Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Do We Really Need Another SRA This Year?GRC Frameworks
6 min readFor Compliance Officers

Do We Really Need Another SRA This Year?

Real Questions Compliance Teams Face

Compliance teams grapple with questions every day, questions that arise in hallway chats after audits, in Slack threads late on a Friday, and during budget meetings when leadership questions resource requests. HIPAA compliance isn't just theoretical. It's a daily practice of balancing regulatory demands with operational needs, and the questions below reflect that tension.

Q1: Our last Security Risk Analysis was eight months ago. Do we really need to do another one already?

Yes, if you've had major changes. No, if you haven't.

The Security Rule (45 CFR §164.308(a)(1)(ii)(A)) requires a comprehensive Security Risk Analysis, reviewed and updated annually or after significant changes to systems or workflows. "Significant changes" include new EHR modules, cloud migrations, departmental restructuring, or adding telehealth capabilities.

More important than timing, your SRA should drive real decisions. If it's just a compliance checkbox, you're missing the point. Use it to prioritize remediation, justify budget requests, and guide vendor evaluations. When your CFO questions the need for multi-factor authentication, your SRA should provide the answer.

Document your review cycle and stick to it. If you're on a 12-month schedule and nothing major has changed, a formal review and sign-off is enough. If you've implemented new technology or expanded to a new location, you need a fresh analysis.

Q2: We have 40+ vendors. Do I really need a signed BAA with every single one?

Only if they create, receive, maintain, or transmit PHI on your behalf.

Your cloud hosting provider storing ePHI? Yes, you need a Business Associate Agreement. Your office supply vendor? No. The key is whether the vendor accesses protected health information as part of their service.

Identifying which vendors touch PHI can be tricky. Your email provider might store patient communications. Your analytics platform might process appointment data. Your billing service definitely handles PHI. Start with a vendor inventory that categorizes risk level and PHI access, then ensure every Business Associate has a current, compliant BAA.

Don't skip periodic evaluations. A signed BAA from 2018 doesn't guarantee that vendor still maintains reasonable safeguards. Ask for SOC 2 reports, security questionnaires, or evidence of their HIPAA compliance. If a vendor refuses to provide assurance, that's a red flag worth escalating.

Q3: Our policy library has 60+ documents. How often do I actually need to review all of them?

At least annually, but you don't have to review everything at once.

Policies and procedures supporting HIPAA compliance should be reviewed regularly and updated as systems or risks evolve. That doesn't mean reading 60 documents in one sitting every January.

Build a rolling review schedule. Divide your policies into quarterly batches, access controls and authentication in Q1, incident response and breach notification in Q2, physical safeguards and facility access in Q3, training and workforce accountability in Q4. Assign owners from IT, HR, and clinical leadership so compliance isn't solely responsible for keeping everything current.

Focus your review on whether the policy still reflects actual practice. If your mobile device policy says all smartphones require encryption but your IT team deployed a new BYOD program six months ago, you've got a gap. If your data disposal procedure references tape backups you haven't used in three years, update it. Policies should describe what you actually do.

Q4: A patient requested their records three weeks ago and our release-of-information team is backlogged. Are we going to get fined?

Not yet, but you're cutting it close.

HIPAA requires requests for PHI to be fulfilled within 30 days, with a possible one-time 30-day extension if you document the reason and notify the individual. You're at day 21, which means you have nine days to either deliver the records or send a written extension notice.

This is an area of heightened enforcement. The Office for Civil Rights has made timely access a priority, and repeated failures to respond within the required timeframe can trigger investigations. If your release-of-information process is consistently backlogged, treat it as an operational risk.

Look at where the delays happen. Is it scanning and redaction? Physician review and approval? Payment processing? Each bottleneck requires a different solution. Consider whether automation tools, workflow redesign, or additional staffing would address the root cause. And track your response times, if you can't measure it, you can't manage it.

Q5: Our annual training completion rate is 87%. Is that good enough?

No. You need 100%, and you need documentation to prove it.

The Security Rule requires that all workforce members receive training appropriate to their role. "All" doesn't mean "most" or "everyone except the physicians who are too busy." It means every person with access to ePHI, from the CEO to the part-time receptionist.

That 13% gap represents real risk. Those untrained individuals might click phishing links, share passwords, or improperly dispose of PHI because they don't know the requirements. And if you face an audit or investigation, you'll need to demonstrate that every workforce member was trained.

Build accountability into your onboarding and annual training processes. New hires shouldn't get system access until training is complete. Annual refreshers should have hard deadlines tied to performance reviews or access privileges. If someone consistently refuses to complete training, that's a workforce accountability issue that requires escalation and documentation.

Role-specific content matters, too. Your IT team needs technical safeguard training that your front desk staff doesn't, and your clinicians need privacy training that your billing department might not. Generic, one-size-fits-all modules check a box but don't build the culture of privacy and security that actually protects patient data.

Q6: Leadership wants to know what we'd face if we had a breach. What should I tell them?

It depends on the size, scope, and cause, but the costs go well beyond regulatory penalties.

Under the Breach Notification Rule, if you experience a breach affecting 500+ individuals, you must notify HHS, the affected individuals, and potentially the media. Breaches under 500 individuals still require notification to affected individuals and annual reporting to HHS.

The financial impact includes notification costs, credit monitoring services, legal fees, potential OCR penalties, and reputational damage that affects patient trust and market position. But the operational impact is often worse: the time your team spends managing the breach response, the distraction from normal operations, and the long-term remediation work required to address the vulnerabilities that allowed the breach.

Frame this for leadership as a risk management conversation. Walk through a scenario: a laptop with unencrypted ePHI gets stolen from an employee's car. What happens next? Who gets notified? What does the investigation look like? How long does your clinical team lose productivity? Use your SRA to show where your current vulnerabilities are and what controls would reduce that risk.

Where to Go for More

Start with the Office for Civil Rights guidance library and the HHS HIPAA FAQs, they're more practical than you'd expect from federal resources. Join peer networks like HCCA where compliance officers share real implementation strategies. And don't ignore your internal stakeholders: your IT director, chief medical officer, and privacy officer all have insights that make your compliance program more effective.

HIPAA compliance isn't something you finish. It's something you maintain through ongoing collaboration, regular assessment, and a willingness to adapt as your organization changes. The questions above won't stop coming, but the answers get easier when you've built the processes to support them.

Promotional banner for the Penetration Report Template Kit

You Might Also Like