Back to Insights

7 Ways Senior Living Communities Fail a HIPAA Risk Analysis

· Tech for Senior Living

Senior living communities fail a HIPAA risk analysis in seven recurring ways: none exists, it covers only the health record system, it is a generic template, the risks found were never fixed, it was never updated, the work was never documented, and no one owns it.

Each of those is fixable, and none of them requires a bigger budget to start. What they require is knowing which one you have. The risk analysis is the foundation of everything else described in our complete guide to HIPAA compliance for senior living, and it is the first document the HHS Office for Civil Rights (OCR) requests when it opens an investigation. If you are still working out what the analysis is supposed to be in the first place, start with what a HIPAA risk analysis is and why OCR keeps fining for it, then come back here.

The seven below are ordered by how often they turn up, most common first. The seventh is last for a different reason: it is the one that quietly causes the other six.

The Seven Failures, Most Common First

1. There is no risk analysis at all

This is still the most common failure by a wide margin, and it is rarely deliberate. The community assumes someone else handled it: the electronic health record vendor, the IT provider, the corporate office, the consultant who ran the last survey prep. Nobody asks to see the document, so nobody discovers it does not exist.

It is also the finding at the center of OCR's enforcement. The agency launched its Risk Analysis Initiative at the end of 2024 specifically to target this gap, and every action closed under it has turned on the same core problem: a risk analysis that was missing or inadequate. As of early 2026, twelve enforcement actions had been closed under the initiative. The test to run this week is simple. Ask for the document by name and see whether anyone can produce it.

2. It covers the health record system and nothing else

The rule requires an assessment of everywhere electronic protected health information (ePHI) lives, which is resident health data in any digital form. Most analyses stop at the electronic health record because that is the obvious system and the one with a vendor to call.

In a senior living community, resident health data is also sitting in the nurse call system, medication management carts, the fax server, shared workstations at the nurses station, care staff phones and tablets, wander management and door access logs, the copier hard drive, and the email account where a family member sent a care question last Tuesday. An analysis that names one system out of a dozen is not accurate and thorough for your environment, which is the standard the regulation actually sets.

3. It is a vendor template with your community name on it

A generic checklist with the community name typed at the top is one of the easier failures for a reviewer to spot, because the findings do not match the building. It lists risks you do not have and misses the ones you do.

The reference OCR investigators work from is NIST Special Publication 800-66 Revision 2, published in February 2024, which lays out what an implementation of this process is supposed to look like. The practical tell is specificity. A real analysis names your systems, your buildings, your vendors, and your actual configuration. If the document would read identically for a dental practice in another state, it will not hold up.

4. The risks were identified and never fixed

This is the failure mode that has changed most recently, and it catches communities that believe they are in good shape. The analysis was done, it was thorough, it produced a findings list, and then the findings sat there.

OCR has signaled that the Risk Analysis Initiative is expanding from whether an analysis was performed to whether the risks it identified were actually managed and mitigated. That shift matters, because an unremediated finding is documented proof the community knew about a gap and left it open. In April 2026 OCR announced settlements with four regulated entities following separate ransomware investigations, affecting more than 427,000 individuals and totaling over one million dollars, with unaddressed known weaknesses a recurring theme. A findings list with no owners and no dates is now a liability rather than a defense.

5. It was done once and never updated

A risk analysis is meant to be ongoing, not a one-time project with a completion date. The regulation does not name a fixed interval, which is exactly why this one slips: nothing sends a reminder.

Senior living has specific triggers that should force a refresh, and most of them are ordinary business events rather than security events. A new electronic health record. An acquisition or a new building added to the portfolio. A change of IT provider. A new nurse call or medication management system. Any security incident, including one that turned out to be nothing. An analysis completed before you bought the system you now run the building on does not describe your community. Annually, plus after any material change, is the working cadence.

6. The work happened but was never documented

Some communities have genuinely done the thinking. Someone walked the building, listed the systems, thought hard about what could go wrong, and made good decisions. None of it was written down in a form anyone else can read.

For compliance purposes that is indistinguishable from having done nothing, because the analysis is a document, not an activity. What has to exist on paper is the inventory of systems holding resident health data, the threats and vulnerabilities affecting each, an assessment of how likely each is and how bad it would be, the safeguards currently in place, and the remediation plan with owners and dates. Our overview of the HIPAA compliance binder covers where this sits alongside your other required records.

7. No one at the community owns it

Here is the one most communities get wrong, and it is the reason the first six keep recurring. The risk analysis is assigned to "IT," which in practice means it is assigned to a vendor, which means nobody inside the community is accountable for whether it exists, whether it is current, or whether anything on it got fixed.

The obligation cannot be outsourced. A provider can do the assessment work, and a good one will. But the covered entity remains responsible under 45 CFR 164.308(a)(1)(ii)(A), and OCR will ask the community, not the vendor. Name a person. It does not need to be a technical person, and in most communities it should not be. It needs to be someone with the authority to ask for the document, read the findings list, and push for the fixes to get funded.

What a Defensible Analysis Looks Like Instead

A risk analysis that holds up is specific to your buildings, covers every place resident health data actually lives, rates each risk for likelihood and impact, records the safeguards already in place, and carries a remediation plan where each item has a named owner and a date. It gets refreshed on a schedule and after every material change, and one person at the community can put their hand on it without calling a vendor.

The direction of travel is worth planning for. The proposed update to the HIPAA Security Rule, published in December 2024 and the most significant revision in over a decade, would tighten several of these expectations further, including an explicit annual cadence. Communities that build the habit now will not have to scramble later. Our summary of what is changing in the 2026 HIPAA Security Rule update covers the timeline in detail.

If you recognized your community in more than one of the seven, that is normal, and it is a better position than not knowing. The gap that should concern you is not the longest list. It is the one nobody has been assigned to close.

Not sure which of the seven describes your community?

A HIPAA risk analysis scoped to senior living tells you where resident health data actually lives across your buildings, what is exposed, and what to fix first. It is a fixed-scope engagement and you keep the documentation.

Request a HIPAA Risk Analysis