Auditor Tips: Conduct an Accurate and Thorough Risk Analysis

Yet a complete and thorough risk analysis is one of the best ways for you and your organization to make intelligent and informed business decisions

Updated:  
February 14, 2023
Auditor Tips
HIPAA
Auditor Tips: Conduct an Accurate and Thorough Risk Analysis
Quick Answer:

Can you conduct a HIPAA risk analysis using only in-house staff?

You can start with in-house resources, but a thorough risk analysis typically requires expertise most internal IT teams lack, spanning IT, business process analysis, and cybersecurity specifically, making qualified external support important for a truly comprehensive result.

- Internal risk analyses often miss vulnerabilities because IT staff are stretched thin and rarely have formal training in security risk assessment specifically.
- Sound resource allocation depends on accurately understanding your risk landscape; without that, it's difficult to decide where security spending should actually go.
- Non-security professionals or unqualified third parties conducting a risk analysis carry the same limitation as doing it entirely in-house, missing threats a specialized reviewer would catch.
- Using internal staff as a starting point is reasonable, but treating that alone as sufficient for full HIPAA compliance risks an incomplete analysis.

*This article was taken from our HIPAA Guide. For more information on this topic, download our free HIPAA Guide.

“Without adequately understanding your risk, how would you best decide where to put your resources?”

As we work with individual entities, we find that because they attempt to perform a risk analysis with only in-house skills, anon-security professional, or an unqualified third party, many vulnerabilities and risks are missed.

An in-house risk analysis can be a great first step toward HIPAA compliance, but if your staff is stretched too thin (as they typically are),you probably won’t see accurate and thorough results. Additionally, IT staff members are rarely trained to perform a formal risk analysis.

Performing a risk analysis is a skill set that requires extensive experience in information technology, business process flow analysis, and cybersecurity, so it is usually unrealistic to expect your IT staff to accomplish this task for you.

Yet a complete and thorough risk analysis is one of the best ways for you and your organization to make intelligent and informed business decisions. After all, without adequately understanding your risk, how would you best decide where to put your resources?