The risk management plan: what you did about what you found

The risk analysis finds the gaps. The risk management plan is what you do about them, and it is a separate Required obligation. Owner, date, and evidence on every finding, or a documented decision to accept the risk.

Last verified: 2026-07-26

Fourteen months ago this clinic did a real risk analysis. Not a template, a real one. It found eight gaps: two unencrypted tablets, a vendor with no BAA, a shared front-desk login, and four more. The document is thorough, and it is filed. An investigator opens it, reads finding number three, and asks one question: what did you do about this? The room goes quiet, because the honest answer is nothing. The analysis was the whole project. Nobody built the part that comes after.

That is the failure this obligation exists to prevent, and it is the most common shape compliance takes in a small clinic: a good look at the problem, followed by no action on it.

Two requirements, not one

The risk analysis and the risk management plan are separate obligations that sit side by side in the rule, and they are both Required. Risk analysis (45 CFR 164.308(a)(1)(ii)(A)) is the looking: an accurate and thorough assessment of the risks to your ePHI. Risk management (45 CFR 164.308(a)(1)(ii)(B)) is the doing: implement security measures sufficient to reduce those risks to a reasonable and appropriate level.

Read them together and the trap is obvious. An analysis that finds gaps and leaves them open satisfies (A) and violates (B). You did the looking. You skipped the doing. And because the doing is a distinct Required specification, skipping it is not a smaller version of compliance, it is a separate violation, one you documented yourself the day you wrote the analysis down. The full treatment of the looking half lives in your risk analysis; this page is the doing half.

What “reduce to a reasonable and appropriate level” actually means

The rule does not ask you to eliminate every risk. It asks you to reduce risks to a reasonable and appropriate level to comply with the general requirements at 45 CFR 164.306(a): the confidentiality, integrity, and availability of ePHI, and protection against reasonably anticipated threats.

“Reasonable and appropriate” is where clinics get room to breathe, and the rule is explicit about it. Flexibility of approach (45 CFR 164.306(b)) says you may choose measures that fit your clinic, weighing your size and complexity, your technical capabilities, the cost of the measure, and the probability and criticality of the risk. A twelve-person clinic is not held to a hospital’s controls. That is real flexibility, and it is the reason a sane risk management plan is possible at all.

But flexibility is a reason to decide, not a reason to ignore. Weighing cost and criticality and concluding that a given residual risk is acceptable is a legitimate outcome (164.306(b)). Never looking at the finding again is not. The difference between the two is a written decision, and it is the whole ballgame.

What a real plan produces

A risk management plan is not a document you write once. It is a live list, one row per finding, and each row carries the same few things:

  • An owner. A named person responsible for the finding, not “the practice” and not “IT.” The compliance officer may hold the list, but each finding needs a human attached to it.
  • A target date. When it will be resolved, set by how bad it is. The unencrypted tablet holding session video does not get the same clock as a low-severity documentation gap.
  • What was done, and the evidence. Not the word “resolved,” but the specific action and proof of it: the device was encrypted on this date, here is the confirmation.
  • Or a documented decision to accept. If you weighed it and decided the residual risk is reasonable and appropriate, that reasoning is the record.

An unaddressed finding is not an accepted risk. It is an open liability with your name on it. An accepted risk has a reason attached. An ignored finding has only a date attached, the day you found it and did nothing, and that is the date an investigator will read back to you.

Why the shelved analysis is worse than no analysis

There is a cruel logic here that mirrors the policy-template problem. A clinic that never did a risk analysis can at least claim it did not know. A clinic that did a thorough analysis, found the gap, and left it open cannot. The document proves knowledge, and knowledge plus inaction is the worst posture an investigation can find. You built the exhibit against yourself and then declined to act on it.

“An unaddressed finding is not an accepted risk. It is an open liability with your name on it.”

This is why “we have a risk analysis” is not the reassuring sentence clinics think it is. The analysis is the input. The plan is the deliverable, and the plan is what turns a finding into a closed item instead of a standing admission.

The enforcement direction

For years the headline failure was the missing risk analysis, and it is still OCR’s most-cited administrative deficiency. But the question does not stop at whether you looked. It moves to what you did about what you found, which is exactly the (A) then (B) sequence the rule lays out. A clinic that can show a finding, an owner, a date, and a closure is answering the harder question before it is asked. A clinic that can only produce the analysis is answering the easy half and hoping the hard half does not come up. For how that plays out once an investigator is involved, see what OCR actually does.

The ABA-specific version

The findings an ABA clinic generates are not abstract, and each one needs an owner and a date rather than a mention:

  • The field tablet with session video, unencrypted, that surfaced in the analysis and is still unencrypted.
  • The scheduling or notetaking tool a clinician adopted, flagged as having no BAA, still in use.
  • The shared login the analysis identified, that nobody has split into individual accounts.
  • The former employee whose access the analysis flagged as still live.

None of these is hard to fix. They stay open because finding them and fixing them are two different jobs, and only the first one got done.

How it dies

The analysis gets treated as the finish line. It is filed, the box is ticked, and the findings inside it are never assigned, dated, or closed. A year later the next analysis finds the same gaps, because nothing between the two ever acted on the first. The plan dies the moment the analysis is mistaken for the deliverable.

The bottom line

Looking is half the requirement and the easy half. The other half is a list where every finding has an owner, a date, and either evidence that it was fixed or a written decision that the residual risk is acceptable. Reduce your risks to a reasonable and appropriate level, decide on purpose about the ones you do not fully close, and keep the record. The clinic that can show what it did about what it found is answering the only question that ultimately matters.

The short version

  • Risk analysis (164.308(a)(1)(ii)(A)) and risk management (164.308(a)(1)(ii)(B)) are a Required pair: one finds the risks, the other reduces them.
  • Doing the analysis and not acting on it satisfies the looking and violates the doing, and a documented finding you ignored is worse than never looking.
  • A real plan tracks each finding with an owner, a target date, what was done, and the evidence, or a documented decision to accept the residual risk.
  • The rule requires reducing risk to a reasonable and appropriate level (164.306(a)), not to zero, and 164.306(b) lets you weigh size, cost, and criticality.
  • OCR's question moves from did you assess to what did you do about what you found.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

Findings with an owner and a date, not a shelf.

WiseUpHIPAA turns each risk finding into a task with an owner, a due date set by its severity, and a place for the evidence of what was done, or an attributed decision to accept the risk with the reason recorded. It shows you what is still open and overdue, so the distance between what you found and what you fixed is visible instead of buried.

Ready to get your HIPAA program in order?

No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.