Has your organization completed a formal, documented HIPAA Security Risk Analysis covering all systems where patient data is stored or transmitted — within the last 12 months?