All Resources
Healthcare· 6 min read

HIPAA Risk Analysis — The OCR's First Question in Every Audit

Lacking a current risk analysis is the single most common HIPAA violation. NIST 800-30 is the methodology OCR expects.

HIPAA Security Rule requires covered entities and business associates to perform a written risk analysis assessing potential threats to ePHI. OCR's first question in any audit: show me the risk analysis.

FAQ

Frequently Asked Questions

Related Services

How PF Consulting Firm can help

Ready to get started?

Talk with our team — at your direction, we prepare documents, organize filings, and walk you through the process. We do not provide legal representation or legal advice; when your matter calls for it, we'll point you to a licensed attorney.

Call NowRequest Consultation