Skip to main content
OCR Fined 21 Entities Last Year. Is Yours Next?Breach Notification
5 min readFor HITRUST Assessors and Consultants

OCR Fined 21 Entities Last Year. Is Yours Next?

Questions about OCR's enforcement are flooding in from assessors working with smaller covered entities and business associates. The pattern is clear: OCR's enforcement strategy has shifted. The old focus on avoiding large fines no longer matches the current risk profile. Here's what compliance teams are asking as they realize the enforcement net has widened.

Q1: Is OCR targeting smaller organizations now?

Yes, and it's been happening for a while. OCR imposed 21 financial penalties in 2025, up from 16 in 2024. The average penalty amount has been declining since 2018, even as the number of enforcement actions climbs. In 2022, 55% of OCR financial penalties hit small medical practices.

Settlements like Vision Upright MRI's $5,000 fine or Comprehensive Neurology's $25,000 penalty in 2025 aren't minor for a small practice. Add remediation costs, legal time, and the distraction of responding to OCR, and you're facing significant business disruption.

The takeaway: OCR isn't limiting enforcement to large health systems. If you're advising a small covered entity that thinks it's under the radar, that assumption is outdated.

Q2: What does OCR look for in an investigation?

Start with the HIPAA Security Rule risk assessment. OCR has flagged the risk analysis provision as the most commonly cited violation and launched an enforcement initiative targeting organizations that suffered hacking incidents without a documented risk assessment. As of January 31, 2026, that initiative had closed 11 investigations with financial penalties.

In practice, if your client suffers a breach and OCR asks for the risk assessment, "we did one informally" or "it's on our list" won't suffice. The requirement under 45 CFR § 164.308(a)(1)(ii)(A) is to conduct an accurate and thorough assessment of potential risks to the confidentiality, integrity, and availability of ePHI. It must be documented and current.

OCR also scrutinizes Breach Notification Rule compliance. Several fines in 2025 were for notification failures, late reporting, incomplete disclosures, or skipping notification entirely. The 60-day clock starts when you discover the breach, not when you finish investigating it.

Q3: Hacking is 80% of breaches now. What does that mean for my compliance roadmap?

Your technical safeguards can't be an afterthought. Hacking and IT incidents accounted for over 80% of large healthcare breaches reported to OCR in 2025. Ransomware attacks rose 278% between 2018 and 2023. The 2025 Conduent Business Services breach alone compromised the PHI of more than 62 million Americans.

Focus your client's limited budget on:

  • Encryption: Properly encrypted data can eliminate the breach notification obligation if a device is lost or stolen. It's essential.
  • Multi-factor authentication on privileged accounts: If an attacker gets one credential, MFA prevents them from accessing the entire system.
  • Phishing-resistant training for staff: Most hacking incidents start with a credential compromise, often from someone clicking a link.

Don't treat these as optional. The Security Rule gives flexibility in implementing safeguards, but the risk assessment should drive those choices, not convenience or cost.

Q4: Should I worry about third-party analytics on my client's website?

Yes, this is a quiet exposure that's easy to miss. Website tracking technologies have sent PHI to third parties without a Business Associate Agreement (BAA), driving the 2025 uptick in unauthorized access incidents. Blue Shield of California's 2025 incident affected 4.7 million individuals.

The compliance gap: if a tracking pixel or analytics tool on your patient portal transmits IP addresses, appointment times, or any other individually identifiable health information to a third party, that third party is a business associate. You need a signed BAA before data flows. Without one, you're out of compliance the moment the first pixel fires.

Review every tool that touches your client's website, patient portal, or scheduling system. Ask: does this tool receive PHI? If yes, is there a BAA? If no BAA, either get one signed or remove the tool. There's no middle ground.

Q5: What's the most impactful action I can advise a client to take now?

Complete a documented HIPAA risk assessment. This is the foundation everything else builds on. It's the first thing OCR asks for in an investigation, the most commonly cited violation, and the control that guides where to spend limited resources.

A real risk assessment isn't a one-time checklist. It's a systematic review of where ePHI lives, who can access it, what could go wrong, and what safeguards you've implemented to reduce risks to a reasonable level. Document your findings, prioritize gaps, remediate them, and repeat annually or when your environment changes.

If your client can't produce that document when OCR comes calling, nothing else will matter. The assessment shows you took the Security Rule seriously before a breach happened.

Q6: How do I explain this shift to a client who thinks compliance is just about avoiding big fines?

Frame it as a probability problem. The old model was low probability of getting caught, high penalty if you did. That supported a "wait and see" approach for some.

The new model is higher probability of enforcement, lower individual penalties, but more frequent. OCR imposed 21 financial penalties in 2025. It's not a rare event anymore; it's routine. Because penalties are smaller, OCR can investigate more cases without needing to prioritize only the most egregious violations.

Your client's risk isn't "will we get hit with a $5 million fine?" It's "will we get hit with a $25,000 settlement, plus remediation costs, plus reputational damage, plus the distraction of responding to OCR for six months?" That's a different calculation, favoring compliance now rather than betting on staying off the radar.

Where to Go for More

If you're advising clients on HIPAA compliance, start with OCR's published guidance on risk assessments and the Breach Notification Rule. NIST SP 800-66 is the implementation guide for the HIPAA Security Rule and details the risk assessment process. For clients pursuing certification, the HITRUST CSF maps HIPAA requirements to a certifiable control framework, streamlining compliance and vendor due diligence.

The enforcement data is public: OCR publishes every large breach on its breach portal, and the resolution agreements are posted with detailed findings. Read a few. You'll quickly see the patterns and know what OCR looks for when they open a case.

You Might Also Like