Skip to content

HIPAA risk management vs risk analysis

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · HIPAA

The risk analysis finds the risks to ePHI; risk management does something about them. HIPAA requires both, and skipping the second is a classic finding.

Two distinct steps

HIPAA's Security Management Process requires both a risk analysis and risk management as separate specifications. The analysis is the assessment — identifying risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. Risk management is the follow-through — implementing measures to reduce those risks to a reasonable level.

Where teams stop short

A common failure is doing a risk analysis (often because it is the famous, named requirement) and then not acting on it. An analysis that identifies risks but drives no remediation satisfies neither HIPAA nor common sense — and OCR specifically looks for evidence that risks found were actually managed.

What risk management looks like

For each significant risk the analysis surfaces, decide and implement a treatment — a control, a process change, an accepted risk with justification — with owners and dates. This is the same risk-treatment discipline ISO 27001 formalises, applied to ePHI.

Keep it current

Both steps are ongoing, not one-time — re-run the analysis and update the management actions as systems and threats change. SentinelPanda links ePHI risks to their treatments and controls so analysis and management stay connected and current.

HIPAA security risk analysis How to build a risk register HIPAA administrative safeguards

Run your compliance program in one workspace.