HIPAA risk management vs risk analysis
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · HIPAA
The risk analysis finds the risks to ePHI; risk management does something about them. HIPAA requires both, and skipping the second is a classic finding.
Two distinct steps
HIPAA's Security Management Process requires both a risk analysis and risk management as separate specifications. The analysis is the assessment — identifying risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. Risk management is the follow-through — implementing measures to reduce those risks to a reasonable level.
Where teams stop short
A common failure is doing a risk analysis (often because it is the famous, named requirement) and then not acting on it. An analysis that identifies risks but drives no remediation satisfies neither HIPAA nor common sense — and OCR specifically looks for evidence that risks found were actually managed.
What risk management looks like
For each significant risk the analysis surfaces, decide and implement a treatment — a control, a process change, an accepted risk with justification — with owners and dates. This is the same risk-treatment discipline ISO 27001 formalises, applied to ePHI.
Keep it current
Both steps are ongoing, not one-time — re-run the analysis and update the management actions as systems and threats change. SentinelPanda links ePHI risks to their treatments and controls so analysis and management stay connected and current.