Run a mini risk analysis on a shared drive
Apply core risk analysis steps to an ePHI storage scenario.
A shared drive folder contains thousands of appeal PDFs with ePHI. Access is broad, ownership is unclear, and files are older than the current claims workflow. Scope -> inventory ePHI -> identify threats and vulnerabilities -> rate risk -> choose safeguards -> assign owners The common trap is to call the folder "legacy" and leave it alone because nobody wants to own cleanup. Scope Define the system boundary: the shared drive folder, subfolders, user groups, connected workflows, and types of ePHI stored. Risk analysis starts with scope. If the boundary is vague, the findings become vague. Inventory Sample files and…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in