0% found this document useful (0 votes)
2 views16 pages

Group Practice Mini Risk Tool Resource

The Mini Risk Tool is designed to assist mental health practices in achieving HIPAA compliance by providing a framework for assessing security and training needs. It highlights the importance of formal risk analysis and mitigation planning, emphasizing the need for comprehensive policies and procedures. The tool offers various resources and support services to optimize practice security and compliance efficiently.

Uploaded by

magdalene
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views16 pages

Group Practice Mini Risk Tool Resource

The Mini Risk Tool is designed to assist mental health practices in achieving HIPAA compliance by providing a framework for assessing security and training needs. It highlights the importance of formal risk analysis and mitigation planning, emphasizing the need for comprehensive policies and procedures. The tool offers various resources and support services to optimize practice security and compliance efficiently.

Uploaded by

magdalene
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

THE

MINI

RISK TOOL
THIS TOOL IS FOR INFORMATIONAL PURPOSES ONLY.
IN ORDER TO MEET HIPAA COMPLIANCE
REQUIREMENTS, THIS TOOL MUST BE PAIRED WITH
THE RISK ANALYSIS SERVICE FROM PERSON
CENTERED TECH.
Training & Security Compliance
Made Effortless For Your Team
Track Staff Training and Security Tasks in Minutes

Start Free Today

Free, fast, and secure.


CLICK OR TAP to get started in just 2 minutes.
No credit card required

Relied on by 1500+ group practices nationwide

Secure logins for every staff


member. No confusion, no
mix-ups.

Automated reminders sent


for you. Stop chasing staff for
training or security task
completion.

One dashboard shows you


exactly who’s on track —
and who isn’t. Clear, real-time training logs
— always audit-ready

Manage & Meet Your Team's Training


Needs With Ease
Optimize your mental health
practice and cover your HIPAA
needs without sacrif icing client
care

It works for you, because we made it for you,


because we are you.

Get Connected
Schedule a call with our team

CLICK OR TAP to schedule a call

[Link]
info@[Link]
YOUR
SECURITY
CIRCLE
CULTIVATING A WALLED GARDEN
OF TRUST, FUNCTIONALITY, AND
COMPLIANCE

Think of this tool as an initial While this mini risk analysis is


“Needs Assessment & a powerful place to begin, it
Treatment Plan” for your doesn’t fulfill the HIPAA
practice’s security and Security Rule’s requirement
compliance foundation. It for a documented “thorough
helps you map what’s inside and accurate” risk assessment.
your “security circle”—the PCT’s consultant-performed
people, systems, and HIPAA Security Risk Analysis &
information you’re responsible Mitigation Planning service
for protecting—and spot what does, and it results in a
may still be outside it. By customized, prioritized action
walking through five key areas plan. If you're ready for deeper
—your tech stack, team clarity and compliance
training, device safeguards, confidence, our focused two-
risk planning, and policies & hour RAMP session offers a
procedures—you’ll gain clarity manageable, high-impact
on what’s solidly in place and next step.
where meaningful action can
strengthen your foundation.

This mini risk analysis is like a gentle check-in for your practice’s security,
compliance, and functionality—designed to help you identify what will most
meaningfully support, optimize, and fortify your practice.
TECH STACK
The tools and programs you use to run your practice.

Outside
Action Required: If you have any filled circles in this section, you need a
formal Risk Analysis and Risk Mitigation Plan

There are unmet functionality needs in either/both client-serving and


internal operations.

Not all third-party services that handle client info (PHI) are a practice
provided and controlled asset (e.g. personal services).

HIPAA Business Associate Agreements are not executed (or


available) between all third-party service providers that handle PHI
and the practice.

Systems containing or handling PHI are not configured to prevent


information being “leaked” or “forgotten.”

Documentation needs being met are reliant on behavior rather than


automated by systems.

Inside
Action Required: If you have any unfilled circles in this section, you need a
formal Risk Analysis and Risk Mitigation Plan

All functionality needs are effectively met (client-serving & internal


operations)

All third-party services that handle client info (PHI) are a practice
asset

HIPAA Business Associate Agreements are executed between all


third-party service providers that handle PHI and the practice

All the practice’s systems are set up so they don’t “leak” or “forget”
information.

Services help maintain documentation automatically (e.g. HIPAA-


secure email, phone, texting.)
TRAINING
See
Recommended
Staff Trainings

Action Required: If you have any


filled circles in this section, you

Outside need a formal Risk Analysis and


Risk Mitigation Plan
CLICK OR TAP for
recommended trainings

All workforce have not been trained on the practice’s P&Ps.

All workforce do not have a foundational knowledge of HIPAA, state laws, and
ethics standards appropriate and necessary to their role within the practice.

Reminders and trainings to ensure the P&Ps are understood and being
followed by everyone (including the leadership team) are not being made.

All workforce are not trained on the P&Ps at least once a year.

All workforce do not have the training and help they need to make sure they
can properly use the equipment and services within the circle.

All workforce do not have the training they need to maintain the circle and
also do their jobs without interruption.

Inside Action Required: If you have any unfilled circles in this section, you need
a formal Risk Analysis and Risk Mitigation Plan

At onboarding, all workforce receive training on the P&Ps and other


registration processes (e.g. remote workspaces and BYOD.) Training on
HIPAA and other laws, as necessary.

All workforce have a foundational knowledge of HIPAA, state laws, and


ethics standards appropriate and necessary to their role within the
practice

Reminders and trainings are continuously provided as needed to ensure


the P&Ps are understood and being followed by everyone (including the
leadership team.)

All workforce are formally trained on the P&Ps at least once/year.

All workforce have the training and help they need to make sure they can
properly use the equipment and services within the circle

All workforce have the training they need to maintain the circle and also
do their jobs without interruption.
DEVICE Get Your Team’s
Devices Secured

SECURITY CLICK OR TAP to learn


more about device
security support

Outside
Action Required: If you have any filled circles in this section, you need a
formal Risk Analysis and Risk Mitigation Plan

All practice-owned data-handling devices have been


“hardened” with necessary technical measures (e.g. full device
encryption, strong and unique encryption passcodes, anti-
virus/anti-malware, firewalls, etc.,)

All workforce members’ personally-owned devices that ever


touch client info have been “hardened” with necessary
technical measures (e.g. full device encryption, strong and
unique encryption passcodes, anti-virus/anti-malware, firewalls,
etc.,)

All practice-owned and personally-owned devices that touch


PHI qualify for Safe Harbor under HIPAA’s Breach Notification
Rule

Hardening of all practice-owned devices is documented

All workforce have been trained on the behavioral security


measures (e.g. never connecting to WiFi that doesn’t meet
trusted network criteria, etc.,) that must be followed for any
devices that ever touch PHI and agreed to abide by them

All workforce member’s personally-owned devices that touch


PHI have been registered and approved as meeting the BYOD
policy requirements for technical security measures and
accompanying behavioral security measures

When any device that has touched practice PHI is no longer


going to be used for practice work, the device is properly
“retired” (e.g. data scrubbed/wiped, factory reset) and
documented as such
Get Your Team’s

DEVICE Devices Secured

SECURITY CLICK OR TAP to learn


more about device
security support

Action Required: If you have any unfilled circles in this section, you need a
Inside formal Risk Analysis and Risk Mitigation Plan

All functionality needs are effectively met (client-serving & internal


operations)

All third-party services that handle client info (PHI) are a practice
asset

HIPAA Business Associate Agreements are executed between all


third-party service providers that handle PHI and the practice

All the practice’s systems are set up so they don’t “leak” or “forget”
information.

Services help maintain documentation automatically (e.g. HIPAA-


secure email, phone, texting.)

HIPAA-Secure Devices, Made Simple


Vulnerability is for your clients. Not your devices.

Person Centered Tech has device


security support for Group Practice
leaders through Practice Care
Premium.

Register and secure all devices —


practice-owned or staff-owned — with
HIPAA-compliant procedures,
simplified management, and peace of
mind
RISK ANALYSIS &
RISK MITIGATION
PLANNING
Outside
Action Required: If you have any filled circles in this section, you need a
formal Risk Analysis and Risk Mitigation Plan

The practice has not conducted and documented an “accurate and


thorough assessment” of the potential threats and vulnerabilities to
the confidentiality, integrity, and availability of electronic protected
health information the practice creates, receives, maintains or
transmits

Threat likelihood and potential threat realization impact have not been
ranked from highest to lowest

The practice has not assessed and documented the security measures
(technical, administrative, physical) used to safeguard e-PHI, whether
security measures required by the Security Rule are already in place,
and if current security measures are configured and used properly

Risks have not been categorized as “addressable” and “required” for


mitigation

“Reasonable and appropriate” safeguards and security measures that


reduce the likelihood of risk to the confidentiality, availability and
integrity of e-PHI have not been identified

A risk mitigation plan for implementing necessary safeguards and


security measures has not been created, followed, and documented

Risk analysis is not updated on an annual and as-needed basis

Security Risk Analysis – without the stress


Schedule your
A technical and practical qualitative assessment led by Risk
a consultant to ensure compliance with HIPAA Assessment
standards for a thorough risk assessment. Today

Protect your clients. Protect your practice.

CLICK or TAP to book yours


RISK ANALYSIS &
RISK MITIGATION
PLANNING
Inside
Action Required: If you have any unfilled circles in this section, you need a
formal Risk Analysis and Risk Mitigation Plan

The practice has conducted and documented an “accurate and thorough


assessment” of the potential threats and vulnerabilities to the
confidentiality, integrity, and availability of electronic protected health
information the practice creates, receives, maintains or transmits

Threat likelihood and potential threat realization impact have been


ranked from highest to lowest

The practice has assessed and documented the security measures


(technical, administrative, physical) used to safeguard e-PHI, whether
security measures required by the Security Rule are already in place, and
if current security measures are configured and used properly

Risks have been categorized as “addressable” and “required” for


mitigation

“Reasonable and appropriate” safeguards and security measures that


reduce the likelihood of risk to the confidentiality, availability and integrity
of e-PHI have been identified

A risk mitigation plan for implementing necessary safeguards and


security measures has been created, followed, and documented

Risk analysis is updated on an annual and as-needed basis

Risk Analysis DONE in 2 hours.


Action plan
Get a consultant-led security risk analysis and risk included — not
mitigation plan – fast, thorough, and HIPAA-compliant. just an
assessment.
Seriously. Book today.
HIPAA
COMPLIANCE
MANUAL
SECURITY POLICIES & PROCEDURES

Outside
Action Required: If you have any filled circles in this section, you need
security policies and procedures

The practice does not have a comprehensive set of formal, written security
compliance policies and procedures which address each standard of the
HIPAA Security Rule and specify how the practice and its workforce meet
each standard

Administrative safeguard policies and procedures do not address: Security


Management Process, Security Personnel, Information Access
Management, Workforce Training and Management, and Evaluation
standards and requirements.

Physical safeguard policies and procedures do not address: Facility Access


and Control, and Workstation and Device Security standards and
requirements.

Technical safeguard policies and procedures do not address: Access


Control, Audit Controls, Integrity Controls, and Transmission Security
standards and requirements.

Written Security P&Ps have not been implemented and followed in-
practice

Get the Policies and Procedures Get Your HIPAA


Your Practice Needs Manual Started
Today
Everything you need to facilitate a strong
security platform that keeps you and your
clients HIPAA safe.
CLICK OR TAP to learn
more about policies and
Get started prodecures
HIPAA
COMPLIANCE
MANUAL
SECURITY POLICIES & PROCEDURES

Inside
Action Required: If you have any unfilled circles in this section, you need
security policies and procedures

The practice has a comprehensive set of formal, written security


compliance policies and procedures which address each standard of the
HIPAA Security Rule and specify how the practice and its workforce meet
each standard

Administrative safeguard policies and procedures address: Security


Management Process, Security Personnel, Information Access
Management, Workforce Training and Management, and Evaluation
standards and requirements.

Physical safeguard policies and procedures address: Facility Access and


Control, and Workstation and Device Security standards and requirements.

Technical safeguard policies and procedures address: Access Control, Audit


Controls, Integrity Controls, and Transmission Security standards and
requirements.

Security P&Ps have been implemented and are followed in-practice

Simplified, Practice-Ready Policies and Procedures

No generic boilerplate — just policies and procedures built for mental health
practices, ready for implementation and peace of mind.

ad for Risk Analysys with lifetime access and consultant performed


Comprehensive Support for Your Group Practice

Practice Care
What you need, no matter where you are.

Practice Care provides the support your group practice needs for
HIPAA compliance, device and workspace security, and ongoing
optimization — all in one service plan.

Whether you’re just starting compliance, getting your devices secure


after a breach, or maintaining policies and procedures, Practice Care
gives you expert guidance and ongoing support.

Premium Device Security

Premium Practice Optimization


Resources
Get The Support
Premium Workspace Security You’re Looking
For Through
Premium Direct Support and Practice Care
Consultation

CLICK OR TAP to learn

Includes
more about Practice Care

Office Hours!

Get started with Practice Care today

Save additional two months free and get 20% off foundational
trainings with annual subscription
Group Practice
Office Hours
Your Questions, Answered —
Live & On-Demand

Weekly live sessions + recordings


Submit questions anytime
Personalized video clips of your answers
Expert-led sessions with specialists

Weekly live sessions and


recordings
Off ice hours were great. I
was really happy with the Personalized video clips
give and take and the to questions you’ve
individual attention. You asked
will def initely be seeing
Expert-led sessions and
me again there.
guest specialists
Abigail McCarrel LCSW, DCSW

Join Group Practice


Office Hours Today
Includes
CLICK OR TAP to learn more about

Office Hours! Practice Care

Included in Practice Care Premium


Compliance Bundle
Investment
All-in-one compliance support, tailored
for group practices.

Purchase
POLICIES AND PROCEDURES the bundle
HIPAA MANUAL and save
$1200 $100
Codify and operationalize Your HIPAA Security Compliance
Program in your Policies & Procedures.

HIPAA SECURITY RISK ANALYSIS AND


MITIGATION PLANNING
$500
2-hour consultant-led risk analysis, with actionable mitigation
plan. Meets federal HIPAA requirements.

ANNUAL GROUP PRACTICE CARE


PREMIUM
$990/yr
Ongoing tools and resources, device security, workspace
security, and direct support-- all in one plan.

trusted and recommended by:


Let’s Get In Touch

Support For Mental Health, By Mental Health


The team of therapists and tech experts at PCT are all here to
help our colleagues in mental health build practices that
leverage tech to provide safe, effective client care.

Liath Dalton
Director & Senior Consultant
Group Program Manager

[Link]
info@[Link]
CLICK OR TAP to book a call with Liath

You might also like