Skip to main content
Category: OCR Enforcement and Penalties

Cooperation with OCR

Also known as: OCR, Cooperating with an OCR investigation, Cooperation with HHS OCR
Simply put

Cooperation with OCR refers to a covered entity's or business associate's willingness to work with the U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR) when it reviews compliance, investigates a complaint, or examines a potential violation of HIPAA rules. This generally includes responding to requests, providing documents, and allowing OCR to look at relevant policies, procedures, and practices. Note that 'OCR' in HIPAA compliance means the enforcement office, not the unrelated technology called Optical Character Recognition.

Formal definition

In the HIPAA context, cooperation with OCR describes how a regulated party engages with HHS OCR, the authority responsible for enforcing the HIPAA Privacy, Security, and Breach Notification Rules, during a compliance review, complaint investigation, or compliance audit. Such reviews typically involve a comprehensive examination of policies, procedures, and practices over a specified period, and cooperation generally entails timely responses to information requests and access to relevant documentation. The degree of cooperation, along with good-faith remediation efforts, is a factor OCR may weigh when determining how a matter is resolved and whether corrective action or civil monetary penalties are pursued; specific penalty tiers and figures are adjusted over time and should be confirmed against current OCR guidance. This term addresses enforcement engagement only and does not, by itself, establish or guarantee HIPAA compliance; state law and the HITECH Act may impose additional obligations beyond those described here.

Why it matters

When HHS OCR opens a compliance review, complaint investigation, or audit, the way a covered entity or business associate engages can shape how the matter unfolds. OCR reviews are typically broad and comprehensive, examining an organization's policies, procedures, and practices over a specified number of years. Cooperation, responding to information requests in a timely way and providing access to relevant documentation, demonstrates a good-faith posture that OCR may weigh when deciding how to resolve a matter, including whether it pursues corrective action or civil monetary penalties. It is worth noting that specific penalty tiers and figures are adjusted over time and should be confirmed against current OCR guidance.

A useful illustration is Baylor University's public pledge of cooperation with an OCR review, which was described as resulting in a broad, comprehensive look at policies, procedures, and practices spanning multiple years. This underscores that an OCR review is rarely limited to a single incident; it can expose the full breadth of an organization's compliance program to scrutiny. Being prepared to cooperate, with documentation readily available, generally reduces friction during that process.

Because a common source of confusion, it is important to emphasize that in the HIPAA enforcement context 'OCR' means the Office for Civil Rights, the HHS office that enforces the HIPAA Privacy, Security, and Breach Notification Rules, not the unrelated Optical Character Recognition technology. Cooperation with OCR addresses enforcement engagement only; it does not by itself establish or guarantee HIPAA compliance, and state law and the HITECH Act may impose additional obligations beyond those described here.

Who it's relevant to

Privacy and Security Officers
These individuals are typically the primary points of contact during an OCR review and are responsible for gathering and producing the policies, procedures, and documentation OCR requests. Maintaining organized, current records generally supports a smoother, more responsive cooperation process.
Compliance Officers
Compliance officers coordinate the organization's overall response to an OCR review, including timely information requests and any good-faith remediation efforts. They should understand that cooperation is a factor OCR may weigh in resolving a matter, though it does not by itself establish HIPAA compliance.
Legal Counsel
Attorneys advise on how the organization engages with OCR, manage the scope of document production, and help navigate potential corrective action or civil monetary penalty exposure. They should confirm current penalty tiers against OCR guidance and account for additional obligations that may arise under state law or the HITECH Act.
Business Associates and Subcontractors
Business associates are directly subject to OCR enforcement of certain HIPAA rules and may face their own reviews or be drawn into a covered entity's investigation. They should be prepared to cooperate with OCR requests and to produce documentation consistent with their obligations under business associate agreements.
Executive Leadership
Because an OCR review can be broad and span multiple years of practices, leadership should understand the organizational stakes of an enforcement engagement and support the resources needed to respond cooperatively and remediate identified issues in good faith.

Inside OCR

Duty to Respond to Investigations
Covered entities and business associates are generally expected to cooperate with the HHS Office for Civil Rights (OCR) when it conducts compliance reviews, complaint investigations, or audits related to the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules.
Providing Access to Records and Information
Cooperation typically involves making requested information, documentation, and records available to OCR, which may include policies, procedures, risk analyses, business associate agreements, and other evidence relevant to the matter under review.
Permitting Access to Facilities
In some cases OCR may need access to facilities, systems, or personnel to complete an investigation or review; regulated parties are generally expected to permit reasonable access consistent with the applicable regulatory text.
Prohibition on Obstruction and Retaliation
Cooperation generally excludes interfering with an investigation, and the HIPAA rules include protections against intimidating, threatening, or retaliating against individuals who file complaints or participate in OCR proceedings. Readers should verify the specific provisions against the current regulation.
Enforcement Authority
OCR is the authority within HHS responsible for enforcing HIPAA. Cooperation obligations flow from the Enforcement Rule and related provisions rather than from any private framework such as HITRUST.
Resolution Pathways
OCR investigations may conclude through voluntary compliance, corrective action, resolution agreements, or civil monetary penalties, depending on the facts and the regulatory tier involved. Specific penalty amounts and tiers are adjusted over time and should be confirmed against current OCR guidance.

Common questions

Answers to the questions practitioners most commonly ask about OCR.

Is cooperating with an OCR investigation optional if a covered entity believes it did nothing wrong?
No. Cooperation with HHS OCR is not contingent on an entity's own assessment of its innocence. Under HIPAA's Enforcement Rule, covered entities and business associates are generally obligated to cooperate with OCR's compliance reviews and investigations, including providing requested records and access. Declining to cooperate because you believe you are not at fault does not remove the obligation and may itself be treated as a compliance concern. If you have questions about the scope of a specific request, address them through counsel rather than by refusing to engage.
Does cooperating with OCR and completing a corrective action plan mean the entity is now HIPAA compliant?
Not by itself. Resolving an OCR investigation, entering into a resolution agreement, or completing a corrective action plan addresses the specific matters OCR identified; it does not certify that an entity is fully compliant across all HIPAA requirements. Compliance is an ongoing obligation that spans the Privacy, Security, and Breach Notification Rules. Similarly, note that cooperation with OCR is a HIPAA enforcement matter and is separate from any private framework such as HITRUST certification, which is not a legal requirement and does not by itself establish HIPAA compliance. Readers should treat corrective actions as one part of a continuing compliance program.
Who inside our organization should be the point of contact when OCR makes an inquiry?
In most cases, organizations designate a specific individual or team, often the Privacy Officer, Security Officer, or legal counsel, to receive and coordinate responses to OCR inquiries. Centralizing communication helps ensure that responses are consistent, that requests are tracked, and that privileged or sensitive information is handled appropriately. Because approaches vary by organizational size and structure, entities should define this point of contact in their policies and confirm the process with counsel.
What kinds of records does OCR typically request during an investigation?
OCR requests generally relate to the matter under review and may include policies and procedures, documentation of safeguards, workforce training records, risk analyses, business associate agreements, and records showing how a specific incident or complaint was handled. The exact scope depends on whether the inquiry concerns the Privacy Rule, the Security Rule (which addresses ePHI specifically), or the Breach Notification Rule. Entities should review each request carefully and, where scope is unclear, seek clarification through counsel.
How should we prepare our documentation before an OCR inquiry ever occurs?
A common practice is to maintain current, well-organized documentation as part of an ongoing compliance program, including up-to-date policies, a current risk analysis, evidence of workforce training, and records of how complaints and incidents are addressed. Retaining documentation in accordance with applicable HIPAA record-retention requirements (which readers should verify against the current regulation) helps an entity respond promptly if OCR does make an inquiry. Note that state law or other frameworks may impose additional retention obligations.
Can an entity involve legal counsel during cooperation with OCR without appearing uncooperative?
Yes. Involving legal counsel is generally consistent with cooperation and is a routine practice. Counsel can help interpret the scope of requests, ensure responses are accurate and complete, and protect legitimate privileges. The goal is to respond in good faith and within the timeframes OCR sets, not to obstruct. Working through counsel to clarify or manage requests is different from refusing to engage, which is what raises cooperation concerns.

Common misconceptions

Achieving HITRUST CSF certification means an organization has already satisfied any cooperation obligations to OCR or can point to certification in place of responding to an investigation.
HITRUST is a private organization and its CSF certification is not a legal requirement and does not by itself establish HIPAA compliance. Certification does not substitute for the duty to cooperate with OCR, and regulated parties must still respond to OCR investigations and reviews directly.
Only covered entities have to cooperate with OCR; business associates and subcontractors are outside its reach.
Both covered entities and business associates can be directly subject to OCR investigation and enforcement for the obligations that apply to them. Obligations attach through defined HIPAA relationships and business associate agreements, so a vendor's cooperation duties depend on its role, not on being a covered entity.
Cooperation is limited to handing over documents, so an organization can otherwise resist or delay an investigation without consequence.
Cooperation generally extends beyond document production and includes permitting reasonable access and refraining from obstruction or retaliation. Failing to cooperate, or retaliating against complainants, can itself be treated as a compliance concern under the applicable rules.

Best practices

Designate and prepare a point of contact (such as the privacy or security officer) to receive and coordinate responses to OCR inquiries, so requests are handled promptly and consistently.
Maintain organized, retrievable documentation, including policies, procedures, risk analyses, and business associate agreements, so that information requested during an investigation can be provided without undue delay.
Involve legal counsel early when an OCR complaint, compliance review, or audit is received, and confirm any specific deadlines or procedural requirements against the current regulation rather than relying on assumptions.
Implement and enforce anti-retaliation protections so that individuals who file complaints or participate in OCR proceedings are not intimidated, threatened, or penalized.
Respond truthfully and completely, and avoid actions that could be viewed as obstructing or interfering with an investigation.
Treat any HITRUST certification or other framework work as supporting evidence only, and do not present it as a substitute for direct cooperation with OCR or as proof of HIPAA compliance.