SESK: Stuff Everyone Should Know · sesk.info/hipaa-risk-analysis-required
What does the Security Rule require before choosing safeguards?
A risk analysis that identifies threats and vulnerabilities to ePHI.
- Make backup copies of all data
- Notify patients within 60 days
- Assess risks and vulnerabilities to ePHI ✔
Why: A covered entity must conduct an accurate and thorough risk analysis of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
Huh, didn't know that: Risk analysis is not a one-time task. It should be updated when systems change.
Why did the risk analysis carry a map? It wanted to find every vulnerability.
Like this card?
References
Answer: Assess risks and vulnerabilities to ePHI. A covered entity must conduct an accurate and thorough risk analysis of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
- 45 CFR 164.308(a)(1)(ii)(A) www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information.
Checked 2026-10-10.
Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.
More stuff everyone should know
That's stuff everyone should know.