PrivacySignal
Healthcare

HIPAA Security Risk Assessment Checklist

HIPAA Journal · · US Federal · Healthcare Privacy

The HIPAA Journal has published a checklist guide covering how organizations should conduct security risk assessments under HIPAA, including identifying threats to protected health information and evaluating how likely those threats are to occur.

Why this matters: Most healthcare data breaches do not start with sophisticated attacks. They start with basics that were never checked. A risk assessment is the part of HIPAA that forces organizations to actually look at where patient data sits, who can reach it, and what could go wrong. Many covered entities treat it as a paperwork exercise. That gap is where breaches happen. If you work in health data compliance, this kind of checklist is less about ticking boxes and more about whether your organization can prove it took the threat seriously before something went wrong.

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

The Attacker Did Not Need to Sleep

Spain received its first reported personal-data breach carried out by an AI agent. The techniques were familiar. The speed and autonomy were not.

· 4 min read Read →

Related stories

Healthcare
HIPAA Journal · · US Federal

HHS-OIG Urges CMS & MA Organziations Increase Efforts to Prevent Durable Medical Equipment Fraud

Each year, millions of taxpayers’ dollars are lost to Medicare and Medicaid fraud, with fraud related to durable medical equipment, […] The post HHS-OIG Urges CMS & MA Organziations Increase Efforts to Prevent Durable Medical Equipment Fraud appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Democratic Senators Reintroduce the Health Infrastructure Security and Accountability Act

On September 17, 2026, two Democratic Senators reintroduced the Health Infrastructure Security and Accountability Act, which seeks to improve cybersecurity […] The post Democratic Senators Reintroduce the Health Infrastructure Security and Accountability Act appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Hacking Group Claims Attack on Cedar County Memorial Hospital

A hacking group has claimed responsibility for an August 2026 cyberattack on Cedar County Memorial Hospital in Missouri. Hacking-related data […] The post Hacking Group Claims Attack on Cedar County Memorial Hospital appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

House Subcommittee on Health Examines Healthcare Cybersecurity Proposals

On September 15, 2026, the United States House Energy and Commerce Committee Subcommittee on Health held a legislative hearing on […] The post House Subcommittee on Health Examines Healthcare Cybersecurity Proposals appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Hacking Incident Affects 46,000 Hawaii Family Dental Patients

A hacking incident at Hawaii Family Dental has affected almost 46,000 individuals. Data breaches have also been announced by Life […] The post Hacking Incident Affects 46,000 Hawaii Family Dental Patients appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
DataBreaches.net · · International

HHS Releases Updated Security Risk Assessment Tool

The U.S. Department of Health and Human Services has released version 3.7 of its Security Risk Assessment Tool, a joint product from the Office for Civil Rights and the Office of the National Coordinator for Health IT designed to help organizations evaluate their HIPAA security compliance.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →