Skip to main content
OCR Found 6% Pass Risk Management. Here's How to Join ThemOCR Enforcement & Penalties
6 min readFor Privacy Officers

OCR Found 6% Pass Risk Management. Here's How to Join Them

Scope

This guide covers the seven HIPAA provisions OCR evaluated during its 2016-2017 desk audits of 166 covered entities and 41 business associates. It includes steps for implementing requirements where failure rates exceeded 85%. If you're preparing for OCR's current audit cycle or addressing gaps found in an internal assessment, bookmark this page.

Key Concepts and Definitions

Desk audit: A remote review of submitted documentation against selected HIPAA provisions, scored on a five-point scale. A score of 1 means you met the standard's goals; a score of 5 means no evidence you tried.

Risk analysis: A documented assessment identifying threats to the confidentiality, integrity, and availability of ePHI across every system that creates, receives, maintains, or transmits it.

Risk management: Implementing security measures to reduce identified vulnerabilities to a reasonable and appropriate level. Analysis without mitigation doesn't satisfy the Security Rule.

Notice of Privacy Practices: The written document required under 45 CFR § 164.520 describing how a covered entity may use and disclose PHI, what rights individuals hold, and the entity's legal duties.

Individual right of access: The Privacy Rule requirement at 45 CFR § 164.524 giving individuals the right to inspect and obtain copies of their PHI within 30 days, with fees limited to reasonable cost-based amounts.

Requirements Breakdown

Provision Pass Rate (CE) Pass Rate (Business Associate) Primary Failure Mode
Risk Analysis 14% 17% Incomplete scope, outdated assessments, or no documentation
Risk Management 6% 12% Risks identified but not mitigated
Notice of Privacy Practices Content 2% N/A Missing individual rights descriptions, plain language failures
Individual Right of Access 11% N/A Missed 30-day deadline, unreasonable fees
Breach Notification Timeliness Pass Pass Most entities met the 60-day requirement
Breach Notification Content 33% N/A Missing data types, mitigation steps, contact information
Website Notice Posting Pass N/A General compliance achieved

Implementation Guidance

Risk Analysis (Security Rule § 164.308(a)(1)(ii)(A))

Start by defining scope. Your risk analysis must cover every location where ePHI exists: EHR systems, email platforms, patient portals, billing systems, backup storage, and mobile devices. Document each system's technical specifications, who accesses it, and what safeguards currently protect it.

Identify threats and vulnerabilities for each system. Threats include ransomware, unauthorized access, phishing, insider misuse, and physical theft. Vulnerabilities are weaknesses those threats could exploit: unencrypted email, missing access controls, unpatched software, or devices without remote wipe capability.

Assess likelihood and impact. For each threat-vulnerability pair, document the probability of occurrence and the potential harm to patients if ePHI is compromised. This assessment drives your risk management priorities.

Update annually at minimum, and whenever you add new systems or discover incidents that reveal gaps. OCR found most failures involved outdated assessments that didn't reflect current infrastructure.

Risk Management (Security Rule § 164.308(a)(1)(ii)(B))

Create a remediation plan that ties directly to your risk analysis findings. For each high or moderate risk you identified, document the security measure you'll implement, who's responsible, the timeline, and the resources required.

Implement technical safeguards first for high-risk systems. If your risk analysis found unencrypted email carrying ePHI, deploy encryption that operates on every message without requiring sender action. If it found inadequate access controls, implement role-based permissions and multi-factor authentication.

Document what you did and when. OCR doesn't require perfection; it requires reasonable and appropriate action proportional to the risk. A covered entity with limited resources can satisfy the requirement if it demonstrates thoughtful prioritization and steady progress.

Track residual risk. Some vulnerabilities can't be eliminated entirely, so document the risk that remains after mitigation, why you've accepted it, and any compensating controls in place.

Notice of Privacy Practices Content (Privacy Rule § 164.520)

Your Notice must include:

  • How you use and disclose PHI for treatment, payment, and healthcare operations
  • Other permitted or required uses and disclosures
  • Individual rights: to request restrictions, to request confidential communications, to inspect and copy PHI, to amend records, to receive an accounting of disclosures, and to receive a paper copy of the Notice
  • Your duties to protect privacy, to provide the Notice, and to abide by its terms
  • How individuals may file complaints with you and with OCR
  • The effective date and your contact information

Write in plain language. If your current Notice reads like a legal contract, rewrite it at an eighth-grade reading level. Test it with non-compliance staff to confirm it's comprehensible.

Individual Right of Access (Privacy Rule § 164.524)

Respond within 30 days of receiving a written request, or document a single 30-day extension if you need it. Most failures OCR found involved missed deadlines.

Charge reasonable cost-based fees only. You may recover the cost of copying (including labor), postage, and preparing a summary if the individual requested one. You can't charge for retrieval, for maintaining the system, or for your time reviewing whether to grant access.

Provide the format requested. If the individual asks for an electronic copy and you maintain the record electronically, send it in the electronic format requested or in a readable alternative if you can't produce the specific format.

Breach Notification Content (Breach Notification Rule § 164.404)

Your notification letters to individuals must contain:

  • A description of what happened, including the date of the breach and the date you discovered it
  • The types of unsecured PHI involved (names, Social Security numbers, diagnoses, treatment records)
  • Steps individuals should take to protect themselves
  • What you're doing to investigate, mitigate harm, and prevent recurrence
  • Contact information for questions

Don't send a letter that meets the deadline but omits what patients need to know. OCR found this pattern in 76% of audited entities.

Common Pitfalls

Treating risk analysis as a one-time project. You can't satisfy this requirement with a consultant's report from 2019. The Security Rule requires ongoing assessment, and OCR scores you on whether your documentation reflects current systems.

Documenting risks without acting on them. The 14% who passed risk analysis and the 6% who passed risk management aren't the same populations. Analysis alone doesn't demonstrate compliance.

Assuming confidence equals compliance. When Paubox surveyed healthcare IT leaders, 92% said they were confident in preventing email-based data breaches. OCR's audits found 6% implementing sufficient risk management. The gap suggests confidence reflects what you've been told rather than what's been verified.

Copying a template Notice without customizing it. Generic language doesn't satisfy the requirement if it doesn't accurately describe your actual practices or doesn't include all required elements.

Charging patients for medical records retrieval. The fee must be cost-based and limited to copying, postage, and summary preparation if requested. Labor to locate records isn't recoverable.

Quick Reference Table

When OCR asks for... You must produce... Common gap
Risk analysis documentation Current written assessment covering all ePHI systems, threats, vulnerabilities, likelihood, impact Outdated scope, missing systems, no annual update
Risk management plan Written remediation plan with implemented safeguards tied to identified risks Risks documented but not mitigated
Notice of Privacy Practices Current Notice meeting all content requirements in plain language Missing individual rights descriptions
Right of access procedures Policy, training records, and response log showing 30-day compliance Missed deadlines, unreasonable fees
Breach notification letters Sample letters containing all required content elements Missing data types or mitigation steps
Security Rule policies Written policies for each applicable standard and implementation specification Policies exist but don't reflect actual practice

What's changing: HHS proposed removing the distinction between required and addressable specifications in December 2024, which would make encryption and multi-factor authentication mandatory rather than subject to alternative documentation. The proposal also requires a maintained technology asset inventory covering every system touching ePHI. The rule remains under review, but if finalized, it converts the scope failures that made most risk analyses inadequate into a binary test.

Where email fits: Your mail platform appears in every risk analysis because it creates, receives, and transmits ePHI. Controls that encrypt every outbound message by default produce the evidence an auditor requests without requiring you to reconstruct what happened on individual sends. Archiving creates the record. Inbound security addresses the entry point most enforcement actions trace back to. If you're preparing documentation for OCR's current audit cycle, start with systems that touch the most patient data most frequently.

You Might Also Like