Skip to content

Security Risk Analysis

share

Measure description

Conduct or review a security risk analysis in accordance with the requirements in 45 CFR 164.308(a)(1), including addressing the security (to include encryption) of ePHI data created or maintained by certified electronic health record technology (CEHRT) in accordance with requirements in 45 CFR 164.312(a)(2)(iv) and 45 CFR 164.306(d)(3), implement security updates as necessary, and correct identified security deficiencies as part of the MIPS eligible clinician’s risk management process.

 ObjectiveMeasureMaximum points
 Protect Patient Health InformationSecurity Risk Analysis0*

*This is a required measure for 2023 for the Promoting Interoperability performance category and must be answered in the affirmative for PI to be successfully reported.

Reporting requirements

To meet this measure, MIPS eligible clinicians must attest Yes to conducting or reviewing a security risk analysis and implementing security updates as necessary and correcting identified security deficiencies.

Definition of terms and additional information

N/A