SCOTT CHILLE/CYBER PULSE/FIELD GUIDE
HIPAA
Security Risk Analysis
Cyber Pulse · Scott Chille, CISSP
Risk Score
Safeguard Avg
Organization Information45 CFR §164.308(a)(1) — Required annually
ePHI System Inventory

Identify every system, device, application, and location where ePHI is stored, processed, or transmitted. This is the foundation of your risk analysis.

Avg Risk Score
0
Critical Risks
0
High Risks
0
Medium Risks
0
Low Risks
Threat & Vulnerability Assessment Score: Likelihood × Impact = Risk Score
ThreatCategoryLikelihood (1–5)Impact (1–5)Risk ScoreRisk Level
Risk Heat Map
↑ Likelihood→ Impact
Risk Distribution
HIPAA Security Rule Safeguard Assessment R=Required · A=Addressable · Score: 4=Full, 3=Substantial, 2=Partial, 1=Planning, 0=None
Prioritized Risk RegisterAuto-populated from threat assessment — edit as needed
Risk IDRisk DescriptionLevelLIScoreTreatmentOwnerTarget Date
Risk Management & Remediation Plan§164.308(a)(1)(ii)(B) — OCR Evidence Documentation
HIPAA Security Risk Analysis — Executive Summary
Organization · Assessment Period
0
Critical Risks
0
High Risks
Safeguard Score
0
Remediation Actions
NIST CSF Function Coverage (Safeguards)
Safeguard Implementation Status
Overall Risk Assessment Narrative
Certification & Sign-Off