HIPAA

HIPAA Risk Assessment

HIPAA-specific requirement to evaluate threats to ePHI and determine the likelihood and impact of potential breaches. HHS OCR cites failure to conduct risk assessments as the most common finding in enforcement actions.

From the library

The full analysis on HIPAA Risk Assessment.

The article is where the term meets the practitioner. Read how this concept actually shows up in audit, in remediation, and in the boardroom.

Read the analysis →
The Authority Brief

One compliance analysis per week from Josef Kamara, CPA, CISSP, CISA. Federal and private compliance, written for practitioners.