Templates
Risk Management
HIPAA Risk Assessment Checklist
🔒

HIPAA Risk Assessment Checklist

1
Identify and document potential threats and vulnerabilities
2
Identify and document all the places where the organization stores ePHI
3
Assess the current security measures
4
Determine the likelihood of threat occurrence
5
Determine the potential impact of threat occurrence
6
Determine the level of risk
7
Approval: Risk Level Determination
8
Identify and document all wireless and remote access points all ePHI flows through
9
Document the physical controls over all data centres and server rooms
10
Determine if the current security measures are sufficient to protect ePHI
11
Identify any additional security measures that could be implemented to further protect ePHI
12
Determine the steps needed to implement any additional security measures
13
Determine the cost of implementing any additional security measures
14
Approval: Additional Security Measures Implementation Plan
15
Update the organization’s risk management plan with the identified changes
16
Identify training needs for staff to comply with the updated risk management plan
17
Develop and execute a training plan for staff
18
Monitor the effectiveness of the updated plan and adjust as needed
19
Approval: Final HIPAA Risk Assessment Report