CYBER DENTAL 2.0
(954) 639-7049

Risk analysis vs risk management for dental IT

One document finds the holes. The other is what you actually did about them. OCR asks for both. A score is neither.

Journal · Legal, Plain English · F·07 | Last reviewed: October 1, 2026 | 3 min read | By CyberDental Group LLC, Hialeah, Florida

Short answer: A HIPAA risk analysis identifies where ePHI lives, what threatens it and how likely and severe each risk is. Risk management is the documented plan and evidence of what you did to reduce those risks. The Security Rule requires both; OCR routinely asks for both. A compliance score, a vulnerability scan or a policy binder is neither.

At a glance

Risk analysis Accurate and thorough assessment of risks to ePHI (45 CFR 164.308(a)(1)(ii)(A))
Risk management Security measures sufficient to reduce risks to a reasonable and appropriate level (164.308(a)(1)(ii)(B))
Update When environment changes and on a regular schedule; at least annually is common
Evidence Inventory, findings, risk ratings, remediation plan with owners and dates, proof of completion
Not a substitute Compliance scores, scans, policy templates

General information, not legal advice.

What is a HIPAA risk analysis?

A risk analysis is the foundational Security Rule requirement: an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of ePHI. In practice it answers five questions in writing:

  1. Where is ePHI? Servers, workstations, sensor PCs, laptops, phones, email, cloud systems, backups, paper-to-digital intake, vendors.
  2. What threatens it? Ransomware, phishing, lost devices, insider error, power or storm events, vendor failure.
  3. What vulnerabilities exist? Unsupported systems, missing MFA, flat network, untested backups, shared passwords.
  4. How likely and how severe is each risk?
  5. What is the resulting risk level for each?

HHS and NIST publish guidance on how to do this, including the approach in NIST SP 800-66.

What is risk management?

Risk management is what you do with the findings. The Security Rule requires implementing security measures sufficient to reduce risks to a reasonable and appropriate level. It is a living plan:

  • A prioritized remediation list from the risk analysis.
  • Owners and dates for each item.
  • Evidence of completion: MFA enforcement logs, patch records, backup test results, training attendance, signed BAAs.
  • Accepted risks, each with a documented rationale.
  • Review cycles to confirm the risk actually went down.

What is the difference, in one sentence?

The risk analysis finds the holes; risk management is the record of how you closed them, or why you chose not to.

Why does OCR care so much?

Failure to conduct an accurate and thorough risk analysis is among the most frequently cited issues in OCR investigations and settlements, and OCR announced a dedicated risk analysis enforcement initiative in late 2024. Practically, an investigator will ask for the analysis, the plan and the evidence. A practice that can produce all three is in a markedly better position than one that cannot. See HIPAA penalties in plain English.

What does a dental example look like?

Finding (risk analysis) Risk Action (risk management) Evidence
Server on an unsupported OS High Migrate by a set date Migration ticket and new OS inventory
No MFA on email High Enforce MFA for all users MFA enforcement report
Backups never restore-tested High Quarterly restore test Dated test records
Guest Wi-Fi shares clinical network High Segment with VLANs Network diagram, firewall rules
Staff untrained on phishing Medium Annual and onboarding training Attendance records

What is not a risk analysis?

  • A compliance score or checklist. See The free compliance score.
  • A vulnerability scan alone: it finds technical weaknesses but does not assess the whole environment, people and process.
  • A policy template with no connection to your actual systems.
  • An old analysis that no longer matches the practice.

How often should they be updated?

Regularly, and whenever something significant changes: a new office, a new PMS, a cloud migration, a breach or a new major vendor. Annual review is a common baseline. See NPP 2026 vs the Security Rule NPRM for how the pending rule would formalize some of this.

Who does the work?

The practice is responsible, and an MSP or compliance partner can lead the technical assessment and produce evidence. On CyberDental's Ultimate plan, HIPAA compliance management supports this work. See Remote, Priority, Ultimate, Concierge.

Frequently asked questions

What is the difference between a HIPAA risk analysis and risk management?

A risk analysis identifies and rates risks to ePHI. Risk management is the documented plan and evidence of the measures taken to reduce those risks to a reasonable level.

How often should a dental practice update its HIPAA risk analysis?

Regularly and whenever the environment changes materially, such as new systems, offices or vendors. Annual review is a common baseline.

Does a vulnerability scan satisfy the HIPAA risk analysis requirement?

No. A scan identifies technical weaknesses but does not assess ePHI locations, threats, people and processes across the whole environment.

Sources and further reading

Related in the Journal

About CyberDental

CyberDental Group LLC is a dental-exclusive managed IT and cybersecurity provider headquartered in Hialeah, Florida. Founded in 2016 by Mr. Dimitri Lopez, it supports 1,000+ licensed dental practices, has completed 250+ dental office IT build-outs, and operates a dental-only HelpDesk. Plans are priced per location: Remote $350/month, Priority $650/month, Ultimate $1,200/month; Concierge is quoted for multi-location groups and DSOs. CyberDental signs a Business Associate Agreement (BAA) with every practice it serves.

CALL TEXT