Skip to main content
Category: OCR Enforcement and Penalties

Compliance Review

Also known as: HIPAA Compliance Review, OCR Compliance Review
Simply put

In the HIPAA context, a compliance review is an investigation-style review conducted by the federal government (HHS Office for Civil Rights, or OCR) to determine whether a covered entity or business associate is following HIPAA rules. Unlike a complaint-driven investigation, a compliance review is generally initiated by OCR itself rather than in response to an outside complaint. Note that outside of HIPAA, the same phrase is also used broadly in other industries to describe an organization's own internal self-checks, which is a different concept.

Formal definition

Under the HIPAA Enforcement Rule (generally at 45 CFR Part 160, Subpart C), a compliance review is one of the mechanisms through which the Secretary of HHS, acting through OCR, assesses whether a covered entity or business associate is in compliance with the applicable HIPAA Administrative Simplification provisions, including the Privacy Rule, Security Rule, and Breach Notification Rule. It is distinct from a complaint investigation in that OCR may initiate a compliance review on its own initiative rather than upon receipt of a complaint; both can lead to requests for information, findings, resolution agreements, corrective action plans, or civil money penalties. This regulatory meaning should not be conflated with the general business or financial-industry usage of 'compliance review' as an internal, self-initiated audit performed by an organization's own compliance function. Readers should verify the specific regulatory authority, scope, and procedures against the current text of the HIPAA Enforcement Rule, as provisions and enforcement practices are subject to change.

Why it matters

A HIPAA compliance review matters because it represents one of the ways federal enforcement can reach an organization without any outside complaint ever being filed. OCR may initiate a compliance review on its own initiative, meaning a covered entity or business associate can come under scrutiny based on OCR's own awareness of a potential issue rather than because a patient, employee, or competitor reported something. Understanding this distinction helps organizations recognize that maintaining HIPAA compliance is not only about responding to complaints; it is about being prepared for federal review at any time.

The outcome of a compliance review can be significant. Like a complaint investigation, a compliance review can lead to requests for information, formal findings, resolution agreements, corrective action plans, or civil money penalties. Because these enforcement mechanisms are administered by HHS OCR and can carry both financial and reputational consequences, organizations generally treat readiness for a compliance review as an integral part of their overall HIPAA program.

There is also an important terminology caution. Outside of HIPAA, the phrase 'compliance review' is widely used across other industries to describe an organization's own internal self-checks or self-audits performed by its compliance function. That common usage is a different concept from the HIPAA meaning, where a compliance review is an investigation-style review conducted by OCR. Conflating the two can lead to confusion about who is conducting the review and what authority backs it, so professionals should be clear about which sense of the term is intended in a given context.

Who it's relevant to

Covered Entities
Health plans, health care clearinghouses, and covered health care providers can be the subject of an OCR-initiated compliance review even where no complaint has been filed. For these organizations, understanding that OCR can act on its own initiative reinforces the value of ongoing, verifiable HIPAA compliance rather than compliance efforts that are purely reactive to complaints.
Business Associates
Business associates are also subject to OCR's compliance-review authority under the HIPAA Enforcement Rule and can face requests for information, findings, resolution agreements, corrective action plans, or civil money penalties. They should be prepared to demonstrate compliance with the applicable Administrative Simplification provisions that apply to them.
Privacy and Security Officers
Those responsible for HIPAA compliance programs need to distinguish an OCR compliance review from the internal, self-initiated 'compliance review' concept common in other industries. Recognizing that a HIPAA compliance review is a federal enforcement mechanism, not merely an internal self-check, helps them scope readiness efforts appropriately.
Legal and Compliance Counsel
Attorneys and compliance professionals advising healthcare clients should be precise about which authority is conducting a review and under what regulatory basis. Because provisions and enforcement practices change over time, counsel should confirm the specific scope and procedures against the current text of the HIPAA Enforcement Rule.

Inside Compliance Review

OCR-Initiated Compliance Review (Regulatory Meaning)
Under the HIPAA Enforcement Rule, a compliance review is an enforcement mechanism by which HHS OCR examines whether a covered entity or business associate is complying with the applicable HIPAA rules. This is distinct from a complaint-driven investigation because it is initiated by the Secretary (through OCR) rather than triggered by a filed complaint. Readers should verify the precise scope and procedures against the current regulatory text at Part 160, Subpart C.
Trigger and Scope
A compliance review is typically initiated by OCR to determine whether a regulated entity is meeting its obligations, and may arise from sources such as breach reports, media coverage, referrals, or OCR's own initiative rather than an individual complaint. The scope can extend to Privacy Rule, Security Rule, and Breach Notification Rule obligations depending on the matter under review.
Documentation and Evidence Requests
During a compliance review, OCR generally requests documentation demonstrating compliance, which may include policies and procedures, the required risk analysis, workforce training records, business associate agreements, and evidence of implemented safeguards. Regulated entities are generally expected to cooperate and produce records showing how obligations are met.
Resolution Outcomes
A compliance review may conclude with a finding of compliance, technical assistance, a voluntary corrective action, a resolution agreement, or, where warranted, formal enforcement including civil money penalties. Penalty tiers and figures are adjusted over time and should be confirmed against current OCR guidance and the current regulatory text.
Internal Compliance Review vs. OCR Compliance Review (Terminology Note)
In common practitioner usage, 'compliance review' may also refer to an organization's own internal self-assessment of its HIPAA program. This everyday usage should not be confused with the regulatory sense of an OCR-initiated compliance review under the Enforcement Rule. When precision matters, distinguish an internal self-audit from an OCR compliance review.

Common questions

Answers to the questions practitioners most commonly ask about Compliance Review.

Is a compliance review just an internal, self-initiated audit that our organization performs on itself?
No. Under HIPAA, the term "compliance review" has a specific regulatory meaning tied to enforcement. In the context of 45 CFR Part 160, Subpart C, a compliance review is generally an action initiated by HHS OCR (the Secretary) to determine whether a covered entity or business associate is complying with the applicable requirements. This differs from an OCR investigation, which typically arises from a filed complaint; a compliance review can be opened without a complaint. Organizations do conduct their own internal assessments, self-audits, or risk analyses, but those internal activities are distinct from the HIPAA compliance review authority exercised by OCR and should not be conflated with it. Readers should verify the current regulatory text for the precise scope.
Does HIPAA leave "compliance review" without any fixed regulatory definition?
Not in the enforcement context. HIPAA's enforcement provisions in 45 CFR Part 160, Subpart C expressly establish the Secretary's authority to conduct compliance reviews to determine whether covered entities and business associates are meeting applicable requirements. So the term does carry an authoritative, regulator-defined meaning when used in that enforcement setting. Where confusion arises is that people also use "compliance review" loosely in everyday practice to describe internal checks; that colloquial usage is not the same as the OCR enforcement mechanism defined in the regulation. When precision matters, readers should distinguish the OCR-initiated compliance review from internal review activities and confirm details against the current CFR text.
What typically triggers an OCR compliance review, if not a complaint?
Unlike an OCR investigation, which is generally prompted by a filed complaint, a compliance review can be initiated by OCR without a complaint. In practice, triggers may include information OCR receives through breach reports submitted under the Breach Notification Rule, media reports, referrals, or other sources that prompt OCR to examine an entity's compliance. Because the specific criteria and priorities OCR applies can change over time, readers should consult current OCR guidance and enforcement materials rather than relying on a fixed list.
How should an organization respond when OCR opens a compliance review?
Organizations generally receive a written notice or data request from OCR identifying the scope and the documentation sought. A typical response involves promptly engaging appropriate internal stakeholders (privacy and security officers, legal counsel, and leadership), preserving relevant records, and providing accurate, complete, and timely responses to OCR's requests. Because OCR may examine documentation such as policies and procedures, risk analyses, and safeguard evidence, having these materials current and organized generally helps. The precise process and timelines are governed by OCR's procedures, so readers should follow the instructions in the specific notice and, where appropriate, obtain legal counsel.
What documentation is typically useful to have available in the event of a compliance review?
While the exact records OCR requests depend on the matter, entities commonly benefit from having current Privacy Rule and Security Rule policies and procedures, a documented and up-to-date risk analysis, records addressing both required and addressable implementation specifications (noting that addressable does not mean optional), business associate agreements, workforce training records, and evidence of administrative, physical, and technical safeguards for ePHI. Maintaining this documentation supports demonstrating compliance but does not by itself guarantee a favorable outcome. Readers should verify current expectations against the applicable regulatory text and OCR guidance.
Does holding HITRUST CSF certification exempt an organization from an OCR compliance review or establish HIPAA compliance on its own?
No. HITRUST is a private organization and its CSF is a certifiable control framework; certification is not a legal requirement and does not by itself establish HIPAA compliance. OCR retains its authority to conduct compliance reviews regardless of any private certification an entity holds. HITRUST certification may help an organization organize and evidence certain controls, and such artifacts might be useful during a review, but they do not replace the entity's obligation to meet the HIPAA requirements enforced by OCR. Organizations should treat HITRUST as a supporting tool rather than a substitute for HIPAA compliance.

Common misconceptions

A HIPAA compliance review is primarily an internal, self-initiated activity that an organization performs on itself.
Under the HIPAA Enforcement Rule, 'compliance review' refers specifically to an enforcement action initiated by HHS OCR to assess a regulated entity's compliance. While organizations do conduct internal self-assessments, that internal exercise is a separate matter and should not be conflated with the regulatory meaning of a compliance review.
A compliance review only happens after someone files a complaint against the organization.
A compliance review is generally distinct from a complaint-driven investigation. OCR may initiate a compliance review on its own or based on other information such as breach reports, without any individual complaint being filed.
Passing a HITRUST CSF assessment means an organization will not face or can disregard an OCR compliance review.
HITRUST is a private organization and its CSF is a certifiable control framework, not a legal requirement. HITRUST certification does not by itself establish HIPAA compliance and does not exempt a regulated entity from an OCR compliance review or from OCR's enforcement authority.

Best practices

Maintain current, well-organized documentation, policies, procedures, the required risk analysis, training records, and business associate agreements, so that evidence of compliance can be produced promptly if OCR initiates a compliance review.
Clearly distinguish internal self-assessments from an OCR-initiated compliance review in your internal terminology and reporting, to avoid confusion about scope and authority.
Establish a defined internal process for responding to OCR inquiries, including designated points of contact and legal counsel involvement, and treat cooperation and timely response as standard practice.
Conduct regular internal self-assessments across administrative, physical, and technical safeguards, and remember that addressable implementation specifications must be evaluated and addressed, not treated as optional.
Verify current penalty tiers, procedures, and regulatory citations against the current text of the Enforcement Rule and OCR guidance rather than relying on figures that may have been adjusted over time.
Do not rely on HITRUST certification or any single control framework as proof of HIPAA compliance; use it as a supporting tool while confirming that HIPAA obligations, and any additional state law or HITECH requirements, are independently met.