Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Hospitals can evaluate electronic health record (EHR) security and privacy by tracing electronic protected health information (ePHI) across the full care environment, analyzing risks to that information and to clinical operations, testing safeguards against evidence, and tracking each finding through remediation and retesting. HIPAA requires a risk-based process and appropriate safeguards—not a universal product checklist, mandatory score, or single assessment schedule.

What does HIPAA require hospitals to assess?

The HIPAA Security Rule applies to ePHI created, received, used, maintained, or transmitted by covered entities and business associates. It requires appropriate administrative, physical, and technical safeguards. The current rule is in 45 CFR Part 160 and Part 164, Subpart C. The U.S. Department of Health and Human Services (HHS) describes the Security Rule as establishing national standards to protect this ePHI.

That scope is broader than the EHR application. A hospital should account for the systems, people, locations, devices, vendors, and workflows through which ePHI moves or is stored. A review limited to the EHR vendor’s software or a completed questionnaire can miss consequential risks in interfaces, endpoints, backups, identity management, or clinical procedures.

HHS lists a proposed update to the Security Rule dated January 6, 2025. A proposal is not the same as an effective rule; hospitals should distinguish proposed changes from currently applicable requirements when documenting obligations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How can a hospital evaluate EHR security and privacy?

Use a repeatable, evidence-based sequence. The precise methods and depth should fit the hospital’s ePHI, systems, workflows, and risks; HHS does not prescribe one universally best risk-analysis method. Qualitative, quantitative, or combined methods may be used.

  1. Set the boundary around ePHI

    Map where ePHI is created, received, maintained, or transmitted and identify who owns each system and workflow. Include the EHR and relevant interfaces, patient portals, mobile access, databases, backups, endpoints, network paths, and third parties. Confirm covered-entity and business-associate relationships, including which party operates each service and handles the information.

    Follow the information rather than stopping at an application boundary. For example, a clinical workflow may involve an EHR, a results interface, a connected diagnostic system, a clinician’s endpoint, and a backup service. Each can affect the confidentiality, integrity, or availability of ePHI.

  2. Build a risk picture for assets and workflows

    For each important asset and workflow, record relevant threats and vulnerabilities, the likelihood of exploitation or failure, and the potential impact. Consider confidentiality, integrity, and availability together. Unauthorized disclosure matters, but so do altered clinical data, delayed access to records, and disruption to care.

    Free tools Windows power users keep installed

    One-click scans. No signup required.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

    Document the rationale for each risk level and connect it to a corrective action. HHS does not establish a mandatory scoring formula, so a hospital should explain its chosen method well enough that decision-makers can understand and consistently apply it.

  3. Test safeguards against operating evidence

    Organize the review across administrative, physical, and technical safeguards. Request evidence appropriate to the hospital’s risk profile, such as policies and procedures, role definitions, user lifecycle records, access-review results, audit-log evidence, incident records, configurations, patch status, resilience documentation, and remediation tracking.

    Determine whether controls work in practice rather than treating written policies as proof of operation. For example, compare an access policy with actual account provisioning and removal records, or compare stated review procedures with completed access reviews and recorded follow-up.

  4. Review privacy, permissions, and purpose

    Compare staff roles and clinical workflows with actual EHR permissions and access records. Ask whether access is appropriate to a user’s role and purpose, whether unnecessary use or disclosure is limited, and how exceptional access is governed and reviewed.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

    The Privacy Rule’s minimum-necessary standard calls for reasonable limits on unnecessary use and disclosure, applied in context. It should not be read as a blanket prohibition on a care team accessing a broader record when needed for treatment.

  5. Include software, vendors, and integrations

    Review supported-software status, patch processes, vendor advisories, vulnerability-scan results, and who is responsible for remediation across the EHR and connected systems. A vulnerability may cross organizational boundaries: the hospital should identify who investigates it, who applies or approves a fix, and how the hospital verifies the result.

    In a January 2026 newsletter, HHS specifically identified EHR software as software that may need patching and pointed to vendor notices, vulnerability scanning, NIST’s National Vulnerability Database (NVD), and CISA’s Known Exploited Vulnerabilities (KEV) catalog as resources. These resources change over time; when documenting a specific vulnerability or patch, include the relevant date and status rather than presenting it as timeless guidance.

  6. Prioritize findings and verify remediation

    For each finding, record the affected ePHI and workflow, risk rationale, remediation owner, target date, interim mitigation if needed, and evidence required to close the issue. Retest or otherwise verify that the corrective action addressed the risk; retain the result with the finding.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

    Reassess when technology, vendors, business operations, or the threat environment changes, and on a periodic schedule chosen by the hospital. HHS requires ongoing evaluation and risk management but does not prescribe one universal interval. The appropriate cadence depends on circumstances and should be supported by the hospital’s risk-management process.

What should a hospital include in its assessment record?

A useful record lets the hospital move from scope to risk, action, and evidence without losing accountability. The contents can be scaled to the system and risk, but should make clear what was assessed, what was found, and how the hospital will follow up.

  • Scope: systems, ePHI flows, locations, workflows, vendors, owners, and relevant covered-entity or business-associate relationships.
  • Method: how threats, vulnerabilities, likelihood, impact, and risk levels were evaluated.
  • Control evidence: the policies, records, logs, configurations, scan results, or other evidence examined, including any material gaps in evidence.
  • Findings and decisions: affected information and operations, risk rationale, prioritization, and chosen response.
  • Follow-through: action owner, target date, interim mitigation where applicable, completion evidence, and verification or retest results.
  • Change and review history: material changes considered and when the assessment or relevant safeguards were revisited.

These records support decision-making and accountability; a form, framework mapping, or score alone does not demonstrate that safeguards are appropriate or effective.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should hospitals judge assessment tools or outside services?

There is no HHS-endorsed universal EHR security scorecard established in the cited guidance. When comparing a tool, framework, or service proposal, evaluate how well it fits the hospital’s environment and whether it supports a complete risk-based process. The following are practical comparison dimensions, not an official HHS scoring rubric:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • How broadly it traces ePHI across systems, workflows, devices, and locations.
  • Whether it addresses administrative, physical, technical, and relevant privacy controls.
  • How deeply it examines operating evidence and tests controls, rather than relying only on attestations or questionnaires.
  • Whether it accounts for vendor, integration, and other dependencies.
  • Whether findings can be traced through ownership, remediation, and retesting.
  • Whether its methods fit the hospital’s scale, architecture, and operational risks.
  • How it distinguishes legal requirements from voluntary frameworks or implementation guidance.
  • How it is updated as threats, software, and the hospital environment change.

HHS characterizes referenced NIST materials as informational rather than legally binding on covered entities. NIST guidance can inform implementation, but mapping to a framework does not by itself establish HIPAA compliance. HHS describes the ONC/OCR Security Risk Assessment Tool as useful for small and medium-sized practices and business associates; that description does not establish it as a complete hospital assessment product.

How often should the evaluation be repeated?

There is no single calendar interval set by HHS for every hospital. Evaluation should be ongoing: review access records and incidents, assess whether safeguards remain effective, and update them when necessary. Revisit risk after material changes to technology, vendors, business operations, or the threat environment, alongside the hospital’s chosen periodic review schedule.

A schedule is only one part of the process. New connections, software changes, vendor notices, incidents, or changes in how clinicians use the EHR can make a prior assessment incomplete before its next scheduled review.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.