Risk analysis

Risk analysis, computed from your own records

Most risk assessment tools hand you a form you fill in once. This is computed from the records you keep about your clinic, with the reasoning shown behind every determination.

Most “HIPAA risk assessment” tools hand you a form. You fill it in once, print it, and it sits in a folder describing a version of your clinic that stops being accurate the day someone new is hired or a new vendor gets added.

WiseUpHIPAA does not work that way. Your risk analysis is built from the records you keep about your clinic, and the system computes it for you instead of leaving you to re-author a form.

What it actually looks at

When your clinic profile is set up, the system builds an inventory of what you have recorded: your assets and devices, your vendors, and the PHI flows you have mapped, whether that is your EHR, your parent portal, your telehealth platform, or the tablets your RBTs carry into a home session.

Every one of those is checked against the records you maintain, not a generic template:

  • Is the asset recorded as encrypted, and is that record current?
  • Is the vendor’s BAA recorded as executed, or is it missing or expired?
  • What is your staff training completion rate right now?
  • What is your turnover rate, and has anyone marked as terminated not yet had their access revoked in the system?
  • For each PHI flow you have logged, is it recorded as encrypted in transit?
  • Who is recorded as owning each asset, and are they marked cleared for it?

These are your own records, kept in one place instead of scattered across spreadsheets and a once-a-year form. The system computes the analysis from them and shows the record behind each determination, so it is only as current as the records you keep.

How the risk gets scored

Each identified risk gets a likelihood and impact determination, and that determination is not arbitrary. It responds directly to the conditions above. A device recorded as unencrypted scores differently than one that is not. A PHI flow recorded as unencrypted in transit scores differently than one that is not. Low training completion or high turnover pushes the likelihood of an insider-related risk upward, because that is what actually increases exposure.

This means two clinics with the same generic “risk” on paper can land at different scores, because their recorded safeguards are different. That is the difference between an actual risk analysis and a template: a template gives every clinic the same page. This gives every clinic its own answer.

What you actually get

The output is not a vague “you’re at risk” message. It is a dated, clinic-specific risk record: what was assessed, what the findings were, and the reasoning behind each determination. When you are ready, that record can be submitted for review and signed off, so what exists is not just an assessment, it is an attested one, with a date and a name attached.

That record is what an investigator is actually asking for when they request your risk analysis. Not a form. Evidence that someone assessed your real risks, and can prove it.

What this replaces

If you are doing this by hand today, it typically means an annual, or less frequent, manual review, a spreadsheet or downloaded template, and hoping you remembered every system, vendor, and staffing change since the last time you looked at it. This replaces that with one place where those records live, and an engine that computes the analysis from them and shows its reasoning, instead of a form you re-author from memory once a year.

The regulation: read the rule behind this control.

Ready to get your HIPAA program in order?

No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.