The Security Rule requires CEs, BAs, аnd subcоntrаctоrs (аlsо considered to be BAs under HIPAA) to perform an initial risk analysis to determine specific unauthorized uses, disclosures, and data integrity losses that could occur to PHI if the proper security systems and safeguards are not in place.