SESK: Stuff Everyone Should Know · sesk.info/hipaa-risk-management-required
After a risk analysis, what must an organization do?
Use risk management to reduce risks to a reasonable and appropriate level.
- Reduce risks to a reasonable and appropriate level ✔
- Eliminate all possible risks
- Encrypt every email
Why: Risk management means implementing security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.
Huh, didn't know that: HIPAA does not require perfect security, but risks must be reduced to a reasonable level.
Why did the risk manager bring a level? To make risks reasonable and appropriate.
Like this card?
References
Answer: Reduce risks to a reasonable and appropriate level. Risk management means implementing security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.
- 45 CFR 164.308(a)(1)(ii)(B) www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.
Checked 2026-10-10.
Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.
More stuff everyone should know
That's stuff everyone should know.