risk of electronic Protected Health Information (“ePHI”) compromise.
Below are five of the most common findings of HIPAA risk analyses, with a closer look at why they occur and how organizations can address them practically.
Treating Compliance Assessments as a Substitute for Risk Analysis
A foundational issue many organizations face is misunderstanding what constitutes a true HIPAA security risk analysis. In practice, organizations often perform security rule compliance assessments, evaluating whether policies and controls exist. However, a true risk analysis should look beyond HIPAA compliance requirements to gain a full picture of all risk to ePHI confidentiality, integrity, and/or availability. Compliance assessments are easier to standardize and execute, while risk analyses require deeper organizational insight, stakeholder engagement, and judgment around likelihood and impact of a vulnerability being exploited.
To move beyond compliance and toward a genuine risk analysis:
- Conduct a formal, enterprise-wide risk analysis aligned to National Institute of Standards & Technology (“NIST”) 800-531 or Office of Civil Rights (“OCR”) guidance2
- Identify and inventory all systems, applications, and workflows involving ePHI
- Map ePHI data flows to understand how ePHI moves across the organization, internally and externally
- Evaluate and score risks based on both likelihood and impact
- Develop and maintain a risk register with clearly prioritized remediation actions
- Regularly update the analysis to reflect changes in systems, processes, and threats
Excluding Non-Technical Stakeholders from Risk Analyses
Even when organizations go beyond compliance assessment and perform a security risk analysis, they often focus heavily on IT systems. Departments outside of IT, such as clinical operations, revenue cycle, HR, customer support, and research, regularly handle ePHI. Yet these groups are often excluded from structured assessments, leading to blind spots in how information is actually handled day-to-day. Many real-world incidents originate from manual processes and inconsistent procedures across departments. Without engaging business stakeholders, these risks go undetected.
To create a more comprehensive view of risk:
- Include all departments that create, access, or transmit ePHI in the risk analysis scope
- Conduct structured interviews and workflow mapping sessions with business units
- Evaluate how ePHI is handled outside of core systems (e.g., spreadsheets, email, paper)
- Standardize policies and procedures across departments
- Deliver role-based training tailored to how each group interacts with ePHI
- Establish accountability for ePHI management within each functional area
- Periodically reassess workflows as processes evolve
Failure to Enforce Data Retention and Disposal Policies
Most organizations have documented data retention policies, but they are not effectively enforced. This can be due to factors such as decentralized ownership of data, lack of automation, and uncertainty around what can be safely and legally deleted. Over time, systems accumulate large volumes of legacy ePHI that is often retained well beyond regulatory or business requirements. The result is a steadily growing data footprint that expands operational complexity and security risk.
To reduce unnecessary exposure and align with data minimization principles:
- Align retention schedules with legal, regulatory, and operational requirements
- Classify data by type, sensitivity, and required retention period
- Develop and document data lifecycle management policy, standards, and procedures
- Implement automated data lifecycle management where feasible
- Periodically audit systems to identify and remediate over-retained data
- Establish clear ownership for data retention enforcement across departments
- Integrate retention controls into system design and procurement processes
- Document and validate defensible disposal actions
Insufficient Business Associate Management: Beyond the BAA
Business associate risk management is frequently reduced to a contractual exercise. Organizations often ensure that a Business Associate Agreement (BAA) is in place but stop short of evaluating whether the vendor can actually safeguard ePHI. Third parties represent one of the fastest-growing sources of breach risk. Even if internal controls are strong, a weak vendor can expose sensitive data and create regulatory liability.
To strengthen business associate oversight:
- Implement a formal third-party risk management program
- Classify BAs based on the sensitivity and volume of ePHI they handle
- Require security documentation such as SOC 2 reports, HITRUST certification, or detailed questionnaires
- Perform risk-based reviews prior to onboarding vendors
- Establish periodic reassessment cycles for high- and medium-risk BAs
- Monitor vendors for changes in risk posture (e.g., breaches, ownership changes, control gaps)
- Integrate BA risk into the organization’s overall risk register and governance processes
Informal AI Governance: The Emerging Gap
The rapid adoption of AI has outpaced governance in most healthcare organizations. Teams are leveraging AI for productivity gains across software development, finance, research, and administrative functions. However, in many cases, this adoption is happening without formal oversight, defined policies, or technical safeguards. The core issue is ensuring that appropriate controls are in place to protect ePHI when AI is used.
To establish responsible AI use:
- Develop and implement an enterprise AI governance framework
- Define approved and prohibited AI use cases
- Require privacy and security reviews before adopting new AI tools
- Enforce strict de-identification standards for any data used with AI
- Assess data readiness for use in AI platforms and models
- Maintain an inventory of approved AI platforms
- Monitor usage across departments to identify shadow AI adoption
- Provide training on acceptable AI use and associated risks
- Align AI governance with existing HIPAA and data protection policies
Conclusion
These recurring findings highlight a broader shift in how organizations must approach HIPAA compliance. What was once viewed as a regulatory exercise has evolved into an enterprise-wide risk management discipline that requires coordination across technology, operations, vendors, and emerging capabilities like AI.
Organizations that address these gaps effectively are those that:
- Embrace risk-based thinking over checklist compliance
- Treat data as an asset to be actively governed throughout its lifecycle
- Engage the full enterprise in managing ePHI risk
- Extend accountability beyond organizational boundaries to third parties
- Proactively adapt governance to keep pace with innovation
By reframing security risk analyses as strategic tools and not just compliance requirements, organizations can build stronger, more resilient programs that are better equipped for today’s cyber risk landscape.
Footnotes:
1: Computer Security Research Center, NIST SP 800-53 Rev.5, “Security and Privacy Controls for Information Systems and Organizations”.
2: Department of Health and Human Services, Office of Civil Rights, “The HIPPA Security Rule,”.
Related Insights
Related Information
Published
August 04, 2026