Skip to main content
SolarWinds MSP
  • Login
  • Support
      SolarWinds MSP
      • Products
        • Remote Monitoring & Management (Cloud) The RMM platform that grows with you. You can be up and running quickly.

          Key Features

          • Active Discovery
          • Automation and Scripting
          • Backup and Recovery
          • Data-Driven Insights
          • Managed Antivirus
          • Mobile Device Management
          • Patch Management
          • Remote Access
          • Remote Monitoring
          • Reports
          • Risk Intelligence
          • Service Desk
          • Web Protection
          • Mobile Applications
        • SolarWinds Backup Leverage on-site and off-site storage to quickly recover from a disaster.

          Key Features

          • Bare Metal Recovery
          • Continuous recovery
          • Data Archiving
          • Faster Backups and Restores
          • File versioning
          • Global Data Centers
          • Hybrid Cloud Recovery
          • Security-focused storage
          • Software Only
          • Virtual Disaster Recovery
          • Virtual Machine Backups
          • Downloads
        • SolarWinds Mail Assure Robust spam and malware protection, including zero-hour detection.

          Key Features

          • Email Security and Protection
          • Mail Archive
          • Service Infrastructure
          • Mailbox Continuity
          • Office 365 & Exchange Support
        • MSP Manager Manage your IT business effectively with a system that minimizes the overhead.

          Key Features

          • Billing
          • Customer Management
          • Customer Portal
          • Dashboard
          • Mobile Apps
          • Scheduling
          • Ticketing
        • SolarWinds Risk Intelligence Put a financial value on your IT risk profile.

          Key Features

          • PII and PHI Discovery
          • Payment Data Discovery
          • Permissions Discovery
          • Risk Intelligence Reporting
          • Vulnerability Scanning
        • MSP Anywhere Get quick, efficient remote access tools that let you get the job done fast.

          Key Features

          • Behind-the-scenes Support
          • Customizeable branding
          • Environment Management
          • Downloads
      • Solutions

        I'm looking to...

        I'm looking for...

        • Manage my MSP Business More Efficiently
        • Manage my IT Department More Efficiently
        • Layered Security
        • Data-Driven Insights
        • Cross-Platform Support
      • Resources

        Webinars & Events

        Resource Center

        • Ask the N-Central Experts
        • Backup and Recovery Academy
        • Remote Management Academy Foundations
        • Upcoming Events
        • Upcoming Webinars
        • Case Studies
        • eBooks
        • White Papers
      • About
        • Contact
        • Worldwide sales and support
        • Careers
        • Newsroom
          • Press Releases
          • In The News
          • Media Contacts
        • Leadership Team
        • Legal
          • Cookie Policy
          • Privacy Policy
          • SolarWinds MSP UK Software Services Agreement
          • Terms of Use
          • GDPR
          • SolarWinds Security Statement
      • Blog
      • TRY NOW
        • SolarWinds RMM
        • SolarWinds Backup
        • MSP Manager
        • SolarWinds Mail Assure
        • SolarWinds Risk Intelligence
        • MSP Anywhere
      Filter Blogs
      • Filter by:
      • MSP Business
        • Backup & Disaster Recovery
        • Best Practices
        • Business
        • Business Growth
        • Business Risk
        • Cloud Computing
        • Customer Service
        • Cybersecurity
        • Data
        • Internet of Things
        • IT Support
        • ITSM
        • LOGICcards
        • Machine Learning
        • Mail
        • Managed Services
        • Marketing
        • Mobile
        • Networking
        • Operations
        • Product
        • PSA
        • Remote Management
        • Research & Trends
        • Risk Intelligence
        • Security
        • Service Desk
        • Services & Support
        • Tips & Advice
        • Training
      Home Blog MSP Business Why a HIPAA risk assessment is an MSP's best friend
      MSP Business

      Why a HIPAA risk assessment is an MSP's best friend

      By Art Gross
      29 November, 2013

      If you are an MSP and have clients that are required to comply with HIPAA regulations, you should encourage them to perform a HIPAA Risk Assessment. A HIPAA Risk Assessment can drive demand for an MSP's products and services. Let's take a closer look at a HIPAA Risk Assessment and some of the benefits to MSPs.

      HIPAA Risk Assessment is a Core Requirement

      The HIPAA Security Rule requires organizations to protect the confidentiality, integrity and availability of electronic protected health information (ePHI or patient information). Organizations are required to implement effective and appropriate administrative, physical, and technical safeguards to protect patient information. A core requirement of the HIPAA Security Rule specifies that an organization conduct a HIPAA Risk Assessment/Risk Analysis on how it is currently protecting patient information and implement additional safeguards to further protect patient information. According to The Department of Health and Human Services (HHS):

      All ePHI created, received, maintained or transmitted by an organization is subject to the Security Rule. The Security Rule requires entities to evaluate risks and vulnerabilities in their environments and to implement reasonable and appropriate security measures to protect against reasonably anticipated threats or hazards to the security or integrity of ePHI. Risk analysis is the first step in that process.

      Meaningful Use Requirement

      If an organization is going for Meaningful Use incentives, which are incentives up to $44,000 per physician for implementing a certified Electronic Health Records system, they are also required to perform a HIPAA Risk Assessment. In order to receive payments, the risk assessment must be done on an annual basis. According to HHS Health Resources and Services Administration (HRSA):

      To receive the incentive payments, you must also demonstrate that you have met the criteria for the EHR Incentive Program’s privacy and security objective. This objective, “ensure adequate privacy and security protections for personal health information,” is the fifth and final health policy priority of the EHR Incentive Program. The measure for Stage 1 aligns with HIPAA’s administrative safeguard to conduct a security risk assessment and correct any identified deficiencies. In fact, the EHR Incentive Program’s only privacy and security measure for Stage 1 is to:

      Conduct or review a security risk assessment of the certified EHR technology, and correct identified security deficiencies and provide security updates as part of an ongoing risk management process.

      The risk analysis and risk management process must be conducted at least once prior to the beginning of the EHR reporting period. You will need to attest to CMS or your State that you have conducted this analysis and have taken any corrective action that needs to take place in order to eliminate the security deficiency or deficiencies identified in the risk analysis.

      Risk Assessment Output

      The output of a comprehensive HIPAA Risk Assessment includes recommendations that an organization should implement to increase the security of patient information. By performing a HIPAA Risk Assessment, an organization is forced to identify where patient data is stored or transmitted, specify how it is being protected and examine the threats or vulnerabilities to that data. A thorough HIPAA Risk Assessment can identify threats to patient data that could cause security breaches. Implementing the recommendations of a HIPAA Risk Assessment could significantly lower the risk of HIPAA breaches and the potential of penalties for non-compliance with HIPAA regulations.

      Common Findings of a HIPAA Risk Assessment

      Some of the common findings of a HIPAA Risk Assessment include the following:

      • Lack of encrypted offsite data backup
      • Lack of an implemented and tested disaster recovery plan
      • Lack of email encryption
      • Lack of laptop encryption
      • Lack of mobile device management including encryption (smartphones / tablets / USB drives, etc.)
      • Lack of anti-virus on all endpoints and servers
      • Lack of security patching of servers and desktops
      • Lack of security penetration and vulnerability testing
      • Lack of security incident response procedures

      A HIPAA Risk Assessment would determine risks of threats to ePHI and recommend that appropriate security safeguards be implemented to address the above findings and lower the risk to ePHI.

      MSPs Can Help Implement the Risk Assessment Recommendations

      A HIPAA Risk Assessment can help sell many of the services that MSPs offer. Many of the common findings of a HIPAA Risk Assessment can be addressed by products and services available from MSPs. Typical MSPs core functions include data backup, disaster recovery, anti-virus services and security patching of servers and desktops. MSPs can also play a valuable role in helping organizations with implementing encryption services.

      An MSP can also help implement a security incident response plan. An MSP can play a core role in reacting and responding to security incidents including a lost or stolen laptop or smartphone, a hacker breaching an organization’s infrastructure or a virus infiltrating an organization’s network.

      Conclusion

      A HIPAA Risk Assessment is a core requirement under the HIPAA Security Rule. All HIPAA regulated organizations are required to perform on-going Risk Assessments. The recommendations of a HIPAA Risk Assessment can help sell additional MSP products and services. For example, it is a lot easier to state HIPAA requires a disaster recovery plan that is implemented, documented and periodically tested then it is to sell disaster recovery benefits on its own. While a HIPAA Risk Assessment might not replace your trusted dog, it can be an MSP's best friend.

      You might also like...

      MSP Business

      10 Things to Consider When Writing MSP Contracts

      MSP Business

      How will proposed additions to HIPAA provisions affect MSPs?

      MSP Business

      SolarWinds MSP N-central Mobile App Update For Android

      MSP Business

      What's in your toolbox-Essential tools for MSPs and IT technicians

      MSP Business

      Proactive IT management: A practical case study

      MSP Business

      Four tips to uncover a managed services customer's budget

      Recent Posts

      • How to Explain Digital Transformation to Clients
      • Writing MSP Contracts—A Deeper Look, Part 1
      • RMM Essentials—What is it and why do you need one?
      • 5 Must-Have Clauses for your SLAs
      • Release Your Inner IT Superhero, Part 5—Spam Stopper
      • More Results

      Categories:

      • Business Growth (360)
      • Tips & Advice (343)
      • Managed Services (294)
      • Best Practices (253)
      • Cybersecurity (207)
      • Business (205)
      • Security (190)
      • IT Support (99)
      • Backup & Disaster Recovery (87)
      • ITSM (69)
      • Data (68)
      • Cloud Computing (52)
      • Product (39)
      • Mail (37)
      • Marketing (35)
      • Risk Intelligence (32)
      • Customer Service (29)
      • Remote Management (22)
      • Networking (21)
      • Service Desk (16)
      • Services & Support (16)
      • Research & Trends (12)
      • Business Risk (12)
      • Internet of Things (10)
      • PSA (10)
      • Mobile (9)
      • Operations (7)
      • Training (6)
      • LOGICcards (4)
      • Machine Learning (3)
      Show moreless
      SolarWinds MSP

      © 2017 SolarWinds MSP UK Ltd. & SolarWinds MSP Canada ULC.
      All Rights Reserved.

      Products

      • SolarWinds RMM
      • SolarWinds N-central
      • SolarWinds Backup
      • MSP Manager
      • SolarWinds Mail Assure
      • SolarWinds Risk Intelligence
      • MSP Anywhere

      Solutions

      • How We Help MSPs
      • How We Help IT Departments
      • Layered Security
      • Cross-Platform Support
      • Data-Driven Insights

      About

      • About Us
      • Careers
      • Newsroom
      • Leadership Team
      • Upcoming Events
      • Legal

      Support

      • SolarWinds RMM
      • Solarwinds N-central
      • SolarWinds Backup
      • SolarWinds Mail Assure
      • MSP Manager
      • Solarwinds Risk Intelligence
      • MSP Anywhere
      • MSP Mail
      • MSP Anywhere Downloads
      • Backup & Recovery Downloads
      • Sitemap
      • Service Status