Tuesday, July 28, 2026

Continuous HIPAA Risk Management for Mid-Size and Rural Hospitals: What It Involves and Who Does the Work

Continuous HIPAA risk management means a hospital's Security Risk Analysis stays open all year. In practice it is a standing risk register, remediation items with named owners and due dates, advisor check-ins on the calendar, and a fresh pass at the analysis whenever a new system, site, or vendor changes the risk picture. Small and mid-size hospitals, including rural and critical access facilities, can run this model without an enterprise GRC department. That is the point of it.

What the law requires today

Every hospital that handles electronic protected health information is required, today, to conduct an accurate and thorough assessment of the risks and vulnerabilities to that information. That is the Security Risk Analysis at 45 CFR 164.308(a)(1)(ii)(A), and it is a Required implementation specification, not an addressable one. The 2026 Security Rule update that would tighten several related expectations is still a proposed rule (an NPRM), not final law, so the obligation to know your risks does not wait on it. When OCR investigates a breach, the risk analysis is among the first documents requested, and its date matters: an assessment that predates your current EHR describes a hospital that no longer exists.

What point-in-time looks like, and what continuous looks like

A point-in-time program produces a report with a date on it. Between that date and the next engagement, new servers go live, a clinic gets acquired, a vendor changes subprocessors, and none of it lands anywhere.

A continuous program has furniture:

  • A risk register that stays open, with each risk scored and owned.
  • Remediation tracking: items, owners, due dates, and evidence when they close.
  • A named advisor who already knows your environment, reachable through the year rather than only at assessment time.
  • A trigger habit: new EHR module, new delivery site, new imaging vendor, updated risk analysis.
  • Documentation that accumulates, so next year's assessment starts from this year's instead of from a blank workbook.

None of that requires new headcount. It requires a platform that keeps the register and a person who keeps the cadence.

The part software alone cannot do: 45 CFR 164.310

The Security Rule's physical safeguards cover facility access controls, workstation use and security, and device and media controls. In a hospital those are concrete questions. Who can reach the server closet, and does the badge log show it? Where do workstations on wheels sit when a nurse steps away? How are retired drives and backup media destroyed, and where is the disposal log? What happens to paper charts in the release-of-information room?

Answering those questions requires someone to assess the facility itself. A hospital risk analysis that skips the physical walkthrough is incomplete on its face, because 164.310 is part of the rule being analyzed.

Multi-site hospitals: one engagement, every site

A hospital is rarely one building. There is a main campus, outpatient clinics, rural health clinics, an attached billing office, sometimes a recently acquired practice still on its own systems. Medcurity runs multi-site Security Risk Analyses under a single engagement: every delivery site assessed, one risk register, one remediation queue, one set of documentation an auditor can follow. Compliance officers at multi-site organizations manage it from one dashboard instead of reconciling site-by-site spreadsheets.

Who this fits, and who it does not

Candor is cheaper than a bad-fit engagement, so here is the map. A large integrated delivery network with a multi-state footprint and an in-house GRC team is usually shopping for an enterprise consultancy; Clearwater is the established name in that segment. A solo practitioner can start with the free SRA tool HHS publishes. The middle of the market is where Medcurity works: small and mid-size hospitals, rural and critical access hospitals, FQHCs and community health centers, and clinics that need the work done right without enterprise overhead.

What working with Medcurity looks like

Medcurity has supported 1,000+ organizations since 2018 and holds a 100% OCR acceptance rate. Hospital engagements pair the platform with people: an onsite assessment of the 164.310 physical safeguards, a compliance advisor available through the year rather than only at assessment time, multi-site coverage under a single engagement, and expert review of the finished analysis. The Security Risk Analysis starts at $499 per year and is right-sized from there, so a critical access hospital is not paying for an IDN's tooling.

If your last risk analysis is a PDF with a date on it, talk with the team about what keeping it open year-round would take at your facility count.

"Accurate and Thorough": The Standard Your Risk Analysis Is Judged Against

Two words in the HIPAA Security Rule decide whether a risk analysis holds up: accurate and thorough.

They are easy to skim past. They are also the exact language the Office for Civil Rights (OCR) uses when it reviews an organization after a breach, so it is worth knowing what each one asks of you.

Thorough means it reaches everywhere ePHI lives

A risk analysis is a review of the risks to the electronic protected health information (ePHI) your organization holds. Thorough means it covers all of it, not the systems that were easy to remember.

That reaches wider than most first drafts. It includes the EHR, but also the billing platform, the backups, the laptop a provider takes home, the scanner in the back office, the cloud storage nobody set up on purpose, and every vendor you send patient information to. A review that covers the obvious systems and stops is the most common way a risk analysis fails this half of the test.

Physical space counts too. The HIPAA Security Rule sets physical safeguards as their own category under 45 CFR §164.310: facility access, workstation placement, and how devices and media get reused or disposed of. Those are facts about your building, and the only reliable way to assess them is to look. A questionnaire can record what someone believes about a satellite clinic. It cannot see the propped-open server closet.

Accurate means the risk levels are real

Accurate is the harder half. It means the analysis reflects your environment as it is, and the risk levels you assign are defensible.

The Security Rule expects you to take each threat, weigh how likely it is against how much damage it would do, and set a risk level from that. A finding marked low because low was convenient is not accurate. Accuracy is what separates a real analysis from a form that was filled in to have one on file.

The document is the deliverable

Here is the part that catches people. The work is not the output. The document is.

If your analysis cannot show what was reviewed, what was found, the risk level assigned to each item, and the plan to address it, an auditor treats it as incomplete no matter how much effort went in. Under HIPAA, undocumented work did not happen. The written record is what gets evaluated, so it has to carry the reasoning, not just the conclusions.

How to read your own report

You do not need to be a security specialist to pressure-test your last risk analysis. Three questions do most of the work.

Does it name every place patient data lives, including vendors and physical sites? Does each risk carry a level with a reason behind it, rather than a blanket rating? Could you hand it to an auditor tomorrow and have it stand on its own?

If any answer is no, that is the gap worth closing before anything forces the question.

This is one of the more solvable problems in healthcare compliance. The standard is written down, the scope is knowable, and the result is a document you can defend. At Medcurity we run the Security Risk Analysis against exactly this standard, starting at $499 and right-sized to the organization, with expert review of the findings rather than a self-scored form. If you want a second look at where yours stands, start a conversation with our team.

Wednesday, July 22, 2026

Who Is Responsible When Your Billing Company Is Breached?

Short answer: both of you, in different ways, and your responsibility does not end because the failure happened somewhere else.

This comes up every time a healthcare vendor makes the news. A billing company, a transcription service, or a scheduling platform is compromised, and the practices that used it spend the following week working out what they owe their patients.

Here is how the responsibility divides.

Your vendor's obligations

A vendor handling patient information on your behalf is a business associate. Business associates are directly regulated. They must safeguard the information, and when a breach happens on their side they must notify you without unreasonable delay and no later than 60 days from discovery, under 45 CFR §164.410.

They can face enforcement directly. The Office for Civil Rights has taken action against business associates, not only against the practices that hired them.

Your obligations

Yours do not transfer. Three things remain with you.

Notifying patients. Unless your agreement says otherwise, notifying affected individuals is the covered entity's duty, which means yours. The clock and the content are set by the Breach Notification Rule, and your vendor's notification to you is the starting gun rather than the finish.

Having had an agreement in place. A signed Business Associate Agreement is required before the vendor touches the information. Discovering during a breach that the agreement was never signed, or was signed in 2019 with a company that has since been acquired, is its own finding separate from the breach.

Having assessed the arrangement. Your Security Risk Analysis is supposed to account for the risks of sending patient information outside your walls. A vendor relationship that never appeared in your assessment is a gap that predates the incident.

The part that decides how bad it gets

When OCR reviews a third-party breach, the questions tend to be the same.

  • Was there a current signed agreement with this vendor?
  • Did your risk analysis account for this relationship?
  • What information did the vendor hold, and why did they need that much?
  • How quickly did you notify once they told you?
  • Do you have a record of any of this?

Notice that four of the five are answerable before an incident. The organizations that come through a vendor breach reasonably well are usually the ones that could produce those answers from a file rather than reconstruct them under pressure.

What to do this quarter

Not a project. A short list.

  1. Pull every vendor that touches patient information and confirm a current signed agreement exists for each one. Include the ones you inherited and the ones that changed ownership.
  2. For each, write down what data they receive and why. Anything they do not need is risk you are carrying for no benefit.
  3. Confirm each agreement names a notification timeline and a contact who still works there.
  4. Make sure your Security Risk Analysis reflects this list rather than a version from two years ago.
  5. Decide now who at your organization makes the notification call, so that decision is not being made for the first time on the day it matters.

Step one usually takes longer than people expect, and the reason is worth knowing: agreements tend to live in whoever's filing system signed them, which is rarely one place.

A note on the 2026 rule changes

You may have seen vendors citing new HIPAA Security Rule requirements. The updated Security Rule is a proposal. It has not been finalized, and nothing in it is a requirement today. Some of what it proposes would tighten expectations around vendor oversight, so it is worth watching, but you are not behind on rules that do not yet exist.

What is true today is that risk analysis is already required, and that vendor relationships belong inside it.

If the list is longer than you thought

Most organizations find more vendors than they expected, and the tracking becomes real work somewhere around the point where renewal dates stop fitting in one person's memory.

We build Medcurity for this kind of work, including Security Risk Analysis and Business Associate tracking, with advisors available through the year rather than only at assessment time. The self-serve Security Risk Analysis starts at $499/year for organizations up to 20 staff and scales with organization size. If you want it scoped against your real vendor count, start a conversation with our team.

Whichever way you handle it, do the vendor list before you need it. It is the cheapest hour in compliance and it is the first thing anyone asks for.