Built by a paramedic and EMS supervisor with 20+ years in emergency healthcare · B.S. Cybersecurity, Cum Laude · SBA Certified SDVOSB
Process
The HIPAA Security Risk Assessment Process, Step by Step
A real HIPAA security risk assessment process is not a checklist filled out from memory. It is a structured review of how your organization actually handles PHI, mapped against the HIPAA Security Rule’s three safeguard categories.
Intake and Scoping
Administrative Safeguards Review
Physical Safeguards Review
Technical Safeguards Review
Risk Analysis and Prioritization
Written Deliverable
This process is built around the three safeguard categories defined in the HHS HIPAA Security Rule, not a generic third-party checklist.
Process
How a Tabletop Exercise Actually Gets Built
A tabletop exercise that creates real pressure is engineered, not improvised. Every inject, every discussion prompt, and every objective is built deliberately, not pulled from a generic template.
Objective Setting
Threat-Informed Scenario Design
Inject Construction
Discussion Prompts and Facilitator Guide
Hot Wash Structure
After Action Report and Improvement Plan
Get Started
Now you know how the HIPAA security risk assessment process works. Let’s start.
No phone calls required. Send a quick email and I’ll respond.
michael@forwardsecuritylabs.com · Direct. No sales team. No handoff.
