Compliance Readiness
A 330-center SRA a reviewer can open (and an OCR desk would recognize)
HIPAA requires a security risk analysis. A 330 center that cannot produce a dated one looks unready, even when the visitor is HRSA and not OCR.
"We did one a few years ago" is not a file. A workbook copied from a mainland template that never names your west satellite, your generator, or the bot with a named eClinicalWorks account is also not a file.
This is written for the compliance officer and CIO at an FQHC or other 330 center in Puerto Rico or the USVI.
HIPAA requires the analysis. HRSA still asks whether you have one
The Security Rule requires an analysis of risks to electronic protected health information. That duty does not wait for a grant year. It does not care that you are a 330 center. It cares that you create, receive, maintain, or transmit ePHI.
HRSA is not OCR. There is no cybersecurity chapter in the Site Visit Protocol. Reviewers still ask whether records can be retrieved, whether patient information is protected against loss, destruction, or unauthorized use, and whether you meet applicable federal requirements. The operator version of that overlap is what HRSA reviewers actually ask for in your cybersecurity file.
A missing or stale risk analysis is the fastest way to look unready. FTCA deeming is a separate file. Do not mix it in and call the SRA done.
Documents for an Operational Site Visit are due before the team arrives. What is not on the table by the close of day one is not in the assessment. The named security official has to speak to the analysis without hunting a share drive.
Scope: every system that holds patient information
An analysis that names "the EHR" and stops is theater.
Scope the systems that actually hold patient information in a 330 operation:
- eClinicalWorks and anything that feeds it: interfaces, scanning folders, healow if you use it, the clearinghouse.
- Backups and the restore path. Backup software is not the proof. Restore is the proof.
- Email and file shares, including the sliding-fee packets that never made it into the chart.
- Imaging and lab systems that sit next to the EHR, not inside it.
- Satellite sites: workstations, printers next to the vaccine fridge, the circuit that fails while the main site is open.
- Automation that has a named eCW account. Digital staff is a user. Users are in scope. So is the BAA.
The November 2025 Site Visit Protocol update is explicit: security policies should protect all patient information, even when it is not technically PHI under HIPAA. Scheduling notes and care-management logs count. Your analysis should not pretend those files do not exist.
If automation touches PHI, you need to know where that PHI lives, who can access it, and how access is logged. If you cannot answer those three questions in one sentence, the system is not ready, and it does not belong in a "out of scope" footnote.
Dated findings plus owners on open items
A reviewer can defend looking at: a dated document, not a memory. Scope. Findings. What you did with them.
An analysis with no follow-through is a paper. Findings need owners and a next date. "IT will look at MFA" is not an owner. A name, a system, and a status is an owner.
What this is not:
- A 40-control matrix invented for the visit.
- Last Meaningful Use-era HITEQ workbook with a new header.
- A vendor PDF that scores you against a product you do not run.
- A certification badge in place of findings.
HITRUST and SOC 2 Type II are how Millennial Networks runs our own stack. They are not a 330-center mandate. HRSA does not require you to buy a badge before the OSV. A certification you will not maintain is worse than a clean, dated analysis that matches production.
Do not invent cost figures from someone else's SaaS page. Produce the analysis you actually run.
Multi-site: one enterprise analysis, site-specific reality
One enterprise analysis. Then the physical and workstation reality at each site.
Do not copy-paste the same workbook into a folder per address. The main clinic in the metro area is not the west site on generator. The USVI site is not a "location" in a drop-down. Water sits between you and the spare part.
What changes by site:
- Who can walk up to a workstation.
- Where paper notes go when eCW is down, and how they get back into the record.
- Which circuit, which generator, which closet.
- Which staff are temps, students, locums, or shared across sites on a single login.
Shared "nurse" accounts fail the unauthorized-use test at every address. Joiners, leavers, and transfers are part of the analysis because access is how PHI walks out.
The security official still has to speak for the whole 330 project. Site managers still have to describe what happens in their hallway. If those two stories disagree, the file is already wrong.
Island threats: grid, generator, last-mile, water between you and the spare
A mainland SRA template will talk about phishing and ransomware. Fine. Include them. Then write the threats that actually take a 330 center offline here.
Grid events. Generator run time that is not infinite. Last-mile that fails in pieces. A satellite that goes dark while the main site is still seeing patients. Weather. A spare-parts delay across water in the USVI.
Chapter 10's "loss or destruction" test is this: can you protect and retrieve patient information when power and connectivity fail the way they fail here. Health outcomes sit on whether the provider can open the chart. The patient with health-related needs still has a slot at 8:00.
Contingency in the analysis means:
- What stays up: EHR, phones, eligibility, e-prescribing.
- A restore you have actually done, on a date you can name.
- What clinic staff do for 24 hours if eClinicalWorks will not open, and how the paper note returns to the record.
- A call tree someone would use at 6:40 a.m., not a 30-page plan that names tools you do not own.
If the vendor's runbook starts with "the patient can wait," they are not a 330 vendor.
How MN runs the SRA as part of managed IT, not as a PDF mill
Millennial Networks is healthcare IT and MSP for FQHCs and CHCs in Puerto Rico and the USVI. Founded 2017. Ten-year mark: January 2027. Humans First, Tech Second.
We do not drop a binder and leave. The SRA is part of managed IT for 330 centers: the same stack that runs help desk around clinic hours, eClinicalWorks, backup you have restored, and the OSV file.
How the work actually runs:
- Inventory the systems that hold patient information, including satellites and any automation with a named EHR account.
- Write findings against production, not against a template.
- Put owners on open items. Track them in the same operating rhythm as incidents, not in a once-a-year scramble.
- Match policies, access, restore evidence, BAAs, and training to the analysis. The SRA is the map. The file is the terrain.
- Sit with the named security official until they can open it on the first ask.
At the lab end of the same island reality, Shailene Corretjer at High Profile Laboratories described always-on IT, fast incident response, and a harder network around sensitive data:
Having an IT team available at all times has been fundamental to our operations. Their fast response and technical expertise to resolve any incident immediately has been extremely valuable. On top of that, strengthening the security of our network has been a great added value, giving us greater peace of mind and confidence in the protection of sensitive data.
Different organization type. Same rule: downtime is not a ticket category. It is an operations failure.
Magaly López, Health IT Specialist at the PR Primary Care Association (HCCN for Puerto Rico and the Virgin Islands):
As Health IT Specialist for the 330 Centers in Puerto Rico and the Virgin Islands, I have seen how Millennial's services have been fundamental in strengthening the technology infrastructure across our clinics. Their team has been a key ally in modernizing systems, enabling more agile, secure, and efficient care.
Ask us to produce the dated analysis you would hand a reviewer this week.
Who this is for
- Compliance officers and CIOs at FQHC, CHC, and other 330 centers in Puerto Rico and the USVI.
- Security officials who will be interviewed and cannot afford to hunt a share drive.
- CEOs who will not buy a badge to paper over a missing file.
FAQ
What is a HIPAA security risk analysis for an FQHC
A dated analysis of risks to ePHI (and, for a 330 center, the rest of the patient information Chapter 10 cares about) across the systems you actually run: EHR, backups, email, imaging, sliding-fee shares, satellites, and automation with a named account. Findings, owners, and follow-through. HIPAA requires it. HRSA still asks whether you have one.
Is a HIPAA risk assessment checklist enough
A checklist is an intake tool. It is not the analysis. Autocomplete will sell you templates from the Meaningful Use era. A reviewer wants scope, dated findings, and what changed in production. If the only artifact is a yes/no list with no owners, you do not have an SRA.
Does HRSA require HITRUST or SOC 2 for a 330 center
No. HITRUST and SOC 2 Type II are certifications of a stack. Millennial Networks claims them for our own operation. They are not your OSV homework. Reviewers want the dated SRA, access, restore, BAAs, training roster, and a person who can speak to them.
How often should a 330 center update the SRA
When the environment changes, and on a cadence you can defend. New site, new EHR module, new automation user, new backup target, a restore you actually ran: those are updates. "We did one a few years ago" fails both an OCR desk and an OSV interview.
Book a discovery call
Ask us to produce the dated analysis you would hand a reviewer this week.
Request a discovery call. Talk to Alberto. Thirty minutes.
Millennial Networks · Metro Office Park Lot. 6, Suite 204, Guaynabo, PR 00968 · 4850 Tamiami Trl N, Suite 301, Naples, FL 34103 · 787-945-2260 · corp@mnetpr.com
