Security Risk Analysis, v1.0

Specifies that a health care related organization must conduct an accurate and thorough assessment of the potential risks and vulnerabilities to protected health information.

Assessment Step

1
Risk Assessment (RiskAssessment)
Does the covered entity or business associate conduct, in accordance with Section 164.306 (Security standards: General rules), an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the organization?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Standard: Security management process. Implement policies and procedures to prevent, detect, contain, and correct security violations.

Conformance Criteria (1)

Conduct Risk Assessment
The covered entity or business associate must conduct , in accordance with Section 164.306 (Security standards: General rules), an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the organization.
Citations
HIPAA-Security-Rule
45 CFR Section 164.308(a)(1)(ii)(A)
HIPAA-Security-Rule
45 CFR Section 164.306