What does the Security Rule require before choosing safeguards?

A risk analysis that identifies threats and vulnerabilities to ePHI.

Start playing free

  1. Make backup copies of all data
  2. Notify patients within 60 days
  3. Assess risks and vulnerabilities to ePHI ✔

Why: A covered entity must conduct an accurate and thorough risk analysis of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.

Huh, didn't know that: Risk analysis is not a one-time task. It should be updated when systems change.

The dad joke
Why did the risk analysis carry a map? It wanted to find every vulnerability.
Like this card?
Play the game

References

Answer: Assess risks and vulnerabilities to ePHI. A covered entity must conduct an accurate and thorough risk analysis of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.

  1. 45 CFR 164.308(a)(1)(ii)(A) www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
    Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information.
    Checked 2026-10-10.

Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.

Test yourself in the game