Skip to main content
Phishing-Proof Your Risk Analysis: A HIPAA ChecklistRegulatory Framework
5 min readFor Business Associate Compliance Teams

Phishing-Proof Your Risk Analysis: A HIPAA Checklist

A phishing email cost Ambry Genetics $700,000 in regulatory penalties and $12.25 million in lawsuit settlements. The breach exposed 225,370 individuals' ePHI over three days in January 2020. However, the Office for Civil Rights (OCR) investigation revealed something more damaging than the attack itself: fundamental gaps in risk analysis, access controls, and workforce management.

This checklist guides you through the specific HIPAA Security Rule requirements that Ambry Genetics failed to implement. Use it to identify whether your organization has similar blind spots before OCR does.

What This Checklist Covers

This checklist addresses the three areas where OCR consistently finds violations during breach investigations: risk analysis under § 164.308(a)(1)(ii)(A), access management under § 164.308(a)(3)(ii)(C), and unique user identification under § 164.312(a)(2)(i). These aren't theoretical requirements. OCR has collected over $3 million in penalties this year alone, with nine out of ten settlements involving risk analysis failures.

Prerequisites

Before you start this checklist, confirm you have:

  • An inventory of all systems that create, receive, maintain, or transmit ePHI. If you don't know where your ePHI lives, you can't analyze risks to it.
  • Documentation of your current security measures. You're comparing what you have against what the Security Rule requires.
  • Authority to interview system administrators and department heads. Risk analysis isn't a paper exercise; you need to understand actual workflows.

The Checklist

Risk Analysis and Management

1. Have you documented all potential threats to ePHI confidentiality, integrity, and availability?

Your risk analysis must identify both human threats (phishing, insider access, social engineering) and environmental threats (hardware failure, natural disasters, ransomware). OCR expects you to consider reasonably anticipated threats, not just the ones that seem likely.

Good looks like: A written risk register that lists specific threat scenarios, the systems they could affect, and the potential impact. "Phishing attack compromising email credentials" should be on that list with an assessment of likelihood and harm.

2. Have you evaluated the vulnerability of your existing security measures to those threats?

Walk through each threat and ask: What's stopping this from happening? If the answer is "nothing" or "employee awareness," you've found a vulnerability.

Good looks like: For each identified threat, you have documented which security controls (technical, administrative, or physical) currently mitigate it and where gaps exist. If phishing is a threat and you don't have multi-factor authentication on email, that's a documented vulnerability.

3. Have you assessed the likelihood and impact of each threat exploiting each vulnerability?

This is where many organizations stop short. OCR wants to see that you've thought through what happens if the threat succeeds.

Good looks like: A matrix showing threat-vulnerability pairs with likelihood ratings (low/medium/high) and impact assessments (number of records exposed, types of data, potential harm). The Ambry Genetics breach exposed names, addresses, dates of birth, driver's license numbers, diagnosis information, medications, treatment data, and some Social Security numbers across 225,370 records. That's high impact.

4. Have you implemented security measures to reduce risks to a reasonable and appropriate level?

"Reasonable and appropriate" means proportional to the risk. If your risk analysis identifies phishing as a high-likelihood, high-impact threat, you can't address it with an annual training video alone.

Good looks like: Technical controls (multi-factor authentication, email filtering, endpoint detection), administrative controls (phishing simulation exercises, incident response procedures), and physical controls where relevant. Document why you chose each measure and how it reduces specific risks.

Access Management

5. Do you have written policies for terminating access to ePHI when employment ends or access is no longer needed?

The Security Rule requires this under § 164.308(a)(3)(ii)(C). Ambry Genetics failed here. Orphaned accounts are phishing targets because nobody's monitoring them for suspicious activity.

Good looks like: A policy that specifies who triggers the access termination process (HR, IT, or both), what systems are included, and the timeline. Same-day termination for involuntary separations; end-of-business-day for role changes.

6. Do you actually terminate access according to that policy?

Having the policy isn't compliance. You need to execute it consistently.

Good looks like: An audit trail showing that access was disabled within the timeframe your policy specifies for the last 10 terminated employees. If you find accounts that should have been disabled months ago, you're non-compliant.

User Identification and Tracking

7. Does every person who accesses ePHI have a unique username?

Shared accounts make it impossible to track who did what. OCR found that Ambry Genetics hadn't assigned unique usernames to all workforce members requiring ePHI access.

Good looks like: No shared "front desk" or "billing department" logins. Every user authenticates with their own credentials. Your access logs show individual names, not role accounts.

8. Can you produce an audit trail showing who accessed specific ePHI and when?

Unique usernames are pointless if you're not logging their activity.

Good looks like: You can pull a report showing which users accessed a specific patient record over the past 90 days. When OCR investigates a breach, they'll ask for this.

Workforce Training

9. Have you trained all workforce members on your HIPAA policies and procedures within the past year?

The Security Rule requires training at § 164.308(a)(5)(i). Generic compliance training doesn't count if it doesn't cover your organization's specific policies.

Good looks like: Training records showing that each employee completed modules on your access termination procedures, your incident response plan, and how to recognize phishing attempts. The training references your actual policies by name.

10. Do you conduct phishing simulations and measure click rates?

Training effectiveness isn't self-reported. You need to test whether your workforce can spot a phishing email.

Good looks like: Quarterly simulated phishing campaigns with click-rate tracking by department. When someone clicks, they get immediate remedial training. You document trends over time to show improvement.

Common Mistakes

Treating risk analysis as a one-time project. The Security Rule requires periodic review and updates. If you completed your risk analysis in 2019 and haven't touched it since, you're non-compliant.

Documenting risks without implementing mitigations. Knowing you're vulnerable to phishing doesn't satisfy the Security Rule. You must implement measures to reduce that risk.

Assuming your IT team handles access termination automatically. Unless HR triggers the process and verifies completion, terminated employees often retain system access for weeks.

Next Steps

  1. Schedule your risk analysis review now. If your last comprehensive analysis is more than a year old, start fresh.
  2. Audit your access termination process. Pull a list of employees who left in the past six months and verify their accounts are disabled.
  3. Implement multi-factor authentication on email if you haven't already. It's the single most effective control against credential phishing.
  4. Document everything. OCR's investigation starts with "show us your risk analysis." If you can't produce it, the settlement conversation begins with a penalty, not a corrective action plan.

You Might Also Like