Risk Management
Risk management is the ongoing process of identifying threats to an organization's information and assets, assessing how serious those threats are, and taking steps to reduce them to an acceptable level. In the HIPAA context, it generally refers to how a covered entity or business associate keeps electronic protected health information (ePHI) reasonably protected. It is a continuous activity rather than a one-time task, and no risk management program can guarantee that all breaches are prevented.
Risk management is the systematic process of identifying, assessing, prioritizing, and addressing risks to organizational operations, assets, and information. Under the HIPAA Security Rule, risk management is generally treated as a required administrative safeguard within the security management process: following a risk analysis, an organization must implement security measures sufficient to reduce risks and vulnerabilities to ePHI to a reasonable and appropriate level. It is distinct from the underlying risk analysis (which identifies and evaluates risks) in that it focuses on the ongoing selection, implementation, monitoring, and control of mitigating measures. Note that the HIPAA Security Rule applies only to ePHI, not to PHI in oral or paper form, and that the HITECH Act, state law, or frameworks such as the HITRUST CSF may impose additional or more specific requirements. Practitioners should confirm current regulatory obligations against the applicable CFR text and current HHS OCR guidance.
Why it matters
Risk management sits at the core of the HIPAA Security Rule's security management process. Because the Security Rule generally treats risk management as a required administrative safeguard, an organization that cannot demonstrate an ongoing process for reducing risks to ePHI may struggle to show it has met its obligations. Risk analysis identifies and evaluates the threats and vulnerabilities, but risk management is where an organization actually selects, implements, monitors, and adjusts the measures that bring those risks down to a reasonable and appropriate level.
The distinction matters in practice: identifying a risk is not the same as addressing it, and regulators and auditors generally look for evidence that identified risks were acted upon over time. Risk management is a continuous activity rather than a one-time exercise, since threats, systems, and business relationships change. It applies to covered entities and business associates alike wherever they create, receive, maintain, or transmit ePHI.
It is important to be realistic about what risk management can accomplish. No risk management program can guarantee that all breaches are prevented; the goal is to reduce risks and vulnerabilities to a reasonable and appropriate level, not to eliminate them entirely. Organizations should also remember that the HIPAA Security Rule covers only ePHI, and that the HITECH Act, state law, or frameworks such as the HITRUST CSF may impose additional or more specific requirements that go beyond the baseline HIPAA obligations.
Who it's relevant to
Inside Risk Management
Common questions
Answers to the questions practitioners most commonly ask about Risk Management.