RA-2 Risk Assessment

Security Categorization

High Risk Moderate Low Cost

RA-2 requires categorizing the system and information it processes, storing categorization results with the system owner, and ensuring the categorization is reviewed and approved by designated personnel. In healthcare, correctly recognizing High confidentiality for ePHI drives control selection — under-categorizing a patient portal as "low" leads to weak protections and audit failure.

Control Objective

Assign and approve security categories (confidentiality, integrity, availability impact) for systems based on the information types they handle — especially ePHI — and keep categorizations current.

Implementation Guidance

  1. Inventory information types per system: ePHI, payment card, research, employee HR, public content.
  2. Apply FIPS 199 / CNSSI-style High/Moderate/Low impact for C, I, and A — ePHI confidentiality is typically Moderate or High depending on scope and harm.
  3. Document rationale and system boundary with the category.
  4. Require security officer (or AO delegate) approval of categorization.
  5. Re-categorize when data types, user population, or connectivity change significantly.
  6. Use category to drive control baselines and CA-6 authorization scope.
  7. Align with data classification labels used in DLP and sharing policies.
  8. Do not let 'marketing sites' silently host patient forms that collect ePHI without recategorization.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Patient self-scheduling widget added to a brochure site

Widget collects DOB and MRN; RA-2 recategorizes the property and pulls it under ePHI controls and a BAA with the widget vendor.

Research de-identified warehouse

Integrity and availability remain important; confidentiality impact may differ if truly de-identified — category documents the distinction carefully.

Clinic EHR vs waiting-room digital signage

Different categories prevent one-size-fits-none security spending and clarify monitoring priority.

Best Practices

  • Information-type based categorization.
  • Written rationale and approval.
  • Recategorize on material change.
  • Drive baselines from category.
  • Align with data classification.
  • Watch for ePHI creep into Low systems.

Common Gaps & Violations

  • Every system labeled Moderate with no analysis.
  • ePHI systems categorized Low to reduce cost.
  • Categories never approved.
  • No recategorization after new data flows.
  • Category undocumented in system inventory.

Required Documentation

  • Security categorization procedure
  • System categorization records (C/I/A + rationale)
  • Approver signatures / workflow evidence
  • Recategorization triggers
  • Linkage to inventory (CM-8) entries

How to Test & Validate

  1. Sample ePHI systems for documented C/I/A categories.
  2. Verify approval by designated personnel.
  3. Confirm rationale mentions ePHI where applicable.
  4. Check a recent system change for recategorization consideration.
  5. Compare category to control baseline applied.

Audit Considerations

Mis-tiered systems explain many control gaps. Assessors expect categories that reflect ePHI harm, not convenience.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.306 Security standards: General rules — scalability and risk-based protection; categorization informs 'reasonable and appropriate'.
  • 164.308(a)(1) Risk Analysis — understanding information sensitivity is foundational.
  • 164.312 Technical Safeguards — stronger technical controls follow higher confidentiality categorization for ePHI systems.
  • 164.316 Policies and procedures — document categorization decisions.

Compliance Tips

  • Put security category on the CM-8 inventory field — mandatory.
  • Train product owners that adding ePHI fields changes category.
  • Use category in go-live gates with CA-6.

Frequently Asked Questions

Is RA-2 required if we already do HIPAA risk analysis?

Risk analysis (RA-3 related practices) assesses risk; RA-2 specifically categorizes systems/information impact to drive consistent baselines.

Must we use FIPS 199 labels?

Use a documented High/Moderate/Low (or equivalent) scheme mapped to your control catalog; FIPS 199 is the common reference model.

How often to review categories?

At least annually and on significant change — document the cadence.

References & Resources

  • NIST SP 800-53 Rev. 5 — RA-2
  • FIPS 199 / NIST SP 800-60 information types
  • Related controls: RA-3, CM-8, CA-2, CA-6, PL-2

Need Help Implementing RA-2?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.