HIPAA programs fail in a predictable place: not the safeguards themselves but the risk analysis that was supposed to choose them. OCR’s settlement history reads like the same finding copied forward, no enterprise-wide risk analysis, or one so stale it predates the systems it should cover, which is why a roadmap that starts anywhere else is decorative. Build the inventory, run the analysis, remediate on a dated plan, and let the paper, training, and breach machinery hang off that spine.
| Step | Deliverable | Rule cite |
|---|---|---|
| 1. Scope | CE/BA determination, PHI system inventory | 160.103 |
| 2. Analyze | Enterprise-wide security risk analysis | 164.308(a)(1) |
| 3. Remediate | Risk management plan with milestones | 164.308(a)(1) |
| 4. Paper | Policies, BAAs, notice of privacy practices | 164.502-530 |
| 5. Train | Workforce training + sanctions, documented | 164.308(a)(5) |
| 6. Drill | Incident response + breach runbook | 164.308(a)(6), 164.400s |
Executing the roadmap
Let the risk analysis drive spending. Encryption, MFA, and logging investments justified by your own analysis are defensible; controls chosen by vendor pitch are not. The risk assessment guide covers methodology.
Close the BAA loop before data flows. Every vendor touching PHI needs an executed agreement first; the BAA guide covers required terms and the subcontractor chain.
Operationalize minimum necessary and access rights. The minimum necessary guide and OCR’s right-of-access initiative define the two Privacy Rule areas with active enforcement.
Pre-build the breach file. The four-factor assessment template, notification letters, and the breach playbook should exist before the incident; OCR’s enforcement trends show what happens otherwise.
Web properties leak PHI through trackers more often than teams expect, OCR has warned on exactly this: check your public pages with a free scan.