Privacy & Security Resources

Security Risk Analysis Tip Sheet

34114
CMS and OCR post on
Security Risk Analysis Tip Sheet

Protect Patient Health Information - Updated March 2016

Conducting or reviewing a security risk analysis to meet the standards of Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule is included in the meaningful use requirements of the Medicare and Medicaid EHR Incentive Programs. Eligible professionals must conduct or review a security risk analysis for each EHR reporting period to ensure the privacy and security of their patients’ protected health information. 

Conducting a security risk analysis is required when certified EHR technology is adopted in the first reporting year. In subsequent reporting years, or when changes to the practice or electronic systems occur, a review must be conducted.

Documents to download

Previous Article My entity just experienced a cyber-attack! What do we do now?
Next Article How to Establish an Ongoing Security Program and Meet Meaningful Use Requirements for Security Risk Analysis

Leave a comment

Add comment

Highlighted Resources & Events

The Quadruple Aim

Quadruple Aim

A Conceptual Framework

Improving the U.S. health care system requires four aims: improving the experience of care, improving the health of populations, reducing per capita costs and improving care team well-being. HITEQ Center resources seek to provide content and direction aligned with the goals of the Quadruple Aim

Learn More

Acknowledgements

This resource collection was cultivated and developed by the HITEQ team with valuable suggestions and contributions from HITEQ Project collaborators.