Passing a HIPAA risk assessment vs reducing risk

A healthcare practice completes its annual HIPAA risk assessment. The document gets filed. If an auditor asks for it, the practice can produce it. Ask most practice administrators what “being HIPAA compliant” means day to day, and the answer usually comes back to this: having the assessment on hand.

That’s a real accomplishment. It’s also a different accomplishment than reducing the practice’s actual risk of a breach, and the two get confused constantly because the assessment is the visible, measurable output while risk reduction is neither.

What a risk assessment actually certifies

A HIPAA risk assessment is a structured exercise: identify where protected health information lives, evaluate the threats and vulnerabilities around it, and document the findings. Done properly, it’s genuinely useful work. It surfaces problems a practice might not otherwise notice.

What it does not do, on its own, is fix any of those problems.

The assessment is a snapshot of what’s wrong, not a record of what got repaired. A completed assessment with fifteen identified findings and a completed assessment with zero look identical in the one place most practices actually check: whether the document exists and is current. Nothing in the completion of the assessment itself distinguishes a practice that closed out its findings from one that filed them and moved on.

Why the gap between the two rarely gets noticed

This distinction stays invisible because of how compliance gets tracked. An assessment is a single deliverable with a clear finish line: it’s done, or it isn’t. Remediation is different. It’s ongoing, distributed across whoever’s responsible for each individual finding, and never has one obvious completion point the way the assessment itself does.

That difference in shape changes what gets managed.

  • A practice can put “completed HIPAA risk assessment” in a compliance calendar with a due date and check it off.
  • A practice cannot put “reduced our overall risk exposure” on the same calendar, because there’s no single event that finishes it.

The assessment gets tracked because it’s trackable. Remediation, the actual work that changes the practice’s exposure, gets managed informally if at all, because nothing forces it into a calendar the same way.

This is well documented in HIPAA enforcement patterns: when the Department of Health and Human Services investigates a breach, one of the most commonly cited failures isn’t the absence of a risk assessment. It’s the presence of one that identified a risk the organization never actually addressed. The assessment existed. The finding sat there, documented and unresolved, until it turned into an actual incident.

What this looks like inside a small practice specifically

The gap is worse in smaller practices than the compliance literature usually accounts for, because the person completing the risk assessment and the person responsible for fixing what it finds are often the same overloaded staff member, or nobody in particular.

A fifteen-provider practice typically doesn’t have a dedicated compliance officer with the authority and bandwidth to chase down every finding across every department. It has an office manager or practice administrator handling compliance alongside scheduling, billing questions, and staff management. When the risk assessment turns up a finding, patch management on an aging server, an access control gap in the EHR, a vendor missing a signed business associate agreement, that finding competes for the same person’s attention as everything else on their desk that week.

Findings that require a purchase, a vendor conversation, or a system change tend to lose that competition. They’re not urgent in the way a scheduling conflict or a billing dispute is urgent. So they wait. And because nothing in the compliance calendar tracks “did this finding actually get closed,” waiting doesn’t show up as a failure anywhere until something goes wrong.

What closing the gap actually requires

Fixing this isn’t about running risk assessments more often. Running the same exercise on a tighter schedule just produces more documented findings sitting in the same unmanaged state.

What it requires is treating remediation as a tracked deliverable with the same discipline currently applied to the assessment itself:

  • Each finding gets an owner, a target date, and a status that’s checked, not just filed
  • Findings that can’t be closed immediately get a documented interim mitigation, not just a note that they exist
  • Someone reviews outstanding findings on a defined cycle, separate from when the next annual assessment is due

This is exactly where practices without an internal compliance function benefit from managed IT services for healthcare that treat remediation tracking as part of the service, not an assumed byproduct of having done the assessment. The distinction matters because a lot of what gets marketed as HIPAA compliance support stops at the assessment. Whether a vendor’s involvement continues into actually closing findings, or ends at handing over the report, is the difference that determines whether the practice’s real exposure changes.

The paperwork was never the point

A completed risk assessment is necessary. It’s also not sufficient, and treating it as sufficient is exactly what the paperwork encourages, because the paperwork rewards the deliverable it can measure. A practice that wants to know whether it’s actually safer than it was a year ago won’t find that answer in whether the assessment got filed on time. It’ll find it in how many of last year’s findings are still open.

Leave a Comment