Cooperation with OCR
Cooperation with OCR refers to a covered entity's or business associate's willingness to work with the U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR) when it reviews compliance, investigates a complaint, or examines a potential violation of HIPAA rules. This generally includes responding to requests, providing documents, and allowing OCR to look at relevant policies, procedures, and practices. Note that 'OCR' in HIPAA compliance means the enforcement office, not the unrelated technology called Optical Character Recognition.
In the HIPAA context, cooperation with OCR describes how a regulated party engages with HHS OCR, the authority responsible for enforcing the HIPAA Privacy, Security, and Breach Notification Rules, during a compliance review, complaint investigation, or compliance audit. Such reviews typically involve a comprehensive examination of policies, procedures, and practices over a specified period, and cooperation generally entails timely responses to information requests and access to relevant documentation. The degree of cooperation, along with good-faith remediation efforts, is a factor OCR may weigh when determining how a matter is resolved and whether corrective action or civil monetary penalties are pursued; specific penalty tiers and figures are adjusted over time and should be confirmed against current OCR guidance. This term addresses enforcement engagement only and does not, by itself, establish or guarantee HIPAA compliance; state law and the HITECH Act may impose additional obligations beyond those described here.
Why it matters
When HHS OCR opens a compliance review, complaint investigation, or audit, the way a covered entity or business associate engages can shape how the matter unfolds. OCR reviews are typically broad and comprehensive, examining an organization's policies, procedures, and practices over a specified number of years. Cooperation, responding to information requests in a timely way and providing access to relevant documentation, demonstrates a good-faith posture that OCR may weigh when deciding how to resolve a matter, including whether it pursues corrective action or civil monetary penalties. It is worth noting that specific penalty tiers and figures are adjusted over time and should be confirmed against current OCR guidance.
A useful illustration is Baylor University's public pledge of cooperation with an OCR review, which was described as resulting in a broad, comprehensive look at policies, procedures, and practices spanning multiple years. This underscores that an OCR review is rarely limited to a single incident; it can expose the full breadth of an organization's compliance program to scrutiny. Being prepared to cooperate, with documentation readily available, generally reduces friction during that process.
Because a common source of confusion, it is important to emphasize that in the HIPAA enforcement context 'OCR' means the Office for Civil Rights, the HHS office that enforces the HIPAA Privacy, Security, and Breach Notification Rules, not the unrelated Optical Character Recognition technology. Cooperation with OCR addresses enforcement engagement only; it does not by itself establish or guarantee HIPAA compliance, and state law and the HITECH Act may impose additional obligations beyond those described here.
Who it's relevant to
Inside OCR
Common questions
Answers to the questions practitioners most commonly ask about OCR.