In reality, risk analyses should be conducted periodically at a frequency based on factors such as changes in technology being utilized, staff turnover, and change in ownership, for example.8 The OCR, which enforces HIPAA, has indicated that a risk analysis should be conducted at least when an EHR is implemented, and annually thereafter.9 Covered entities attesting to meaningful use must be aware