HIPAA Risk Assessment for a Multifamily Senior Living Property's IT Systems

A property that runs a wellness clinic, hosts a home health agency, or bills Medicare on-site can find itself under HIPAA's Security Rule regardless of whether it calls itself a hospital, an assisted living community, or an independent living community — and the determination hinges entirely on function, not on the sign out front. Skilled nursing facilities are almost always covered entities because they bill Medicare/Medicaid electronically as routine practice. Assisted living and memory care communities fall into a murkier middle: they are typically regulated at the state level (in California, by the Department of Social Services' Community Care Licensing division) but become covered entities the moment they bill for on-site clinical services. Even independent living communities can trip into HIPAA scope if they operate an on-site medical facility that bills third-party payers.

The more common — and more overlooked — path into HIPAA obligations for multifamily senior living properties is the Business Associate route. A property doesn't have to be a covered entity itself to inherit Security Rule duties. If it hosts a third-party home health or hospice agency's staff and equipment, shares a nurse-call or EHR data interface, or simply provides the network infrastructure that a covered entity's protected health information (PHI) passes through, it can become a Business Associate requiring a signed Business Associate Agreement (BAA). In practice this means the property's own IT and low-voltage vendors can become downstream Business Associates too, merely by having administrative access to systems that store or transmit ePHI. "We're not a hospital, HIPAA doesn't apply to us" is one of the most common — and most expensive — misconceptions in the industry once actual data flows and vendor relationships are mapped out.

Even where a property never touches a resident's medical chart, its physical security systems routinely handle data that qualifies as electronic protected health information (ePHI). Video surveillance footage becomes PHI when it can reasonably identify a person and reveals something about their health status or care — footage of a resident having a medical event, being assisted after a fall, or simply the camera roster for a locked memory-care unit. That reclassification triggers the full weight of the Security Rule: encryption of footage at rest and in transit, role-based access control with multi-factor authentication for anyone viewing or exporting clips, audit trails logging every login and download, and network segmentation isolating the camera system from guest WiFi and other building systems. Door-access control systems are addressed even more directly, since 45 CFR 164.310's Facility Access Controls standard requires documented procedures to validate a person's access by role, control visitors, and log security-related repairs to physical hardware — a literal description of a managed access-control deployment.

Nurse call and emergency pendant systems deserve particular attention because they increasingly ride the same IP backbone as WiFi, cameras, and building automation, while carrying data that is unmistakably health-related: which resident triggered a call, response times, and in newer systems, fall-detection or vitals data tied to a specific unit number. When that data reveals a resident's health status, the system inherits the same encryption, access-control, audit-logging, and segmentation obligations as any other ePHI-bearing system — even though it was likely procured and installed as a life-safety device, not a health record system. Properties that treat nurse call, WiFi, cameras, and access control as one flat network are, in effect, treating their entire building as ePHI-in-scope the moment any one of those systems touches resident health data. This is precisely the kind of unsegmented, converged network that OCR enforcement and cybersecurity researchers repeatedly flag as the highest-risk configuration in healthcare-adjacent facilities.

Caring nurse assisting an elderly resident in a senior living community

Under 45 CFR 164.308(a)(1), a risk analysis has never been optional. The Security Management Process standard requires covered entities and Business Associates to conduct "an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability" of all ePHI they create, receive, maintain, or transmit — across every form of electronic media, from a single nursing-station workstation to a full multi-building network. HHS describes it as the foundational compliance activity because every other required safeguard is supposed to flow from what the risk analysis finds. That's also why OCR enforcement actions so consistently cite "failure to conduct an accurate and thorough risk analysis" as the lead finding, even in cases where the actual incident was a stolen laptop, a ransomware attack, or a misdirected disclosure — the underlying systemic failure is almost always a risk analysis that was never done or never kept current.

The regulatory landscape is also about to shift. HHS published a Notice of Proposed Rulemaking to overhaul the Security Rule on January 6, 2025, and while the comment period closed in March 2025 and a spring 2026 finalization target has already slipped, the direction of travel is unmistakable. The proposal eliminates the current distinction between "addressable" and "required" safeguards — nearly everything becomes mandatory, removing the flexibility smaller operators have historically leaned on. Specific proposed mandates include universal multi-factor authentication, required (not addressable) encryption of ePHI at rest and in transit, a new Vulnerability Management standard requiring automated vulnerability scans at least every six months and penetration testing at least annually by a qualified person, and mandatory network segmentation with a documented technology asset inventory and network map. Once finalized, covered entities and Business Associates would have 240 days to comply — a tight runway for properties still running flat, unsegmented networks.

Enforcement against long-term care operators is not theoretical. OCR settled a HIPAA investigation with Cadia Healthcare Facilities, a Delaware provider of rehabilitation, skilled nursing, and long-term care services, over disclosure of patients' protected health information, requiring a corrective action plan monitored by OCR for two years. OCR has also pursued Deer Oaks, a behavioral health provider delivering psychiatric and psychological services to residents of long-term care and assisted living communities — a reminder that enforcement reaches vendors serving senior living residents even when the property itself isn't the named respondent. 2025 was the worst year on record for large healthcare breaches, with 772 breaches affecting more than 500 individuals reported to OCR, exposing PHI on nearly 140 million people; healthcare breaches now average $7.42 million in cost, the highest of any industry tracked. Corrective action plans following a settlement typically run one to three years and carry their own ongoing compliance costs on top of any fine.

Penalties are structured in four tiers, adjusted annually for inflation. Effective for violations assessed on or after January 28, 2026, per-violation exposure ranges from $145 at the low end (Tier 1, "did not know") up to $2,190,294 in annual aggregate exposure for the top tier — willful neglect that goes uncorrected. OCR's 2019 enforcement-discretion policy still caps effective (not just statutory) maximums lower for the bottom two tiers, so a first-time, promptly-corrected finding is unlikely to produce a seven-figure fine on its own. But the willful-neglect tier, and the accumulating cost of a multi-year corrective action plan, are exactly where an uncorrected risk-analysis gap can land. Under the Breach Notification Rule, any breach affecting 500 or more residents also triggers mandatory notice to prominent local media and to HHS's public breach portal — commonly called the "Wall of Shame" — within 60 days, converting a technical failure into local news coverage.

California operators carry an additional, and in some ways sharper, layer of exposure through the Confidentiality of Medical Information Act (CMIA, Cal. Civil Code § 56 et seq.), which predates HIPAA by more than fifteen years and layers on top of it rather than replacing it. CMIA allows individuals whose medical information is negligently released to recover nominal damages of $1,000 per violation without proving actual harm, plus attorney's fees — and administrative penalties can add up to $2,500 per violation for negligent disclosure, or up to $25,000 per violation for knowing and willful misuse by a non-licensed entity, all stacking on the same incident. A 2026 California Supreme Court decision further lowered the bar for asserting a CMIA claim, holding that plaintiffs need only show data faced a "significant risk" of unauthorized access rather than proving it was actually viewed — meaningfully expanding litigation exposure for an exposed-but-possibly-unviewed camera feed or misconfigured shared drive. Separately, CPRA rights apply in full to employee, applicant, and visitor data that falls outside the direct PHI exemption, so HR files and visitor logs need their own compliance treatment.

For a typical 100-to-150-unit senior living property with networked cameras, door access control, WiFi, and a nurse-call or pendant system, a realistic and defensible budget for a genuinely thorough, professionally conducted HIPAA risk assessment falls in the $10,000-$30,000 range — well beyond the free HHS/ONC Security Risk Assessment tool, which is useful only as a baseline and not a substitute for an assessment covering real ePHI exposure across converged systems. Remediation that follows a risk assessment — network segmentation, access-control hardening, encryption rollout, MFA deployment, and documentation of policies and procedures — typically lands anywhere from $25,000 to $100,000 or more in the first year, depending on how much of the existing infrastructure is legacy and unsegmented. Total annual HIPAA compliance costs, including training and ongoing policy maintenance, generally run from $25,000/year for small operators up to $85,000-$120,000+/year for larger, multi-site programs. Properties that defer this work don't avoid the cost — they simply shift it to the far more expensive post-breach column of corrective action plans, litigation, and reputational damage.

This is precisely the gap where Mytek Pros works. As a licensed low-voltage contractor and Managed Service Provider (License #1116987) with DIR public-works registration (PW-LR-1001158430, BICSI certified) serving multifamily housing and affordable housing developers throughout California, Mytek Pros designs and installs the exact systems this article covers — structured cabling, surveillance CCTV, door access control, and WiFi — with network segmentation and access controls built in from day one, not bolted on after an OCR finding. Our team also conducts HIPAA, SOC 2, NIST, and related compliance audits, and our managed IT and managed security services (typically $125-$250 per user/month) provide the ongoing encryption, MFA, monitoring, and documentation that both the current Security Rule and the pending NPRM demand. If your senior living property has never mapped its actual ePHI exposure across cameras, access control, WiFi, and nurse-call systems, contact Mytek Pros at (619) 353-5702 or inquire@mytekpros.com to scope a risk assessment before OCR — or a plaintiff's attorney — does it for you.

Questions about audits? Get in touch or explore our Audits services.