Skip to content

HIPAA Risk Assessment

Requirement: HIPAA Security Rule §164.308(a)(1)(ii)(A) — Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) held by the covered entity or business associate.

Owner: Rory (Security Officer) Review frequency: Annual (December) + any material change to environment or threat landscape Last reviewed: May 2026 Next review: December 2026

This assessment satisfies §164.308(a)(1)(ii)(A). It is intended to be read alongside the Threat Model, which provides STRIDE analysis and kill chain coverage detail. The threat model is the engineering reference; this document is the compliance-formatted risk register auditors expect.


Scope

ePHI Systems in Scope

SystemLocationePHI RoleTenant
DDE AVD environment + published appAzure DDE (ciriusdde.com)Primary PHI access plane — Medicare patients access clinical data hereDDE
DDE session hosts (7 AVD hosts)Azure DDE, Billings subscriptionProcess ePHI during patient sessionsDDE
DDE Active Directory (ACTDIRAZC01, ACTDIRAZC02)Azure DDE, Firewall subscriptionIdentity authority for all DDE access — compromise enables PHI accessDDE
Azure PROD domain controllers (ACTDIRAZP01, ACTDIRAZP02)Azure PRODIdentity for internal staff accessing PHI-adjacent systemsPROD
Veeam backup store (AWS S3, Backup account)AWS (863609217450)Contains backup images of PHI systemsAWS
Azure Recovery Services VaultsAzure PROD + DDEBackup copies of PHI-bearing VMsPROD + DDE
cirius-openai-kv-prod (Key Vault)Azure PROD (logging subscription)Holds secrets for SecOps platform and AI inference — SecOps processes security events that may contain PHI fragmentsPROD
psql-secops-prod (PostgreSQL)Azure PROD (logging subscription)SecOps incident database — incidents may reference PHI system identifiersPROD
M365 (Exchange Online, SharePoint, Teams)Microsoft tenantStaff communication may reference ePHISaaS
Log Analytics — cirius-logging-law-centralAzure PROD (logging subscription)Security logs include system event data from PHI systemsPROD

Risk Scoring Methodology

Each risk is scored on two axes:

  • Likelihood (1–5): How probable is this threat given current controls and threat landscape?

    • 1 = Rare (once in 10+ years)
    • 2 = Unlikely (once in 5–10 years)
    • 3 = Possible (once in 2–5 years)
    • 4 = Likely (once in 1–2 years)
    • 5 = Almost certain (within the next year)
  • Impact (1–5): What is the harm if this threat materializes?

    • 1 = Negligible (no PHI affected, minor disruption)
    • 2 = Minor (limited PHI exposure, brief disruption)
    • 3 = Moderate (significant PHI exposure, reportable incident)
    • 4 = Significant (large PHI breach, HHS notification, major disruption)
    • 5 = Catastrophic (mass PHI breach, business-threatening, regulatory penalties)

Risk Score = Likelihood × Impact (1–25)

ScoreLevelResponse
1–5LowAccept, monitor annually
6–9MediumTreat within 12 months
10–15HighTreat within 6 months
16–25CriticalTreat immediately

Risk Register

R-001 — Ransomware Attack (RaaS affiliate)

FieldValue
ThreatRansomware-as-a-Service affiliate using credential spray → lateral movement → backup destruction → encryption
Asset affectedAll PHI systems, identity systems, backup targets
VulnerabilityDetective control gaps at kill chain stages 2–7 (execution, persistence, credential dump, lateral movement, exfiltration, defense evasion)
Likelihood (inherent)5 — Active attacks against healthcare SMBs; Cirius experienced an incident November 2024
Impact5 — Full PHI breach, HHS notification, potential business failure
Inherent risk score25 — Critical
Current controlsConditional Access + MFA, Twingate ZTNA, Palo Alto + DNS Security, Cortex XDR, Arctic Wolf MDR (act-first), immutable backups (Object Lock), Keeper MFA on all credentials
Likelihood (residual)3 — Controls significantly reduce probability but gaps remain
Impact (residual)3 — Immutable backups contain blast radius; DR failover limits downtime
Residual risk score9 — Medium
Remediation in progressKill chain Phase 1 (audit policy enabling EventID 4688, 4698) and Phase 2 (6 detection agents) — target completion before September 2026 audit
Risk ownerRory

R-002 — Credential Compromise / Account Takeover

FieldValue
ThreatPhishing, credential spray, or password reuse compromising a staff account with PHI access
Asset affectedDDE AVD environment, M365, domain controllers
VulnerabilityActive phishing campaign observed against Cirius identities (justinc, gregd, adrianam, paulb, sophien, lauramaeb). MFA conditional access partially in report-only mode.
Likelihood (inherent)5 — Active campaign confirmed
Impact4 — PHI access via compromised account; depends on account privilege
Inherent risk score20 — Critical
Current controlsEntra MFA enforced, Conditional Access policies, Twingate device posture, Arctic Wolf behavioral monitoring, Maester weekly M365 audit
Likelihood (residual)3 — MFA significantly reduces success rate
Impact (residual)3 — Twingate posture and Cortex XDR limit lateral movement post-compromise
Residual risk score9 — Medium
Remediation in progressConditional Access policies transitioning from report-only to enforce; FIDO2 hardware distribution for privileged accounts
Risk ownerRory

R-003 — Insider Threat (Unauthorized PHI Access)

FieldValue
ThreatAuthorized employee accesses PHI beyond scope of their role, or exfiltrates PHI
Asset affectedDDE AVD environment, M365 (SharePoint, Teams)
VulnerabilityLimited Data Loss Prevention enforcement (Purview DLP in report-only for most policies)
Likelihood (inherent)2 — Small workforce, relatively small attack surface
Impact4 — Intentional PHI breach triggers HHS notification
Inherent risk score8 — Medium
Current controlsPurview DLP (report-only transitioning to enforce), Arctic Wolf monitoring, audit logging, Conditional Access session controls, role-based access
Likelihood (residual)2 — Controls reduce opportunity but not intent
Impact (residual)3 — DLP and logging provide detection and containment
Residual risk score6 — Medium
Remediation in progressPurview DLP enforce mode rollout per compliance/purview-dlp-enforce-mode-criteria.md
Risk ownerRory

R-004 — Third-Party / Supply Chain Compromise

FieldValue
ThreatCompromise of a vendor with PHI access (Microsoft, AWS, Arctic Wolf, Palo Alto) or of a GitHub Actions dependency
Asset affectedAll PHI systems (for vendor compromise); CI/CD pipeline (for supply chain)
VulnerabilityDependency on third-party SaaS with PHI access; GitHub Actions dependencies
Likelihood (inherent)3 — Major cloud vendors are high-value targets
Impact4 — Vendor breach with PHI access is a reportable event
Inherent risk score12 — High
Current controlsBAAs in place for all PHI vendors; GitHub Actions SHA-pinned; supply_chain_agent monitors for un-pinned actions; vendor risk assessments (compliance/vendor-risk-inventory.md)
Likelihood (residual)2 — Vendor security programs and contractual obligations reduce probability
Impact (residual)3 — BAAs define breach notification obligations; SHA pinning limits CI/CD blast radius
Residual risk score6 — Medium
Remediation in progressOngoing SHA-pin enforcement via supply_chain_agent
Risk ownerRory

R-005 — Infrastructure Failure / Availability Loss

FieldValue
ThreatAzure region failure, accidental infrastructure destruction, or extended outage affecting PHI system availability
Asset affectedDDE AVD (Medicare patient access), all Azure PROD systems
VulnerabilitySingle Azure region (US West 2); DR failover not yet exercised for current architecture
Likelihood (inherent)2 — Azure region failures are rare but not impossible
Impact3 — PHI unavailability triggers HIPAA contingency plan requirements; DDE downtime affects Medicare patients
Inherent risk score6 — Medium
Current controlsVeeam DR replication (nightly) to AWS, Recovery Services Vaults with immutability, DR failover procedure documented, AWS DR environment maintained
Likelihood (residual)2 — DR capability reduces impact of any failure
Impact (residual)2 — RPO ~24h, RTO 4–8h for full DR failover
Residual risk score4 — Low
Remediation in progressQ2 2026 DR test (June) — first live validation of current architecture
Risk ownerRory

R-006 — Backup Destruction (Ransomware Pre-cursor)

FieldValue
ThreatRansomware actor destroys backups before encrypting primary systems, eliminating recovery path
Asset affectedAzure Recovery Services Vaults, Veeam AWS S3 store
VulnerabilityRSV soft delete provides 14-day protection but does not prevent a determined attacker with Azure admin credentials from initiating deletion
Likelihood (inherent)3 — Standard ransomware playbook; observed in November 2024 incident
Impact5 — Recovery becomes impossible without backups
Inherent risk score15 — High
Current controlsRSV soft delete (14 days) + immutability (Unlocked) on all active vaults; AWS S3 Object Lock (GOVERNANCE, 6-year); Veeam backups in separate AWS org account; break-glass accounts never in suppression rules; backup agent monitors vault health
Likelihood (residual)2 — Object Lock and S3 immutability prevent deletion even by admin accounts
Impact (residual)2 — Immutable copies survive even a full Azure compromise
Residual risk score4 — Low
Remediation in progressEvaluate escalating RSV immutability from Unlocked to Locked for highest-criticality vaults
Risk ownerRory

R-007 — Unpatched Vulnerability Exploitation

FieldValue
ThreatExploitation of an unpatched vulnerability in a public-facing or internally accessible system
Asset affectedAll internet-exposed endpoints, Windows VMs
VulnerabilityPatch lag between release and deployment; 9 public-facing endpoints in monthly scan scope
Likelihood (inherent)3 — Vulnerability exploitation is common against healthcare targets
Impact3 — Depends on the system; PHI exposure possible if DDE or identity systems affected
Inherent risk score9 — Medium
Current controlsMonthly Nuclei + Nmap pen testing, Cortex XDR behavioral prevention, Intune patch compliance enforcement, patch management policy (security/patch-management.md), vulnerability notification system (Lambda/SES)
Likelihood (residual)2 — Monthly scanning and enforcement reduce window
Impact (residual)2 — Cortex XDR behavioral detection catches exploitation even for unpatchable
Residual risk score4 — Low
Remediation in progressKill chain execution agent will detect post-exploitation activity
Risk ownerRory

Aggregate Risk Summary

Risk IDDescriptionResidual ScoreLevel
R-001Ransomware attack9Medium
R-002Credential compromise9Medium
R-003Insider threat6Medium
R-004Supply chain / vendor6Medium
R-005Infrastructure failure4Low
R-006Backup destruction4Low
R-007Unpatched vulnerability4Low

Overall posture: MEDIUM — No Critical or High residual risks. All residuals are Medium or Low with active remediation on the two Medium items (kill chain completion, CA enforce mode).

Target posture after September 2026: LOW-MEDIUM across all risks, with kill chain Phase 2 and full CA enforce mode reducing R-001 and R-002 residual scores.


Risk Treatment Plan

Risk IDTreatmentTarget DateOwner
R-001Kill chain Phase 1 (audit policy) + Phase 2 (6 agents)July 2026Rory
R-002Conditional Access enforce mode + FIDO2 for privileged usersJuly 2026Rory
R-003Purview DLP enforce mode rolloutQ3 2026Rory
R-004Continue SHA-pin enforcement; annual vendor reviewsOngoingRory
R-005Q2 2026 DR test to validate current architectureJune 2026Rory
R-006Evaluate RSV Locked immutability for critical vaultsQ3 2026Rory
R-007Kill chain execution agent for post-exploit detectionJuly 2026Rory

Acknowledgment

This risk assessment has been reviewed and approved by the Security Officer.

RoleNameDate
Security OfficerRoryMay 2026
T1 Domain AdminKevin(pending review)
T1 Domain AdminGreg(pending review)


Document History

DateChangeAuthor
May 2026Initial draft — seven risks with inherent/residual scoring, treatment plan, acknowledgment table. Translates threat model into HIPAA-format RA per §164.308(a)(1)(ii)(A).Rory

Internal use only — Cirius Group