Skip to main content
Category: OCR Enforcement and Penalties

Resolution Agreement

Also known as: HIPAA Resolution Agreement, OCR Settlement Agreement
Simply put

A resolution agreement is a settlement between HHS and a covered entity or business associate to resolve potential HIPAA violations, typically identified through an OCR investigation or compliance review. Rather than proceeding to formal penalties, the organization agrees to specific terms, which often include actions to come into compliance. Entering into such an agreement is generally a voluntary alternative to contested enforcement.

Formal definition

A resolution agreement is a settlement instrument signed by the U.S. Department of Health and Human Services (HHS), acting through its Office for Civil Rights (OCR), and a covered entity or business associate to resolve alleged noncompliance with the HIPAA Rules. In most cases it is accompanied by a corrective action plan and a monetary settlement amount, and it typically imposes ongoing obligations such as monitoring for a defined period. It should not be confused with civil money penalties imposed under the Enforcement Rule; a resolution agreement is generally a negotiated resolution reached in lieu of, or to conclude, a formal enforcement action. Note that the terms of any individual agreement, including any monetary amounts and duration, vary case by case and should be confirmed against the specific agreement and current OCR guidance. The term 'resolution agreement' is also used by other agencies (for example, the U.S. Department of Education's OCR under Title VI or other civil rights statutes) in unrelated contexts; those are distinct from HIPAA resolution agreements administered by HHS OCR.

Why it matters

For compliance officers and legal counsel, a resolution agreement represents the point at which a potential HIPAA compliance problem becomes a formal, documented commitment to HHS. Rather than contesting an enforcement action or facing the imposition of civil money penalties under the Enforcement Rule, an organization can generally negotiate a settlement that resolves the matter on defined terms. Understanding this mechanism helps organizations weigh their options when OCR opens an investigation or compliance review, and it underscores why proactive compliance and cooperation with OCR can shape the outcome of an inquiry.

Because a resolution agreement is typically accompanied by a corrective action plan and often ongoing monitoring obligations for a defined period, its effects extend well beyond the initial settlement. Organizations may find themselves committed to specific remediation steps, reporting requirements, and oversight that can last for years. These agreements also become part of the public record of OCR enforcement activity, which can inform how peer organizations assess their own risk posture and prioritize compliance efforts.

It is important to note that a resolution agreement is distinct from civil money penalties and from resolution agreements used by other agencies in unrelated contexts. For example, the U.S. Department of Education's Office for Civil Rights also uses instruments called resolution agreements under civil rights statutes such as Title VI; those are separate from HIPAA resolution agreements administered by HHS OCR and should not be conflated. Any specific terms, monetary amounts, or durations vary case by case and should be confirmed against the individual agreement and current OCR guidance.

Who it's relevant to

Compliance and Privacy Officers
Those responsible for HIPAA compliance need to understand resolution agreements as a possible outcome of an OCR investigation or compliance review. Familiarity with the typical structure, a settlement paired with a corrective action plan and ongoing monitoring, helps in planning both proactive compliance and any response to an OCR inquiry.
Legal Counsel
Attorneys advising covered entities or business associates evaluate whether negotiating a resolution agreement is preferable to contesting formal enforcement or facing civil money penalties. They also negotiate the specific terms, which vary case by case and carry ongoing obligations.
Covered Entities and Business Associates
Any organization subject to the HIPAA Rules may become a party to a resolution agreement if OCR identifies potential noncompliance. Business associates, not only covered entities, can be directly party to such agreements with HHS.
Executive Leadership and Boards
Because resolution agreements can involve monetary settlements and multi-year monitoring commitments, leadership should understand their potential operational, financial, and reputational implications, and support the resources needed to implement any corrective action plan.

Inside Resolution Agreement

Settlement Basis
A resolution agreement is a negotiated settlement between a covered entity or business associate and HHS OCR, typically entered into to resolve potential HIPAA violations without a formal finding of liability or the imposition of a civil money penalty through the enforcement process.
Monetary Settlement Amount
Most resolution agreements include a settlement payment. This amount is negotiated and distinct from the statutory civil money penalty tiers; specific figures vary case by case and should be confirmed against OCR's published enforcement actions.
Corrective Action Plan (CAP)
Resolution agreements generally incorporate a corrective action plan requiring the entity to address the deficiencies identified, which may include revising policies and procedures, workforce training, and remediation of specific Privacy Rule, Security Rule, or Breach Notification Rule gaps.
Monitoring and Reporting Obligations
CAPs typically impose a defined period of monitoring during which the entity must report to OCR on its compliance activities, submit documentation, and may be subject to review of its remediation efforts.
Duration and Term
The agreement generally specifies a time period over which the obligations apply. Terms vary by agreement and should be verified against the specific document rather than assumed.
Enforcement Authority
Resolution agreements are administered by HHS OCR, the authority responsible for enforcing the HIPAA Privacy, Security, and Breach Notification Rules, not by HITRUST or any private body.

Common questions

Answers to the questions practitioners most commonly ask about Resolution Agreement.

Does entering a resolution agreement mean HHS OCR has formally found the entity guilty of violating HIPAA?
No. A resolution agreement is a settlement, and it generally includes language stating that the agreement is not a formal finding or admission of liability. Entities typically enter into these agreements to resolve potential violations identified during an OCR investigation without a formal determination of noncompliance. Readers should review the specific terms of any given agreement, as language can vary.
Is the settlement payment in a resolution agreement the same thing as a civil money penalty?
No. The monetary amount in a resolution agreement is generally described as a settlement amount, not a civil money penalty (CMP). A CMP is imposed through the formal enforcement process under the Enforcement Rule and is subject to defined penalty tiers, whereas a resolution amount is negotiated as part of a voluntary settlement to resolve an OCR investigation. Penalty tiers and figures are adjusted over time and should be confirmed against current HHS guidance.
What does a corrective action plan typically require an entity to do?
A corrective action plan (CAP) is generally attached to or accompanies a resolution agreement and typically requires the entity to take specific remedial steps within defined timeframes. These commonly include revising policies and procedures, conducting or updating a risk analysis, providing workforce training, and reporting on progress to OCR over a monitoring period. The exact obligations depend on the issues OCR identified, so readers should refer to the terms of the particular agreement.
How long does an entity remain subject to oversight under a resolution agreement?
The monitoring period is defined within each agreement and its associated corrective action plan, and it generally lasts for a set number of years during which the entity must submit reports and demonstrate ongoing compliance. Because the duration varies by agreement, the specific term should be verified against the text of the applicable resolution agreement.
Do resolution agreement obligations apply to business associates as well as covered entities?
Resolution agreements can involve either covered entities or business associates, depending on which party OCR investigated. Because business associates have direct obligations under certain HIPAA rules, they can be subject to OCR enforcement and to resolution agreements. The obligations imposed apply to the party that entered the agreement; flow-down responsibilities to subcontractors are addressed separately through business associate agreements rather than through the resolution agreement itself.
Does completing a corrective action plan guarantee that an entity is HIPAA compliant going forward?
No. Completing a CAP satisfies the specific remedial obligations of a particular agreement but does not by itself establish ongoing HIPAA compliance or prevent future investigations or breaches. Compliance is an ongoing obligation that generally requires continued risk analysis, safeguards, and program maintenance. Entities should treat a completed CAP as a baseline rather than a permanent assurance and continue monitoring against current regulatory requirements.

Common misconceptions

A resolution agreement is an admission that the entity violated HIPAA.
Resolution agreements are typically negotiated settlements that generally do not constitute a formal admission of liability. They resolve potential violations without OCR proceeding to a formal penalty determination, though they do require corrective action.
Paying the settlement amount ends the entity's obligations.
In most cases the accompanying corrective action plan imposes ongoing obligations, including remediation, training, and periodic reporting to OCR over a defined monitoring period, that extend well beyond any monetary payment.
Achieving HITRUST certification would have prevented or resolved the matter.
HITRUST is a private organization and its CSF is a certifiable control framework; certification is not a legal requirement and does not by itself establish HIPAA compliance or preclude an OCR enforcement action or resolution agreement.

Best practices

Treat a corrective action plan as a binding roadmap: track each obligation, its deadline, and the responsible owner, and retain documentation demonstrating completion for OCR reporting.
Conduct or update an accurate, thorough risk analysis of ePHI as part of remediation, since Security Rule risk analysis deficiencies frequently feature in OCR enforcement matters.
Address both required and addressable implementation specifications under the Security Rule, remembering that addressable does not mean optional and that decisions must be documented and reasonable.
Review policies and procedures across the applicable rules (Privacy, Security, and Breach Notification), and reassess business associate agreements to confirm obligations flow appropriately to vendors and subcontractors.
Engage legal counsel early when negotiating with OCR to clarify the scope, term, and reporting requirements, and confirm any monetary figures and penalty tiers against current OCR guidance since amounts are adjusted over time.
Check whether state law or the HITECH Act imposes additional obligations beyond the resolution agreement, as HIPAA settlements do not necessarily satisfy all applicable requirements.