DrapCode assesses ePHI risks across your systems, people, and vendors. Get a documented analysis and a prioritized plan for addressing the findings.

A healthcare organization may know its EHR is protected but have less visibility into exported reports, staff devices, connected apps, and backup copies. An analysis limited to the main system can miss the places patient information actually travels. DrapCode’s HIPAA Security Risk Analysis examines those paths and the safeguards around them. We document potential risks to the confidentiality, integrity, and availability of ePHI, then identify what your team needs to address.


Our team reviews the environment with the people who operate it. That means understanding how information is collected, accessed, shared, stored, and recovered, not relying on a questionnaire alone. You receive a written analysis that identifies assessed systems, explains findings, and prioritizes remediation. Your team can use it to assign work, track decisions, and update the analysis when its environment changes.
The scope follows your organization’s ePHI rather than a fixed list of applications.
Identify patient information across applications, devices, exports, cloud services, and backups.
Trace how ePHI passes between staff, systems, vendors, and care settings.
Examine credible threats to information confidentiality, integrity, and availability across operations.
Review policies, configurations, physical protections, and evidence supporting current controls.
Record each finding’s likelihood, impact, existing controls, and rating rationale.
Recommend practical fixes, responsible owners, and an order for follow-through.
DrapCode reviews the technology and operational evidence needed to understand each risk.
Examine authentication, permissions, and changes to workforce access over time.
Review whether logs support meaningful monitoring and investigation of system activity.
Assess encryption, retention, backups, and transfer methods across ePHI locations.
Map integrations and services that receive, maintain, or transmit patient information.
A health system asks a digital health company for its current risk analysis. DrapCode conducts the assessment and delivers documented findings the team can use to explain its risks and remediation work.
A practice introduces a patient portal . DrapCode reviews the new patient-data flows and determines whether the organization’s existing analysis still accurately covers the environment.
A provider links a telemedicine platform to its EHR platform. We assess the information moving between the tools, the people accessing it, and the safeguards protecting it.
DrapCode scopes the analysis around the systems and workflows your organization uses today.
The work can involve sensitive information about your systems and security arrangements. DrapCode limits the review to the agreed scope and handles assessment materials through appropriate access and sharing controls. A risk analysis is an ongoing part of a regulated organization’s security management process. HIPAA requires an accurate, thorough assessment of risks to ePHI, but the current rule does not impose a universal annual deadline.HHS explains the requirement and its scope.


DrapCode builds and operates healthcare applications, so our assessment can examine the application workflow alongside hosting, access, integrations, and vendor dependencies. Findings are tied to the way the system is used. We deliver a documented assessment and a remediation plan your technical and operational teams can work from. Where a finding concerns an application DrapCode builds or maintains, we can also scope the implementation work separately.
Have DrapCode assess the risks across your ePHI environment and document what needs attention.