What a security risk assessment actually is

A security risk assessment answers three plain questions in writing: where does our sensitive information live, what could go wrong with it, and how well do our current safeguards reduce that risk? It is not a scan you buy and forget, and it is not a stamp. It is an organized look at your data, systems, people, and vendors that ends in findings your leadership can examine and act on.

It is the foundation because every other decision depends on it. You cannot right-size training, choose safeguards, write honest policies, or answer an insurer’s application accurately until you know what you actually hold and where it is exposed. Boards sometimes want to skip to buying a tool. The assessment is what tells you which tool, if any, is the right one.

The output that matters is a short, honest record: what you found, what it means, what you will do about it, and who owns each item. That record is what an insurer, an accreditor, or a board member can read months later — and it is worth far more than any “certified” badge, because no United States government agency certifies security or HIPAA compliance in the first place.

Why the volunteer-scale model raises specific risks

Running a clinic on volunteers and a small core staff is not a weakness — it is a mission-centered model, and it is how much of this work gets done at all. But it does concentrate a few specific risks worth naming plainly, so you can assess them rather than worry about them:

  • Access churn. Volunteers and interns arrive and leave more often than employees. Every departure that does not end in a removed login leaves an open door into email, scheduling, or records.
  • Training gaps. A rotating team means the person answering the phone or opening an attachment this month may not have had security training yet. Attackers target exactly that gap with phishing.
  • Shared devices and accounts. A front-desk computer or a shared inbox used by several people makes it hard to know who did what — and one weak password protects everyone at once.

None of these means the volunteer model is unsafe. They mean the assessment should be sized to how your clinic really runs, so the findings match your day rather than a hospital’s.

The security risk assessment checklist

Work through these in order. For each, the note describes what good looks like so you can mark honestly where you stand. You do not need to fix everything at once — you need to see and record everything first.

  1. Asset & data inventory. What good looks like: a single written list of every place client or health information lives — the records system, email, forms, scheduling, spreadsheets, paper files, phones, and cloud storage. You cannot protect what you have not listed.
  2. Who-has-access review. What good looks like: a current roster of every person with a login to each system, matched against who still volunteers or works there. Every former volunteer’s access is removed, and access matches role.
  3. Multi-factor authentication on email, EHR, and remote access. What good looks like: MFA turned on everywhere it is offered, especially email and the records system. This is one of the highest-value, lowest-cost safeguards available.
  4. Automatic and tested backups. What good looks like: backups that run on their own, are kept separate from the main system, and have been restored at least once to prove they work. A backup you have never tested is a hope, not a safeguard.
  5. Annual staff and volunteer training. What good looks like: everyone who touches email, scheduling, or records completes short security and phishing-awareness training when they start and once a year, with a record of who completed it.
  6. Vendor list and written agreements. What good looks like: a list of every outside tool or service that processes client or health information, with a written agreement in place for each. Free tools still handle real data.
  7. Physical safeguards. What good looks like: paper records in locked storage, screens not visible from the waiting area, devices that lock when idle, and a clean-desk habit at the front desk.
  8. A tested one-page incident response plan. What good looks like: a single page naming who to call, what to do first, and how to reach counsel and your insurer if data is lost or exposed — and at least one walk-through so it is not read for the first time during a crisis.
  9. Written policies that match practice. What good looks like: short policies describing what you actually do, not a binder copied from a hospital. A policy you do not follow is worse than none, because it documents a gap.
  10. A public claims-language review. What good looks like: your website, intake forms, and marketing checked so that every privacy promise matches reality. No page says “HIPAA compliant” or “HIPAA certified” unless it is accurate; safer language describes a privacy and security program aligned to HIPAA standards.
  11. A named owner. What good looks like: one person accountable for keeping this checklist current and reporting to the board on a schedule. Shared ownership becomes no ownership.

Two companion checklists go deeper on the pieces boards ask about most: the questions a board should be asking in board cybersecurity questions, and how to evaluate the tools you rely on in the vendor risk checklist.

How to read your results and what to prioritize

Once you have marked each item honestly, you will have a picture rather than a grade. The point is not to be perfect — it is to know your exposure and decide, in order, what to address. A few items reduce the most risk per dollar for an organization at your scale:

  1. Regulatory clarity. Establishing in writing which rules actually apply to you — and matching your public language to that answer — removes the risk that lives in a mismatch between claim and practice. We cover this in does HIPAA apply to your pregnancy help organization.
  2. MFA everywhere it is offered. The single most cost-effective barrier against the account takeovers that begin most breaches.
  3. Tested backups. The difference between a bad week and a closed clinic when ransomware or a failed drive hits.
  4. A tested incident plan. Knowing the first three calls to make turns panic into a process, and reduces both the harm and the cost of an incident.

Everything else on the checklist still matters, but these four carry the most protection for the least spend. Fix them first, record what you did, and bring the rest to your board on a schedule.

The honest limit of self-assessment

A checklist you run yourself is a genuine and valuable start — it produces the documented findings that make every later conversation easier. But it has a real limit worth stating plainly. The people who will judge your program — cyber-insurers reviewing an application, accreditors examining evidence, surveyors, and, if something goes wrong, a state attorney general — think in exactly these terms, and they weigh independent review more heavily than self-certification.

That is not a reason to skip the checklist. It is the reason to run it, and then to have the findings reviewed by someone outside your own team. Independent eyes catch the gap you have stopped seeing, and a signed, independent deliverable carries weight a self-graded worksheet cannot. Clinical Risk Monitor exists for organizations that need this standing function without staffing it full-time: industry-standard tooling and an AI analysis layer accelerate the work, and a named compliance expert reviews the evidence and signs the deliverable. The AI drafts; it never signs. We are not a certification body, and we do not certify compliance with any law — we help you run a verified program your board, insurer, and accreditor can examine.

Questions boards ask next