OCR to Release HIPAA Risk Management Guidance: Questions Requested

The administrative safeguards of the HIPAA Security Rule require HIPAA-regulated entities to conduct a risk analysis to identify risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI), and then reduce any identified risks and vulnerabilities to a reasonable and appropriate level.

The Department of Health and Human Services (HHS) Office for Civil Rights currently has an enforcement initiative targeting noncompliance with the risk analysis provision of the HIPAA Security Rule and has imposed multiple penalties for noncompliance under this initiative. OCR has also identified risk management failures during its investigations of data breaches that have increased the severity of some of the penalties imposed on HIPAA-regulated entities this year.

The HIPAA text is a little vague about exactly what is required in terms of risk management, stating that HIPAA-regulated entities should “Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.” The HIPAA Security Rule is deliberately written in a way to ensure it stands the test of time and remains relevant as technology advances. Specific cybersecurity resources for risk management are not stated in the HIPAA text, as they could easily become outdated, and “reasonable and appropriate” could be interpreted in different ways.

To help clear up any confusion about the HIPAA risk management requirements, Nick Heesters, OCR’s Senior Advisor for Cybersecurity, will explain all in a guidance video. Heesters will cover several risk management topics in the video presentation, including the HIPAA Security Rule risk management requirements; risk management and cybersecurity resources; and OCR investigations that have identified potential risk management violations.

Ahead of recording the presentation, OCR has issued a request for HIPAA-regulated entities to submit questions about risk management. Requests should be submitted via email, and a selection of the questions will be answered in the guidance video. Questions should be submitted no later than December 8, 2025 – [email protected]

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/