Understanding Your HIPAA Risk Assessment Report
The Risk Assessment Report is a detailed plan of action designed to assist you in implementing your compliance plan. It serves as a blueprint for your organization's HIPAA compliance strategy and identifies any non-compliance issues or vulnerabilities. This report is often the first document requested by auditors in the event of a breach.
Define what the Risk Assessment Report is and why it matters.
Provide guidance on how to effectively review results.
Clarify the scope of the assessment regarding Protected Health Information (PHI).
Explain the transition from Risk Assessment to Policy and Procedure (P&P) creation.
The primary focus of this Assessment is strictly PHI and HIPAA. While other data security is important, this Report specifically addresses how PHI flows through your environment and the associated risks.
Delegated to Total HIPAA: These are items our team will be creating or resolving for you. Many of these items will be included in the customized HIPAA Policies and Procedures we will create.
Delegated to Client: These are actions your team must take internally to mitigate specific vulnerabilities identified. This does not mean that Total HIPAA will not assist your team in determining the best solution or provide suggestions for implementation as these are items we cannot physically implement in your systems.
Some of the vulnerabilities identified in this report will be directly resolved through the implementation of your customized HIPAA Privacy and Security Policies and Procedures. Other vulnerabilities need to be reviewed by your team to determine the best resolution method. This review is your opportunity to ensure the information is accurate before we move into the P&P creation phase.
We need your review and honest feedback on whether mitigating certain vulnerabilities is cost prohibitive or otherwise not doable.
The report is accessible through the application and includes several key components for review:
Verify Accuracy: Ensure all information regarding your day-to-day functions and technical environment is correct. “I don’t know” does not provide us with the information we need to create your custom HIPAA Compliance Plan.
Add Comments: Use the application to leave comments or ask questions on specific line items if you need clarification. It is key that you leave comments and engage with our team if you have any questions as it is important that you understand why items were flagged as vulnerabilities and how to resolve them.
Answer Questions: Please review all comments from the Total HIPAA Compliance Team in the comments when reviewing the report. These answers are key to helping our team continue to understand your organization and how your team interacts with PHI.
Technical Consultation: We recommend involving your IT department or vendors to review technical security questions.
Submit for Review: Once you have completed your internal review and added any necessary comments, click the "Submit Comments For Review" button. You do NOT need to mitigate every vulnerability before your review of the report is submitted. We just need to ensure the report is as accurate as possible to date to create a HIPAA Compliance Plan reflective of the Organization.
Compliance Team Review: Our team will review your feedback and finalize the assessment.
P&P Personalization: Upon verification of the report, our Compliance Team will begin personalizing your customized Policies and Procedures.