HIPAA Risk Assessment: What LA Practices Should Expect (With Real Findings)

If your practice hasn’t had a HIPAA risk assessment in the last twelve months, you’re not just behind on paperwork — you’re carrying findings you don’t know about. We’ve run these assessments for LA medical groups, dental practices, and an 850-staff hospital, and the same issues surface over and over. Here’s what the process actually involves, and the findings we see most.

What a HIPAA risk assessment actually is

The Security Rule requires covered entities to conduct an “accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information.” In practice, that means someone technical inventories every place ePHI lives — EHR, imaging systems, email, file shares, backups, connected devices — and evaluates the controls protecting each one, then documents the gaps and a remediation plan.

It is not a questionnaire your office manager fills out in an afternoon, and it is not something OCR accepts on good faith after a breach. The first thing investigators request is your most recent risk assessment and evidence you acted on it.

The findings we see most in LA practices

1. Flat networks

Front-desk workstations, guest Wi-Fi, imaging equipment, and the EHR server all on one network segment. One phished receptionist becomes a path to everything. Network segmentation was the single biggest fix in our Beverly Hospital engagement — an 850-staff hospital running un-segmented before the rebuild.

2. Access that outlives employment

Former staff with live EHR or email credentials weeks after departure. No documented offboarding checklist, no access reviews. This is among the most common OCR findings nationally, and the cheapest to fix.

3. Unencrypted devices

Laptops that leave the building without full-disk encryption. A stolen unencrypted laptop is a reportable breach; a stolen encrypted one generally is not. The difference is a checkbox — enforced, verified, and documented.

4. Missing audit logging

The Security Rule expects you to know who accessed what. Many practices have logging technically available in their EHR but never enabled, never reviewed, and never retained.

5. Backups nobody has tested

Ransomware turns “we have backups” into “we think we have backups” at the worst possible moment. Tested, separated, documented restores are both a HIPAA expectation and the thing that determines whether an attack is a bad day or a closure event.

6. No business associate agreements

IT vendors, billing services, transcription, cloud tools — each needs a BAA. We routinely find practices where the IT provider itself never signed one.

What to expect from the process

A proper assessment for a small-to-mid practice takes two to four weeks: discovery and scanning, staff interviews, control review against the Security Rule safeguards, then a findings report ranked by risk with a remediation roadmap. The report is written evidence — date-stamped, methodical, and specific — which is exactly what an auditor, an insurer, or a plaintiff’s attorney will ask to see. Our HIPAA compliance consulting covers the assessment and the remediation, and our HIPAA IT services keep the controls maintained year-round.

Frequently asked questions

How often is a risk assessment required?

HHS guidance expects it to be ongoing, with a formal refresh at least annually and after any material change — new EHR, new location, merger, or a security incident.

Does a small practice really need this?

Yes — enforcement actions regularly hit practices under 25 staff, and the settlements routinely exceed what a decade of proper IT would have cost. Cyber insurance carriers increasingly require the same evidence.

Can our EHR vendor’s compliance attestation cover us?

No. Your EHR being HIPAA-capable says nothing about your network, devices, access controls, staff, or backups. The risk assessment obligation is yours.

Not sure where your practice stands? Book a free 10-minute call — we’ll tell you what an assessment would cover for your environment and what it typically surfaces.