HIPAA Security Risk Assessment Process

No black box.
Here’s exactly how the work gets done.

Two of the most requested services at FSL are the HIPAA security risk assessment process and tabletop exercise development. Here is the actual process behind both, step by step, so you know exactly what you’re getting before you ask.

Built by a paramedic and EMS supervisor with 20+ years in emergency healthcare  ·  B.S. Cybersecurity, Cum Laude  ·  SBA Certified SDVOSB

SBA Service-Disabled Veteran-Owned Certified, HIPAA security risk assessment process provider

Process

The HIPAA Security Risk Assessment Process, Step by Step

A real HIPAA security risk assessment process is not a checklist filled out from memory. It is a structured review of how your organization actually handles PHI, mapped against the HIPAA Security Rule’s three safeguard categories.

1

Intake and Scoping

A structured intake form covers your organization type, how PHI is created, received, maintained, and transmitted, what systems are in use (EHR, ePCR, billing, email), and who has access to what. This defines the scope before any review begins.
2

Administrative Safeguards Review

Policies, workforce training records, access management procedures, business associate agreements, and incident response plans are reviewed against what HIPAA actually requires versus what exists on paper.
3

Physical Safeguards Review

Facility access controls, workstation security, device and media controls. For organizations operating outside a fixed facility, this includes how PHI is handled in vehicles, in the field, and on mobile devices.
4

Technical Safeguards Review

Access controls, audit logs, encryption in transit and at rest, and authentication mechanisms across every system in scope. This is where most gaps actually live, and where vague answers get the most scrutiny.
5

Risk Analysis and Prioritization

Every gap identified is rated by likelihood and impact, not just listed. This produces a prioritized list so you know what to fix first instead of a wall of findings with no order to them.
6

Written Deliverable

A finished document covering scope, methodology, findings, risk ratings, and remediation recommendations. Written to be usable, something you can hand to an auditor, a payer, or your own leadership without translation.
No part of the HIPAA security risk assessment process at FSL is automated guesswork. Every finding traces back to something specific you described in intake or something specific reviewed in your systems. If a finding does not have a clear “why,” it does not go in the report.

This process is built around the three safeguard categories defined in the HHS HIPAA Security Rule, not a generic third-party checklist.

Process

How a Tabletop Exercise Actually Gets Built

A tabletop exercise that creates real pressure is engineered, not improvised. Every inject, every discussion prompt, and every objective is built deliberately, not pulled from a generic template.

1

Objective Setting

Before any scenario is written, the specific capability or gap being tested is defined. An exercise without a clear objective tests nothing. This is where most generic tabletop packages fail before they even start.
2

Threat-Informed Scenario Design

The scenario is built around real threat data relevant to your sector, not a generic disaster movie plot. Ransomware exercises reflect actual ransomware behavior. MCI exercises reflect real incident command failures observed in the field.
3

Inject Construction

Each inject is written to create genuine decision pressure with no obviously correct answer. Injects layer urgency and ambiguity deliberately, the way real incidents actually unfold rather than a clean linear timeline.
4

Discussion Prompts and Facilitator Guide

Generic prompts get generic answers. Each prompt is written to push past the first response and force participants to name a specific person, a specific process, or a specific gap, the way a real facilitator should.
5

Hot Wash Structure

The hot wash is built into the package, not an afterthought. Structured prompts capture observations while the room is still in it, before details get lost or softened in retelling.
6

After Action Report and Improvement Plan

Raw observations are translated into documented findings, with an improvement plan that assigns real owners and real deadlines. A finding with no owner is a finding nobody fixes.
This process applies whether you buy a ready-to-run package, request a fully custom exercise, or come through the Train the Trainer program to build this capability yourself. The method does not change. Only who is doing the building changes.

Get Started

Now you know how the HIPAA security risk assessment process works. Let’s start.

No phone calls required. Send a quick email and I’ll respond.

michael@forwardsecuritylabs.com  ·  Direct. No sales team. No handoff.

Forward Security Labs / Forward Career Labs LLC  ·  Wolcott, Connecticut  ·  ForwardSecurityLabs.com  ·  SBA Certified SDVOSB  ·  SAM.gov Registered  ·  CAGE: 1AFL4