HHS says providers should use tool for risk assessment

Share this article:
Karen DeSalvo
Karen DeSalvo

The HHS Office of National Coordinator for Health Information Technology and Office for Civil Rights are making a new security risk assessment tool available to help small- to mid-sized providers conduct their own risk assessments. 

The ONC application, available for downloading at www.HealthIT.gov/security-risk-assessment also produces a report that can be provided to auditors. The tool is available for both Windows operating systems and iOS iPads.

 “Protecting patients' protected health information is important to all healthcare providers and the new tool we are releasing will help them assess the security of their organizations,” said Karen DeSalvo, M.D., national coordinator for health information technology. “The SRA tool and its additional resources have been designed to help healthcare providers conduct a risk assessment to support better security for patient health data.”

Conducting a security risk assessment is a key HIPAA mandate and a core requirement for providers seeking payment through the Medicare and Medicaid Electronic Health Records Incentive Program, commonly known as Meaningful Use. Failure to conduct risk assessments on time has been the top problem identified in Meaningful Use attestation audits.

Besides ensuring compliance with HIPAA administrative, physical and technical safeguards, risk assessments also help providers address an organization's vulnerabilities, potentially preventing health data breaches or other adverse security events. 

Many long-term care facilities might not technically be considered a small- to mid-sized provider, but they still could benefit from the new tool, ONC spokesman Peter Ashkenaz told McKnight's. They can use it to get a “sense of what risk assessment may entail,” he said. 

He also recommended that long-term care providers explore the security tool at scap.nist.gov


Share this article:

More in News

Revisions to False Claims Act urged by former deputy AG

A panel of witnesses debated the merits of the False Claims Act before a Judiciary subcommittee meeting Wednesday, with one former attorney general arguing current policy provokes unfair litigation and "coercive" settlements.

Medicare SNF rate finalized, reimbursements to increase by $750 million next year

Medicare SNF rate finalized, reimbursements to increase by ...

Medicare skilled nursing facility reimbursements will increase by $750 million next year under a final payment rule announced Wednesday by the Centers for Medicare & Medicaid Services.

Nursing home did not warn worker who was taken hostage in active ...

A nurse at a Life Care Centers of America facility in Colorado was not notified that she would be threatened and taken hostage by a gunman as part of an active shooter drill, according to a lawsuit filed Tuesday.