The day an acquisition closes, the acquired organization's electronic protected health information becomes ePHI held by your covered entity, and your Security Risk Analysis is out of date. Not at the next annual review. That day.
45 CFR §164.308(a)(1)(ii)(A) scopes the analysis to all ePHI held by the covered entity. §164.308(a)(8) requires periodic evaluation in response to environmental or operational changes affecting the security of ePHI. An acquisition is the clearest example of such a change there is, and it is one of the few that arrives with a legal closing date attached, which makes the gap easy for anyone reviewing to spot later.
What comes with the acquisition
A checklist of what has entered scope, in rough order of how often it gets missed:
1. Systems you did not choose and may not migrate for years. The acquired practice's EHR, practice management system, and imaging setup often stay in place through a long transition. Both stacks are in scope for the whole transition, not just the one you standardized on.
2. Their business associates, and their BAAs. Every vendor touching the acquired entity's ePHI is now touching yours. You inherit the relationships and you inherit whatever the agreements do or do not say. Some will be missing. Some will name an entity that no longer exists.
3. Physical locations you have not assessed. Facility access controls, workstation placement, server closets, and device and media handling under §164.310, at buildings nobody from your organization has walked for this purpose.
4. Their workforce, and their access. Accounts, credentials, badge access, and remote access arrangements that were provisioned under someone else's policies. Also anyone who left the acquired organization during the transaction and whose access was never revoked.
5. Historical data and backups. Archives, old backup media, retired systems still holding records. This is the category most likely to be discovered years later, because it is not part of anyone's daily workflow.
6. Their outstanding findings. Whatever their last risk analysis identified and did not remediate is now your open remediation item. If they had no analysis, that absence is now yours.
The due diligence version and the compliance version differ
Transaction due diligence generally asks whether the target has a compliance program and whether there have been reportable breaches. Both are reasonable questions and neither produces what you need afterward.
What you need afterward is an updated enterprise-wide analysis that includes the acquired sites and systems, on your method, with findings tied to specific assets and a single remediation plan. A copy of the target's old risk analysis is useful input. It is not a substitute, because it was scoped to a different entity.
A sequence that works
Before close, if you can: get the asset inventory and the BAA list. These two documents determine most of the post-close work, and they are much easier to obtain while the seller is motivated.
Within the first weeks: establish what ePHI exists and where. Systems, locations, backups, archives, and anything held by their business associates. This is the scope expansion, and until it is written down the rest is guesswork.
Then: assess the new sites and systems on your own method, including physical safeguards at each location. Consistency of method matters here, because findings rated on two different scales cannot be merged into one plan.
Then: fold the results into one enterprise-wide analysis with one remediation plan, rather than keeping the acquired entity's assessment as a separate document. Two analyses covering one entity is the state you are trying to leave.
Record the trigger. The documentation should show that the acquisition prompted a reassessment, with the date. That record is what demonstrates §164.308(a)(8) was met, and it costs nothing to write down at the time and is unreconstructable later.
If you are several acquisitions in
Organizations that have grown by acquisition over a few years frequently find that the analysis describes the original entity plus whichever additions happened to be in flight during an assessment cycle. Sites acquired between cycles never got added.
The fix is not another annual assessment on the old scope. It is one scope reconstruction: list every location and every system the entity holds today, compare it to what the current analysis covers, and treat the difference as the work. That is usually a smaller project than it sounds, and it is the only way the numbers reconcile.
Medcurity models multiple sites under a single engagement, so an acquired location joins your existing structure instead of starting a separate analysis. We have guided more than 1,000 healthcare organizations through Security Risk Analysis since 2018, from private practices to large health systems. If you are integrating a new site and want to talk through scope, start a conversation with our team.
Top comments (0)