Skip to main content
OCR Fines 14% Compliance: A Risk Assessment AutopsyRegulatory Framework
5 min readFor Covered Entity Leaders

OCR Fines 14% Compliance: A Risk Assessment Autopsy

The Challenge

In October 2024, the Office for Civil Rights (OCR) launched its Risk Analysis Initiative. By February 2026, it had announced its 11th and 12th enforcement actions under the program. The pattern was clear: covered entities that thought they'd completed a HIPAA security risk assessment couldn't produce documentation meeting the Security Rule requirements when OCR investigated.

The problem wasn't ignorance. Most organizations knew a risk assessment was necessary. The issue was execution. An earlier OCR audit found that only 14% of covered entities were substantially meeting their risk analysis obligations. This means 86% were at risk of enforcement action, not because they ignored HIPAA, but because their approach to this foundational compliance requirement was incomplete, undocumented, or outdated.

This isn't just about one entity; it's a systemic failure across the industry to treat risk assessment as the structured, ongoing process the Security Rule demands.

The Environment and Constraints

Healthcare organizations face a significant challenge: the Security Rule doesn't provide a step-by-step methodology. It requires a risk assessment but doesn't specify the format, tools, or documentation structure. This flexibility can be a trap. Without a clear template, many organizations create assessments that seem complete internally but fail to demonstrate compliance externally.

The enforcement environment has shifted. Large healthcare data breaches now occur at about two reported breaches per day, roughly double the rate seen in 2018. OCR's dedicated Risk Analysis Initiative indicates that the agency views incomplete risk assessments as a root cause of these incidents, not just a paperwork issue.

Every covered entity and business associate faces the same legal obligation, regardless of size. A solo provider has no exemption. A small practice can't claim limited resources as a defense. The requirement applies equally to a three-person clinic and a 300-bed hospital.

The constraint isn't technical capacity; it's structure. Organizations that fail audits typically have partial controls in place but can't prove they systematically identified all ePHI locations, assessed all required safeguard categories, assigned risk levels to gaps, and documented a remediation plan with assigned ownership and deadlines.

The Approach That Works

Organizations that pass OCR scrutiny treat the risk assessment as a six-step documentation process, not a one-time project:

Step one: Inventory every ePHI location. This includes electronic health records systems, cloud storage, email, portable devices, mobile applications, and third-party platforms. Data mapping is essential. You can't assess risk to ePHI you haven't identified.

Step two: Audit administrative safeguards. Do you have a documented security management process? Have you designated a security officer? Is workforce training in place, with access permissions managed by job role? Can you demonstrate periodic security evaluations? These aren't yes-or-no questions during an audit. You need documentation for each.

Step three: Review physical safeguards. Facility access controls, workstation use policies, and device disposal procedures must be documented. Physical safeguards extend to home offices and portable devices, not just your main facility.

Step four: Assess technical safeguards. Access controls, audit controls, integrity protections, and transmission security must be evaluated. The core question for each: do you have this control in place, and can you prove it?

Step five: Identify threats and vulnerabilities. Consider ransomware, phishing, unauthorized access, hardware failure, and natural disasters. Internal risks like human error and weak passwords, and external risks like cyberattacks and physical theft, should be documented. Identify both the threat and the vulnerability in your current environment that would allow it to cause harm.

Step six: Assign risk levels and remediation actions. Every gap gets a likelihood rating, an impact rating, and a specific remediation action with a responsible party and target date. Vague action items don't count as a plan.

Organizations that meet OCR's standard use a structured template to document findings in each area. That template becomes the evidence during an audit.

Results and What Changed

Organizations that adopted this structured approach didn't eliminate every risk. They demonstrated a defensible process. When OCR reviews a risk assessment, the question isn't whether you've achieved perfect security. It's whether you've systematically identified risks, evaluated your current controls, prioritized gaps, and assigned remediation actions.

The measurable outcome isn't a compliance score; it's auditability. Can you produce documentation that shows you completed all six steps? Can you demonstrate that you revisited the assessment when significant changes occurred to your systems, operations, or workforce?

The shift from "we did a risk assessment" to "here's our documented risk assessment process" is what separates the 14% from the 86%.

What They Would Do Differently

Organizations that struggled with OCR reviews consistently made the same mistakes:

They treated the risk assessment as a one-time project instead of an ongoing requirement. The Security Rule requires you to revisit the assessment whenever significant changes occur. If you implemented a new EHR system, added a business associate, or moved to cloud storage since your last assessment, your documentation is already outdated.

They used vague language in their documentation. "Security issue" doesn't tell an auditor what system is affected. "Improve access controls" doesn't specify who's responsible or when the action will be completed.

They documented gaps without assigning risk levels. A list of findings isn't a risk assessment. You must evaluate likelihood and impact for each gap, then prioritize remediation accordingly.

They failed to document existing controls. Even partial controls should be noted. If you have some access restrictions in place but they don't cover all ePHI locations, document what you have and what's missing. Silence during an audit looks like absence.

Takeaways for Your Team

If your last risk assessment is more than a year old, or if you can't produce documentation that covers all six steps above, you're in the 86%. Here's how to move into the 14%:

Start with data mapping. You can't assess risk to ePHI you haven't identified. Create a complete inventory of every location where ePHI is created, received, stored, or transmitted.

Use a template that forces specificity. Each risk entry needs a description, likelihood rating, impact rating, existing controls, and a remediation action with an owner and deadline.

Prioritize high-risk gaps immediately. Don't wait until every gap is resolved before acting on the most critical ones. Encryption gaps on portable devices that regularly transmit patient data qualify as high likelihood and high impact.

Assign ownership to every remediation item. Unassigned tasks stay incomplete. Every action needs a responsible party and a target date.

Schedule a follow-up review within six months. The risk assessment isn't a one-time project. It's an ongoing process that must be revisited whenever significant changes occur.

The 14% aren't doing anything technically complex. They're following a structured process and documenting it thoroughly. That's the difference between passing an OCR audit and facing an enforcement action.

You Might Also Like